Generate MD5, SHA-1, SHA-256, and SHA-512 hashes from any text instantly, all computed in your browser.
Input text
Enter text above…
Enter text above…
Enter text above…
Enter text above…
All hashing happens locally in your browser. Your text is never sent to a server.
A cryptographic hash function takes any input and produces a fixed-length output (the hash or digest). The same input always produces the same hash. A tiny change to the input produces a completely different hash. It's a one-way function and you cannot reverse it to get the original input.
MD5 produces a 128-bit (32 hex character) hash and was once widely used for passwords and security. It's now considered cryptographically broken. Collisions (two different inputs with the same hash) can be generated quickly. Use MD5 only for checksums and data integrity, not for security.
SHA-256 (part of the SHA-2 family) produces a 256-bit hash and is the current standard for most security applications: HTTPS certificates, Bitcoin mining, file integrity verification, and password hashing (when used with a proper key stretching algorithm like bcrypt or Argon2).
When you download software, the publisher often provides a SHA-256 hash. After downloading, you can hash the file yourself and compare. If they match, the file is intact and unmodified. If they differ, the file may be corrupted or tampered with.
Passwords should never be stored as plain text. Instead, store a hash. But a raw SHA-256 hash of a password is still vulnerable to rainbow table attacks. Always use a dedicated password hashing algorithm (bcrypt, scrypt, or Argon2) with a random salt.
A collision is when two different inputs produce the same hash. For MD5, collisions are computationally trivial. For SHA-256, no practical collision has ever been found. SHA-3 (Keccak) is the newest NIST standard, designed with a completely different internal structure as insurance against SHA-2 weaknesses.
Generate MD5, SHA-1, SHA-256, and SHA-512 cryptographic hashes from any text. Everything is computed in your browser — no data is sent to any server.
Input: "hello"
MD5: 5d41402abc4b2a76b9719d911017c592 | SHA-256: 2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824
Input: "Hello" (capital H)
Completely different hash — demonstrates sensitivity to input changes
Input: an entire book
Hash length is always fixed — SHA-256 always produces exactly 64 hex characters regardless of input size
Verifying a file download using SHA-256
Identical hashes = verified, authentic file
MD5 was designed by Ron Rivest in 1991. By 2004, researchers had demonstrated practical collision attacks (two different inputs producing the same hash), making it unsuitable for security. SHA-256, part of the SHA-2 family designed by the NSA and published in 2001, remains the current standard and underpins Bitcoin's proof-of-work mining system.
A hash is a fixed-length fingerprint generated from data. It can help compare downloads, detect accidental changes, index content, or identify a file in a system. The same input and algorithm produce the same output, while even a small input change normally produces a very different value. A hash is not encryption and cannot be decoded into the original.
Use the algorithm required by the system, protocol, or publisher you are working with. SHA-256 is a common general-purpose integrity choice. Older algorithms such as MD5 and SHA-1 can still appear in legacy checksums, but they are not suitable for new security designs because collision attacks are known.
A plain hash is not a safe password-storage design. Passwords need a slow, salted, purpose-built password hashing method such as Argon2, scrypt, or bcrypt, with rate limiting around login attempts. Use this page for learning and integrity checks; never paste a real password, private key, or confidential document into an online tool.
Generate a hash using the same algorithm named by the publisher, then compare the complete output character by character with the published checksum. A match supports file-integrity verification, while a mismatch means the file or the claimed checksum needs investigation. It does not prove that the publisher or download is trustworthy by itself.