Hash Generator
Generate SHA-1, SHA-256, SHA-384 and SHA-512 hashes instantly in your browser using the Web Crypto API. Nothing you type is ever uploaded.
Related tools
All Developer tools →This tool runs entirely in your browser. Nothing you enter is sent to our servers, so there is nothing for us to store or see.
About the Hash Generator
A cryptographic hash turns any input into a fixed-length fingerprint. The same input always produces the same hash, a single changed character produces a completely different one, and the process cannot be reversed. That combination makes hashes useful for verifying that a file downloaded intact, that a message was not altered, or that two values match without storing either.
This tool computes SHA-1, SHA-256, SHA-384 and SHA-512 using the Web Crypto API built into your browser — the same audited implementation used for HTTPS — so results are correct and computed locally. Output is available as lowercase or uppercase hex, or as Base64.
MD5 is deliberately not offered. It has been considered broken for collision resistance since 2004 and providing it invites use in exactly the situations where it should not be used.
How to use the Hash Generator
-
Type or paste your text
Enter anything into the left box. Hashes update as you type, with no button to press.
-
Choose an algorithm
SHA-256 is the sensible default for almost everything. Use SHA-512 when you want a longer digest, or SHA-1 only for compatibility with an old system.
-
Pick an output format
Lowercase hex is what most tools expect. Uppercase hex and Base64 are available for systems that require them.
-
Copy the hash
Use Copy to put the digest on your clipboard, ready to paste into a checksum field or a comparison.
Frequently asked questions
Can a hash be reversed to get the original text?
Not directly — hashing is designed to be one-way. However, short or common inputs can be found by brute force or by looking them up in a precomputed table, which is why hashing alone is not enough to protect passwords. Real password storage needs a slow, salted algorithm such as bcrypt, scrypt or Argon2.
Why is MD5 not offered here?
MD5 has been known to be vulnerable to practical collision attacks since 2004, meaning two different inputs can be made to produce the same hash. It should not be used for anything security-related, and offering it here would mostly serve people who do not realise that. SHA-256 is the right default.
Which algorithm should I use?
SHA-256 unless you have a specific reason not to. It is fast, widely supported and has no known practical weaknesses. SHA-512 gives a longer digest and is actually faster on 64-bit hardware. SHA-1 is deprecated for security use and should only be chosen when an existing system requires it.
Is my input sent to your server to be hashed?
No. Hashing uses the Web Crypto API built into your browser, so the computation happens on your device and the text never leaves it. This matters because people often hash sensitive values here to compare them against something else.
Will the same text always give the same hash?
Yes. Hash functions are deterministic, so identical input produces identical output every time, on any machine and in any implementation. That is exactly what makes them useful for verifying that a file or message has not changed in transit.