Hash Generator
Generate MD5, SHA-1, SHA-256, SHA-384, SHA-512 and other hash digests.
Drop file here or click to browse
Maximum 10 MB (*/*)
Enter text or upload a file, then click Generate Hashes
About the Hash Generator
Generate MD5, SHA-1, SHA-256, SHA-384, and SHA-512 hash digests from any text or file. Hashing produces a fixed-length fingerprint that changes completely if even one bit of the input changes, which makes it the standard way to verify downloads, detect file corruption, and store password verifiers.
How to use it
- 1 Type or paste the text you want to hash, or drop in a file.
- 2 All supported algorithms compute at once — no need to pick one first.
- 3 Compare the digest against a published checksum to verify integrity.
- 4 Click any result to copy that digest to your clipboard.
What it does
- MD5, SHA-1, SHA-256, SHA-384 and SHA-512 computed simultaneously
- Hash entire files without uploading them
- SHA-* built on the browser-native Web Crypto API; MD5 implemented directly since browsers omit it
- Weak algorithms flagged inline rather than hidden
- Lowercase hexadecimal output ready for checksum comparison
Frequently asked questions
Are my files uploaded to hash them?
No. Every calculation happens locally in your browser using JavaScript. Nothing you paste is uploaded, logged, or stored on a server, which makes the tool safe to use with production data, credentials, and customer records.
Which hash algorithm should I use?
Use SHA-256 unless you have a specific reason not to — it is the current default for file integrity, digital signatures, and blockchain applications. Use SHA-512 when you want a larger digest. Reach for MD5 or SHA-1 only when matching a checksum some existing system already publishes in that format; do not choose either for anything new.
Is MD5 safe to use?
Not for anything security-sensitive. Practical collision attacks let an attacker craft two different files that hash to the same MD5 digest, which breaks it for signatures, certificates, and detecting deliberate tampering. It is included here because plenty of legacy tooling and file-integrity workflows still publish MD5 checksums, and matching one of those is a legitimate reason to compute it — just not to protect against an adversary.
Why do browsers not support MD5 natively?
The Web Crypto API only exposes SHA-1/256/384/512 through SubtleCrypto.digest() — MD5 was left out deliberately because it is broken for security purposes. This tool computes MD5 with its own RFC 1321 implementation instead, verified against the RFC test vectors and cross-checked against Node's independent crypto module.
Can I reverse a hash back to the original text?
No. Hashing is one-way by design. What attackers do instead is guess: they hash billions of candidate inputs and look for a match. That is why passwords must be hashed with a slow, salted algorithm such as bcrypt, scrypt, or Argon2 rather than a raw SHA or MD5 digest.
Should I use SHA-256 to store passwords?
No. SHA-256 is designed to be fast, which is exactly wrong for passwords — it lets an attacker test billions of guesses per second on stolen hashes. Use a deliberately slow, salted password hash such as bcrypt, scrypt, or Argon2id.