Skip to content

Hash generator

SHA-256 and other SHA hashes of any text, updated as you type.

  • SHA-256
  • SHA-384
  • SHA-512
  • SHA-1

Text is hashed as UTF-8. Line endings and trailing spaces count.

How it works

Hash functions in practice

A cryptographic hash function turns any input into a short, fixed-size value. Change one letter and the result is completely different, which makes hashes ideal for spotting changes:

  • Download checks: compare a file's SHA-256 with the one the publisher lists.
  • Caching and deduplication: identical content gives an identical hash.
  • Signatures and certificates: the data is hashed, then the hash is signed.
  • Git identifies every commit and file by its hash.

Hash lengths

AlgorithmBitsHex charactersStatus
SHA-116040Broken for security use
SHA-25625664Recommended
SHA-38438496Secure
SHA-512512128Secure

More tools

More on the bench

  • JSON formatter and validatorPretty-print, minify and validate JSON, with the exact line of any error.
  • Base64 encoder and decoderEncode text to Base64 and back, including URL-safe Base64 and emoji.
  • URL encoder and decoderPercent-encode and decode URLs and query values, and break a URL into parts.
  • CSV to JSON converterConvert CSV to JSON and JSON to CSV, with delimiter detection.
  • UUID generatorGenerate random v4 or time-ordered v7 UUIDs, one or a hundred at a time.
  • JWT decoderRead the header and claims of a JSON Web Token, with expiry dates in plain English.

Frequently asked questions

What is a hash?

A hash is a fixed-length fingerprint of data. The same input always gives the same hash, the smallest change gives a completely different one, and you can't work backwards from the hash to the input. Hashes are used to check file integrity, compare data and build digital signatures.

Which algorithm should I use?

SHA-256 is the standard choice for most purposes today. SHA-384 and SHA-512 are longer variants from the same SHA-2 family. SHA-1 is broken for security uses and is only here for compatibility with older systems.

Can I use SHA-256 to store passwords?

No. Plain SHA hashes are designed to be fast, which makes them fast to brute-force. Passwords should be stored with a slow, salted password hashing function such as Argon2, scrypt or bcrypt.

Why is there no MD5?

MD5 has been broken for decades and browsers' built-in crypto doesn't offer it. If you need MD5 for a legacy checksum, use your operating system's md5 or md5sum command.

Is my text sent anywhere?

No. Hashes are computed by your browser's Web Crypto API on your device. The text never leaves the page.