Hash Generator
Generated locally — no data sent to servers.
- Paste or type the input text.
- Choose the algorithm: MD5, SHA-1, SHA-256 or SHA-512.
- The hash is computed as you type and can be copied directly.
A hash is a one-way function: it turns any input into a fixed-size output, and there is no path back. SHA-256 always produces 64 hexadecimal characters, whether the input is a single letter or a one-gigabyte file.
The same input always produces the same hash, and any minimal change, a space or a capital letter, changes the output completely. That is why hashes verify integrity: if two files share a SHA-256, they are identical.
A hash is not encryption. Encryption is reversible with the key; hashing is not reversible at all.
MD5 and SHA-1 are broken for security use. Practical attacks exist that produce two different inputs with the same hash, which destroys any guarantee of authenticity. They remain useful only as checksums against accidental corruption, or to compare files.
SHA-256 is the current standard for integrity and signing. SHA-512 uses the same design with a larger output and is often faster on 64-bit processors.
MD5 is computed here by an in-house TypeScript implementation following RFC 1321. The SHA algorithms use the browser native Web Crypto API, which requires a secure context: HTTPS or localhost.
Applying SHA-256 to a password and saving the result is a classic mistake. Hash functions are designed to be fast, and that speed lets an attacker test billions of guesses per second on a graphics card.
For passwords, use an algorithm designed to be slow and memory-hard: Argon2id is the current recommendation, and bcrypt with a high cost factor is an accepted alternative. Both incorporate a salt automatically, which defeats precomputed tables.
The text you type never leaves your browser. All computation is local and nothing is logged.
Frequently asked questions
No. What exists are databases of precomputed hashes for common inputs, which allows recognising predictable values such as "123456". That is not reversal, it is a lookup in a ready-made list.
Inertia, and because it is fast. For detecting accidental file corruption it still works. For anything depending on an attacker being unable to forge the hash, it has been inadequate since 2004.
Output size, 256 against 512 bits, and internal word size. On 64-bit processors SHA-512 is often faster despite the larger output. Both are considered secure.
Yes, that is one of the legitimate uses. Matching hashes indicate identical content, and for that purpose even MD5 suffices, since nobody is deliberately trying to deceive you.
No. All computation happens in your browser.