Hash Generator (SHA-256, SHA-512, MD5)

Compute SHA-1, SHA-256, SHA-384, SHA-512 and MD5 hashes or HMACs of text or files, and check a download against its published checksum.

Digests

MD5 is computed in JavaScript because the Web Crypto API does not offer it. MD5 and SHA-1 are not collision-resistant, so use them only for checksums, never for security.

Overview

A cryptographic hash function turns input of any size into a short, fixed-length fingerprint. Developers reach for one when verifying that a download wasn't corrupted or tampered with, generating cache keys and ETags, deduplicating files, signing webhook payloads, or checking what value a system actually stored. This tool shows all common algorithms side by side, so you don't have to know in advance which one a checksum file uses.

Text is encoded as UTF-8 before hashing, which is what nearly every language and command-line tool does. Files are read in your browser with the File API and hashed with the native Web Crypto API (crypto.subtle.digest). Nothing is uploaded. Turn on HMAC to compute keyed hashes, and paste a published checksum into the compare box to get a clear match or no-match answer.

What makes a hash function cryptographic

Every hash function maps input to a fixed-size output. A cryptographic one adds three guarantees: it is infeasible to find an input for a given hash (preimage resistance), to find a second input with the same hash as a known one, or to find any two inputs that collide. Two properties are visible right away:

  • Deterministic and fixed length. The same bytes always give the same digest. SHA-256 is always 256 bits (64 hex characters), whether you hash one byte or a 4 GB disk image.
  • Avalanche effect. Changing a single bit of the input flips about half of the output bits, so similar inputs give unrelated-looking hashes:
SHA-256("hello world")  = b94d27b9934d3e08a52e52d7da7dabfac484efe37a5380ee9088f7ace2efcde9
SHA-256("hello world!") = 7509e5bda0c762d2bac7f90d758b5b2263fa01ccbc542ab5e3df163be08e6ca9

The flip side is that invisible differences matter. The most common "wrong hash" report is a trailing newline: echo hello | sha256sum hashes hello\n, not hello. Use printf '%s' hello or echo -n. Windows line endings (\r\n), a byte-order mark, or a different text encoding change the hash in the same way. The byte count next to the input tells you exactly how many bytes were hashed.

How to verify a downloaded file

Projects publish a checksum next to their installers and ISO images. Hash the file you downloaded and compare the result. You can drop the file into this page and paste the published value into the compare box, or use the built-in command on your OS:

# macOS
shasum -a 256 ubuntu-24.04-desktop-amd64.iso

# Linux (and check a whole SHA256SUMS file at once)
sha256sum ubuntu-24.04-desktop-amd64.iso
sha256sum -c SHA256SUMS --ignore-missing

# Windows PowerShell
Get-FileHash .\ubuntu-24.04-desktop-amd64.iso -Algorithm SHA256

# Windows cmd
certutil -hashfile ubuntu-24.04-desktop-amd64.iso SHA256

The compare box accepts all of these output formats. It ignores case and surrounding spaces, strips a trailing file name or a sha256: prefix, and also accepts certutil's space-separated hex. A matching checksum proves that the file is the one the checksum describes. It only proves the file is authentic if the checksum came from a trusted source, such as an HTTPS page or a GPG-signed SHA256SUMS file, rather than the same mirror that served the download.

Checksums are not password hashes

SHA-256 is designed to be fast, and that is exactly what you don't want for passwords. An attacker who steals a table of sha256(password) values can test billions of guesses per second on a GPU, and an unsalted table falls to precomputed lookups. Adding a salt stops the lookups but not the speed.

Use a dedicated password hashing function instead: Argon2id (the current OWASP recommendation), scrypt or bcrypt. They generate a unique salt for each password and are deliberately slow. Argon2 and scrypt are also memory-hard, which makes GPU and ASIC cracking expensive. Their cost settings let you raise the work factor as hardware gets faster.

HMAC for message authentication

A plain hash proves integrity only if the attacker can't replace the hash too. An HMAC mixes a secret key into the computation (RFC 2104), so only someone who holds the key can produce a valid tag. Webhooks from payment providers and Git hosts are signed this way. The receiver recomputes the HMAC over the raw request body and compares it in constant time:

const crypto = require('crypto');
const expected = crypto.createHmac('sha256', process.env.WEBHOOK_SECRET)
    .update(rawBody)            // the exact bytes received, not re-serialized JSON
    .digest('hex');
const ok = crypto.timingSafeEqual(Buffer.from(expected), Buffer.from(signatureHeader));

Don't build your own sha256(secret + message). SHA-256 and SHA-512 are vulnerable to length-extension attacks, which let an attacker append data and compute a valid hash without knowing the secret. HMAC's nested construction prevents that. The HS256 algorithm in a JSON Web Token is HMAC-SHA-256 as well, which you can see in the header with the JWT decoder. If you need to send raw digest bytes in a header, switch the output to Base64 or use the Base64 encoder.

Frequently Asked Questions

Is SHA-1 broken?

For collision resistance, yes. In February 2017 the SHAttered attack by CWI Amsterdam and Google produced two different PDF files with the same SHA-1 hash, and later research made chosen-prefix collisions practical. Browsers stopped trusting SHA-1 certificates, and Git added collision detection and a SHA-256 repository format. SHA-1 is still fine for detecting accidental corruption, but not against an adversary.

Why is MD5 here if it's insecure?

Many older mirrors, package indexes and storage APIs still publish MD5 checksums (S3 ETags for single-part uploads, for example), so you still need to compute it. MD5 collisions can be generated in seconds on a laptop, so treat a matching MD5 only as proof that the file wasn't corrupted in transit. The Web Crypto API leaves MD5 out on purpose, so this page implements it in JavaScript and tests it against the RFC 1321 vectors.

Why doesn't my hash match the one from another tool?

The input bytes differ. Look for a trailing newline, \r\n line endings, leading or trailing spaces, or a different encoding such as UTF-16 instead of UTF-8. If one side is Base64 and the other is hex, they can be the same digest written two ways. The compare box checks both forms.

How large a file can I hash?

Files of several hundred megabytes work in a modern desktop browser. The file is loaded into memory, so very large files depend on available RAM, and browsers refuse files over 2 GB. For larger disk images, use sha256sum or Get-FileHash, which stream from disk.

Which algorithm should I use?

SHA-256 is the default choice for checksums, content addressing and HMAC signatures. SHA-512 can be faster on 64-bit CPUs and gives a longer digest. SHA-384 is SHA-512 truncated with different starting values, which also makes it immune to length extension. For random identifiers rather than fingerprints, use the UUID generator instead.