Skip to main content
ToolsBay

Runs in your browser — nothing is uploaded · verify

Hash Generator — free, and it runs in your browser

Generate MD5, SHA-1, SHA-256, SHA-384 and SHA-512 digests of any text.

  • Every digest at once, so you need not know which one the other system used.
  • Compare a checksum, build a cache key, or fingerprint a payload.
  • The SHA digests use the browser’s own Web Crypto and MD5 is computed in the page, so the input is never transmitted.
Tab indents · Esc then Tab to leave1 line
MD5Broken — collisions are trivial to produce. Checksums only.

Waiting for input…

SHA-1Broken — practical collisions demonstrated in 2017. Legacy use only.

Waiting for input…

SHA-256

Waiting for input…

SHA-384

Waiting for input…

SHA-512

Waiting for input…

  • 70 tools

    Free, with no account and no watermark

  • 0 bytes

    Of your files or text uploaded — this tool runs in the tab

  • No queue

    The work happens in this tab, not in a line behind other users

Three steps, nothing to install

Hash Generator in three steps

  1. TEXT123456Paste it in — it never leaves the tab

    Paste your text

    A string, a file’s contents, or a value you need to compare against a published checksum.

  2. TEXTDIGESTConverted on your own device

    Get every digest at once

    Every digest is computed together, so you do not have to know in advance which one the other system used.

  3. Copy DIGEST

    Copy the digest

    One click per algorithm, ready to paste into a comparison.

Why use Hash Generator

  • The browser’s own crypto

    SHA digests come from the Web Crypto API — the same implementation your browser uses for TLS — rather than from a hand-rolled routine.

  • MD5 and SHA-1 are for checksums

    Both are broken for security purposes and both are still what a mirror publishes next to a download. They are here for verification, and the page does not pretend otherwise.

  • Your text stays in the page

    What you paste is not transmitted or stored, so an API response full of customer records, a token or an internal query never leaves your machine.

Frequently asked questions

No. Hashing is one-way by design. What an attacker can do is guess: hash millions of candidate inputs and compare. That is why hashing a common password offers little protection on its own.

What a hash function does

A hash function maps input of any size to a fixed-length fingerprint. The same input always produces the same output; changing a single character produces a completely different result. It cannot be run backwards, which is what makes it useful for verifying that something has not changed without storing the thing itself.

Which algorithm to use

  • MD5 (128-bit) — broken since 2004. Collisions can be produced in seconds. Acceptable only as a checksum against accidental corruption.
  • SHA-1 (160-bit) — broken in practice since 2017. Being phased out everywhere; do not start new work with it.
  • SHA-256 (256-bit) — the current default for signatures, certificates and content addressing. No known weaknesses.
  • SHA-384 / SHA-512 — same family, longer output. SHA-512 is often faster than SHA-256 on 64-bit hardware.

Hashing is not encryption, and not password storage

Encryption is reversible with a key; hashing is not reversible at all. And while passwords should be hashed rather than stored in plain text, a general-purpose hash is the wrong tool: its speed is a liability. Password hashing needs an algorithm that is deliberately expensive to compute and salted per user.

To generate a strong password in the first place, use the password generator. For reversible encoding rather than hashing, see the Base64 encoder.

Related guides

More tools

70 tools, none of which want your file

Everything this tool does happens in the page you are looking at. No account, no upload, no watermark.