DevToolsForYou
Private by defaultRuns in your browser

Hash generator

Paste text and generate common hash digests in the browser for checksums, fixtures, signatures, and quick verification tasks.

Quick samplesUseful for testing
Hash MD5/SHA

About this tool

A cryptographic hash reduces input of any length to a fixed-length digest, and does it deterministically: the same input always produces the same output, while changing a single bit produces a completely different one. Hashes are one-way — there is no operation that turns a digest back into the text that produced it. That property is what makes them useful for integrity checks, cache keys, deduplication, ETags, content addressing, and commit identifiers. The four algorithms here are not interchangeable. MD5 and SHA-1 are both broken for security purposes: practical collision attacks exist for each, so an attacker can construct two different inputs with the same digest. They remain perfectly reasonable as fast non-adversarial checksums for detecting accidental corruption. SHA-256 and SHA-512 are the current defaults for anything where an attacker might benefit from forging a match — signatures, certificate fingerprints, and integrity attestations. This tool computes all four from text input using the browser's Web Crypto API, so the text you paste never leaves your machine.

No signup requiredRuns in your browserInstant results
How to use
  1. 1

    Type or paste the text you want to hash into the input field.

  2. 2

    Select your algorithm — SHA-256 for security use cases, MD5 for checksums, SHA-512 for maximum strength.

  3. 3

    The hash is computed instantly as you type.

  4. 4

    Click Copy to copy the hash hex string to your clipboard.

Why use this tool?
  • →

    Generate checksums for text fixtures, payloads, or copied content.

  • →

    Compare MD5 and SHA hashes when testing integrations or signature flows.

  • →

    Create deterministic digests in the browser without sending data elsewhere.

ExamplesInput → output

MD5 hash

Inputhello
Output5d41402abc4b2a76b9719d911017c592

SHA-256 hash

Inputhello
Output2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824

SHA-512 hash

Inputhello
Output9b71d224bd62f3785d96d46ad3ea3d73319bfbc2890caadae2dff72519673ca72323c3d99ba5c11d7c7acc6e14b8c5da0c4663475c2e5c3adef46f73bcdec043
Common errorsAnd how to fix them

The hash does not match the one from my server or CLI tool

Cause: Almost always a difference in the exact bytes being hashed rather than a difference in the algorithm. A trailing newline is the usual culprit — echo adds one, so echo hello | md5sum and hashing the five characters hello give different digests.

Fix: Use printf instead of echo, or echo -n, so no newline is appended. Also check for a trailing space, a byte-order mark on a pasted file, or CRLF line endings where the other side used LF.

Non-ASCII text hashes differently in another tool

Cause: Hashes operate on bytes, not characters, so the text encoding matters. This tool encodes input as UTF-8. A tool defaulting to UTF-16 or Latin-1 will hash a different byte sequence for the same visible string.

Fix: Make sure both sides encode as UTF-8 before hashing. Be aware that visually identical Unicode strings can differ in normalisation form — é as one code point and as e plus a combining accent are different bytes and hash differently.

Using this to hash a password

Cause: A plain hash is designed to be fast, which is exactly the wrong property for password storage. Modern hardware computes billions of SHA-256 digests per second, so a stolen table of unsalted hashes falls quickly to brute force.

Fix: Store passwords with a purpose-built, deliberately slow, salted algorithm — bcrypt, scrypt, or Argon2id. Use these general-purpose hashes for integrity and identity, never for credentials at rest.

Frequently asked questionsCommon questions answered

These answers explain common hash md5/sha tasks, expected input formats, and edge cases so both visitors and search engines can understand what this tool does.

What is the difference between MD5, SHA-1, SHA-256, and SHA-512?

They are different hashing algorithms with different output lengths and security properties. SHA-256 and SHA-512 are generally preferred over MD5 and SHA-1 for modern security-sensitive use cases.

Can I use this hash generator for passwords?

Not directly. Password storage should use dedicated password hashing algorithms like bcrypt, scrypt, or Argon2 rather than plain MD5 or SHA hashes.

Why do two similar inputs produce completely different hashes?

Cryptographic hashes are designed so even tiny input changes produce very different outputs. That behavior helps detect changes and tampering.

Does this tool hash files?

This version hashes text input pasted into the page. It is useful for strings, payloads, tokens, and copied fixtures rather than file uploads.

Code examplesUse this tool in your code

In Node.js use the built-in crypto module. In browsers use the Web Crypto API (SubtleCrypto), which is async.

JavaScript / Node.jsNode.js (crypto module)
const crypto = require("crypto");

// SHA-256
const sha256 = crypto.createHash("sha256")
  .update("Hello, world!")
  .digest("hex");
console.log(sha256);
// 315f5bdb76d078c43b8ac0064e4a0164612b1fce77c869345bfc94c75894edd3

// SHA-512
const sha512 = crypto.createHash("sha512")
  .update("Hello, world!")
  .digest("hex");

// MD5 (checksums only — not for security)
const md5 = crypto.createHash("md5")
  .update("Hello, world!")
  .digest("hex");
console.log(md5); // 6cd3556deb0da54bca060b4c39479839

// HMAC-SHA256 (for message authentication)
const hmac = crypto.createHmac("sha256", "secret-key")
  .update("Hello, world!")
  .digest("hex");
See full JavaScript / Node.js examples →