Utilities

Hash generator

MD5, SHA-1, SHA-256, SHA-384 and SHA-512 of text or a file, with optional HMAC and a checksum check. Everything runs in your browser: nothing is uploaded.

Hashed as UTF-8 as you type. Line breaks count as LF (\n), and a line break at the end changes the hash.

Case doesn’t matter for hex. The page finds which algorithm it matches.

Questions

Is my text or file uploaded?

No. Hashing runs in your browser: MD5 with this page’s own code, SHA-1 and SHA-2 with the browser’s WebCrypto API. A file is read from your disk and never uploaded, and nothing you type is sent anywhere or put in the address bar.

Why doesn’t my hash match the one from the command line?

Usually a line break. echo abc | sha256sum hashes “abc” plus a newline; use printf abc or echo -n abc. Text here is hashed as UTF-8 with LF line breaks, so a file saved with Windows CRLF line breaks hashes differently from the same text pasted here. For an exact match, hash the file itself.

Are MD5 and SHA-1 safe to use?

Not for security. Collisions, two different inputs with the same hash, can be made for both: for MD5 in seconds, for SHA-1 since 2017 (SHAttered). Use them only to catch accidental corruption, such as checking a download against a published checksum. For signatures, certificates and anything an attacker could tamper with, use SHA-256 or stronger.

Can I hash passwords with this?

Don’t store passwords as any of these hashes. They are fast, even SHA-512, so attackers can test billions of guesses a second against a leaked hash. Store passwords with a slow password hash such as Argon2id, scrypt or bcrypt, with a unique salt for each.

What is an HMAC?

A hash mixed with a secret key (RFC 2104). Only someone with the key can make or check it, so it proves a message came from a key holder and wasn’t changed. Webhooks from Stripe, GitHub and Slack are signed this way, usually with HMAC-SHA256. The key here can be text, hex or Base64.

How do I check a download’s checksum?

Open the File tab, choose the file and paste the published checksum into the compare box. Hex in any case, Base64, a line from sha256sum or shasum, and an SRI value such as sha384-… all work. The page says which algorithm matches, or that none does.

How large a file can I hash?

Up to 2 GB. The file is read in pieces with a progress bar and MD5 is worked out as it reads; WebCrypto then hashes the whole file at once, so it has to fit in memory. Above 500 MB this can be slow, especially on phones. For bigger files use shasum -a 256 file (macOS), sha256sum file (Linux) or certutil -hashfile file SHA256 (Windows).

esc