Search DevTools

Jump to any tool or page

Hash Generator

Hash any text with MD5, SHA-1, or SHA-256. The result updates as you type.

Input

anything you like

SHA-256 digest

The digest appears here as you type.

Developer Utilities

About Hash Generator

Generate MD5, SHA-1, SHA-256, and SHA-512 digests from text or files. Hashing is one-way and deterministic: the same input always yields the same digest, and the digest cannot be reversed to recover the input.

Frequently asked questions

Which hash algorithm should I use?
For integrity checks and general-purpose hashing, SHA-256 is the sensible default. MD5 and SHA-1 are both cryptographically broken — practical collision attacks exist for each, and SHA-1 collisions were demonstrated publicly in 2017 — so neither should back a security decision, though MD5 remains acceptable as a fast non-security checksum for cache keys or deduplication. For hashing passwords, none of these are appropriate.
Why should passwords not be hashed with SHA-256?
Because SHA-256 is designed to be fast, and speed is exactly what an attacker with a stolen database wants — commodity GPUs compute billions of SHA-256 hashes per second, making brute-force and rainbow-table attacks cheap. Password storage needs a deliberately slow, salted, memory-hard function: bcrypt, scrypt, or Argon2. These accept a work factor you raise as hardware improves, and they salt automatically so identical passwords produce different stored hashes.
What is a hash collision and does it matter?
A collision occurs when two different inputs produce the same digest. Collisions must exist mathematically, since a fixed-length output cannot uniquely represent unbounded input — what matters is whether they can be found deliberately. For MD5 and SHA-1 they can, cheaply, which lets an attacker craft two files with matching digests and substitute one for the other. SHA-256 has no known practical collision attack.
Why does the same file give a different hash elsewhere?
Almost always an input difference rather than an algorithm one. Trailing newlines, a UTF-8 byte-order mark, and CRLF versus LF line endings all change the bytes and therefore the digest. Text hashed as a string also differs from the same text hashed as an uploaded file if encoding or line endings differ. Comparing bytes rather than assuming visual equivalence resolves most mismatches.
Can a hash be reversed?
Not by inverting the function — hashes are one-way by construction. But they are not secret: identical input always yields identical output, so an attacker can hash likely candidates and compare. That is precisely how rainbow tables and dictionary attacks recover common passwords from unsalted digests. A hash protects data only when the input has enough entropy that guessing it is infeasible.