How to use the hash generator
Type or paste text into the box. MD5, SHA-1, SHA-256, SHA-384 and SHA-512 hashes are calculated instantly as you type, and each one can be copied with a click. SHA hashes use your browser's built-in Web Crypto API; nothing is sent to a server.
Hash algorithms compared
| Algorithm | Output | Security status | Typical use |
|---|---|---|---|
| MD5 | 128 bits (32 hex) | Broken — collisions are trivial | Legacy checksums, cache keys |
| SHA-1 | 160 bits (40 hex) | Broken — practical collisions since 2017 | Git object IDs (legacy) |
| SHA-256 | 256 bits (64 hex) | Secure | File integrity, signatures, HMAC, blockchains |
| SHA-384 | 384 bits (96 hex) | Secure | TLS certificates, subresource integrity |
| SHA-512 | 512 bits (128 hex) | Secure | High-security integrity checks |
Properties of a good hash function
- Deterministic — the same input always gives the same output.
- Avalanche effect — changing one character changes roughly half the output bits.
- One-way — you can't recover the input from the hash.
- Collision-resistant — it's infeasible to find two inputs with the same hash.
Common uses
- Verifying downloads. Compare a file's published SHA-256 checksum with your own to confirm it wasn't corrupted or tampered with.
- Webhook signatures. Payment gateways such as Razorpay sign webhooks with HMAC-SHA256 so you can confirm they're genuine.
- Deduplication and caching. Hash content to create stable keys for caches or to detect duplicate files.
Don't hash passwords with these
General-purpose hashes are designed to be fast, which is exactly wrong for passwords. Use a slow, salted password hashing function like Argon2id or bcrypt. Need a strong password to begin with? Try the password generator.
Frequently asked questions
What is a hash?
A hash function turns input of any size into a fixed-length fingerprint. The same input always produces the same hash, a tiny change produces a completely different hash, and you can't reverse a hash back to the input.
Is MD5 still safe to use?
Not for security. MD5 and SHA-1 have practical collision attacks. They're fine for non-security checksums such as detecting accidental file corruption or cache keys, but use SHA-256 or stronger for anything security-related.
Should I hash passwords with SHA-256?
No. Fast hashes like SHA-256 let attackers try billions of guesses per second. Store passwords with a slow, salted algorithm such as Argon2id or bcrypt — Laravel's Hash::make() uses bcrypt by default.
Why doesn't my hash match another tool's?
Usually a whitespace or encoding difference — a trailing newline, Windows (CRLF) line endings or a different text encoding. This tool hashes the exact UTF-8 bytes of what's in the box.
Last updated: 22 September 2026Suggest an improvement · Report a problem
