Hash Generator
Generate SHA-1, SHA-256, SHA-384 and SHA-512 digests from any text.
Hashing runs entirely in your browser with the Web Crypto API — nothing is uploaded. SHA-1 is included for checksum compatibility but is no longer considered safe for security use.
Generate SHA-1, SHA-256, SHA-384, and SHA-512 cryptographic hash digests from any text input — useful for verifying file integrity, generating checksums, or working with APIs that require a hashed value.
The same input always produces the same hash, and changing even a single character produces a completely different result, which is exactly what makes hashes useful for detecting tampering.
Choosing an algorithm
| Algorithm | Digest length | Status |
|---|---|---|
| MD5 | 128 bits | Broken. Checksums only, never security. |
| SHA-1 | 160 bits | Broken since 2017. Legacy compatibility only. |
| SHA-256 | 256 bits | The sensible default for integrity. |
| SHA-384 / SHA-512 | 384 / 512 bits | Secure; SHA-512 is often faster on 64-bit CPUs. |
| bcrypt / Argon2 | Varies | For passwords — deliberately slow. |
'Broken' means practical collisions have been demonstrated — two different inputs producing the same digest — not that the algorithm fails to run.
Why you must not hash passwords with SHA
SHA-256 is designed to be fast, and that is exactly the wrong property for password storage. A modern GPU can compute billions of SHA-256 hashes per second, so a stolen database of SHA-256 password hashes is a dictionary attack waiting to happen.
Password hashing algorithms — bcrypt, scrypt, Argon2 — are deliberately slow and memory-hard, with a tunable work factor and a per-user salt built in. The salt means identical passwords produce different hashes, defeating precomputed rainbow tables; the slowness means an attacker gets thousands of guesses per second rather than billions.
Verifying a download
- Find the checksum published by the software vendor, ideally on a different server or signed with their key.
- Compute the hash of the file you downloaded, using the same algorithm they published.
- Compare the two strings — checking the first and last several characters is enough in practice.
- If they differ, the file is corrupt or tampered with. Re-download from the official source rather than using it.
- A checksum published on the same page as a compromised download proves nothing, which is why signed checksums matter.
Frequently asked questions
- Which hash algorithm should I use?
- SHA-256 is a solid general-purpose default for integrity checks; SHA-1 is considered cryptographically broken for security purposes and should only be used where required for legacy compatibility.
- Can a hash be reversed back to the original text?
- No — cryptographic hash functions are one-way by design; there's no way to recover the original input from the hash alone.
- Is this suitable for hashing passwords?
- No — plain SHA hashes of passwords are vulnerable to precomputed lookup attacks. Password storage should use a dedicated algorithm like bcrypt or Argon2 with per-user salting, not a raw SHA hash.
- What does it mean that SHA-1 is 'broken'?
- Researchers demonstrated a practical collision in 2017 — two different files producing the same SHA-1 digest. That defeats its use for signatures and tamper detection, though it still works as a non-adversarial checksum.
- What is a salt and why does it matter?
- A unique random value mixed into each password before hashing. It ensures two users with the same password get different hashes, which defeats precomputed rainbow tables. Proper password hashing algorithms handle salting for you.
- Is my input sent anywhere?
- No. Hashing uses your browser's built-in Web Crypto API and runs entirely on your device.
Read more on this
- Practical password security, without the folkloreWhy length beats symbols, why scheduled password changes were abandoned, and the three habits that actually prevent account compromise.
- Understanding JSON Web Tokens (JWT) and token securityHow JWT headers, payloads and signatures fit together, why tokens are encoded rather than encrypted, and how to avoid critical authentication flaws.