Hash Generator

Generate SHA-1, SHA-256, and SHA-512 hashes of any text.

About this tool

Generates SHA-1, SHA-256, and SHA-512 hashes of whatever text you type, live, using the browser's built-in Web Crypto API — the same implementation the browser uses for HTTPS. Nothing is uploaded; the hashing happens entirely in your browser once the page has loaded.

What a hash is. A cryptographic hash function turns any input into a fixed-length string of hex digits (40 for SHA-1, 64 for SHA-256, 128 for SHA-512). The same input always produces the same output, a single changed character produces a completely different output, and there's no practical way to run it backwards to recover the input. It's a fingerprint, not encryption — there's no key and nothing to decrypt.

What it's good for. Verifying that a download or a copied block of text arrived intact (compare its hash against a published one), generating a stable identifier for a piece of content, or de-duplicating. Text is read as UTF-8 before hashing, so the same characters always hash the same way regardless of platform.

Which algorithm to use.

AlgorithmDigestUse
SHA-25664 hex charsThe default choice for anything new
SHA-512128 hex charsLonger digest; slightly faster on 64-bit hardware for large inputs
SHA-140 hex charsOnly for compatibility with older systems — broken for security use

SHA-1 is not collision-resistant. Researchers have produced two different files with the same SHA-1 hash. Don't rely on it where an attacker could benefit from forging a match; it's fine for a non-adversarial checksum against accidental corruption.

Hashing is not password storage. A plain SHA hash of a password is fast to brute-force. Real password storage uses a deliberately slow, salted function like bcrypt, scrypt, or Argon2. This tool is for content hashing, not credentials.

No MD5. The Web Crypto API doesn't offer MD5, and it's thoroughly broken, so it isn't included. For a non-cryptographic checksum of an uploaded file, use the file checksum tool. To actually encrypt text with a password, use text encryption.

Frequently asked questions

Which hash should I use?
SHA-256 for anything new. SHA-512 if you specifically want a longer digest. SHA-1 only when an older system requires it — it's no longer secure against a motivated attacker.
Why isn't MD5 included?
It isn't available in the browser's Web Crypto API, and it's cryptographically broken, so it's intentionally left out.
Can I get the original text back from a hash?
No. Hashing is one-way by design. The only way to "reverse" a hash is to guess inputs and hash them until one matches.
Is this safe for hashing passwords?
No. Plain SHA hashes are far too fast for password storage. Use a purpose-built slow hash such as bcrypt, scrypt, or Argon2 with a per-user salt.
Does it work offline?
Yes, once the page has loaded. Hashing uses the browser's built-in crypto and needs no network.
Will the same text always give the same hash?
Yes. Text is encoded as UTF-8 first, so identical characters produce an identical digest on any device.