Developer Hashing

Hash generator

Algorithm

The digest appears here as you type

Hashed in your browser · the file is never uploaded

Local · WebCrypto for SHA, in-page code for MD5

Hashing turns any input into a fixed-length fingerprint: 32 hexadecimal characters for MD5, 64 for SHA-256, 128 for SHA-512. The same input always gives the same digest, one changed character gives a completely unrelated one, and there is no way back. Useful for checking something has not changed, useless for hiding it.

How to generate a hash

1 Type or paste the text. The digest updates as you type.
2 Switch algorithms to compare. SHA-256 is the sensible default; MD5 and SHA-1 are here for checksums published years ago.
3 Tap the digest to copy it.

Which one to use depends entirely on why. For anything security-related, SHA-256 or SHA-512. For verifying a download against a checksum published years ago, whichever the publisher used, which is often MD5 or SHA-1. Both are broken against a deliberate attacker but still perfectly good at catching a corrupted transfer. CRC-32 does not belong to that family at all; it is an error-detecting code, which is why ZIP files carry one.

MD5 has been broken since 2004, and it is worth being precise about what that means, because it is not useless. What is broken is collision resistance: an attacker can construct two inputs that hash the same. That defeats MD5 for signatures and for anything where a hostile party supplies the file, and does not defeat it for spotting a truncated download. Browsers dropped MD5 from WebCrypto precisely to stop people reaching for it by default, so the implementation here ships with the page while the SHA family comes from the browser itself.

The other recurring confusion is that SHA-256 is not encryption. Encryption is reversible with a key; hashing is not reversible at all, and a site offering to decrypt a digest is looking it up in a table of previously-hashed common inputs. That is also why a fast hash is the wrong tool for storing passwords: an attacker can try billions of candidates a second against a stolen database.

One thing that trips people up: this hashes the bytes of the text as UTF-8, so an accented character or an emoji contributes more than one byte and the digest reflects that.

What people use it for

  • Generating a SHA-256 digest of a string
  • Reproducing an MD5 that older documentation quotes
  • Comparing digests to see whether two strings match exactly
  • Seeing how the same text hashes under each algorithm
  • Working out why a digest from another tool came out different
  • Showing what one changed character does to a hash

Questions

SHA-256 unless something specific requires otherwise. It is fast, well-studied and has no known practical weaknesses.

RFC 1321: the MD5 message-digest algorithmNIST FIPS 180-4 — secure hash standardMDN, SubtleCrypto.digest()
Was this tool any good?
Internal signal only · I use it to find the tools worth rebuilding