Skip to main content
ZEKILO Dev

Hash Generator

Type text or open a file to see five hashes at once. Everything is computed in this browser.

Stays in your browserFIPS 180-4RFC 1321RFC 2104As of 2026.10.03

Input

Press Esc, then Tab to leave the editor.

Output

Hash values by algorithm
MD5—Known collisions. Not for security use.
SHA-1—Known collisions. Not for security use.
SHA-256—
SHA-384—
SHA-512—

How to use Hash Generator

  1. 1Type or paste text into the input panel, or press Open file. You can also drop a file onto the card.
  2. 2Choose the output format (hex or Base64). Turn on HMAC and type a key if you need a keyed hash.
  3. 3Press the copy button on a row to copy that hash, or open Compare and paste an expected hash to check it.

Hash Generator options

Input type
Text is encoded as UTF-8 before it is hashed. File hashes the bytes of the file exactly as they are, up to 2 GB.
Output
hex in lowercase (default), HEX in uppercase, or Base64.
HMAC
Computes a keyed hash with the key you type. The key is read as UTF-8 and is not stored.
Compare
Paste an expected hash to see whether it matches one of the five results. Letter case and surrounding spaces are ignored.

Standards

SHA-1, SHA-256, SHA-384, and SHA-512 are defined in FIPS 180-4, MD5 in RFC 1321, and HMAC in RFC 2104. A hash is computed over bytes, not characters. Text is turned into bytes with UTF-8 first, so the same text always gives the same hash here and in any other tool that uses UTF-8.

All five results are shown together because checksums are published in different algorithms. Paste the published value into Compare and the tool tells you which of the five it matches.

How the hashes are computed

For text, the SHA family is computed by the browser itself through the Web Crypto API (crypto.subtle.digest, and crypto.subtle.sign for HMAC). MD5 is not part of Web Crypto, so it is computed by hash-wasm, a WebAssembly library.

A file is not read into memory at once. A background worker reads it 4 MB at a time and feeds each piece to hash-wasm, which keeps a running state for all five algorithms. That is why a 2 GB file can be hashed without holding all of it in memory, and why you can cancel halfway.

Hash Generator examples

  • Hashes of a short text

    Input

    ZEKILO

    Output

    MD5: f36f86467ce6ba1a1063f6e7019d5e6d
    SHA-1: 42d40f3480e77ccf59395369cc957ec5a2bf7c4b
    SHA-256: f1dfccaf4a395154a1b494c0f0e068765a099f596f3e79934dcc98a2fda67f26
    SHA-512: 788d48bb5f283e6ece352c20c9e7fd494928df4417a90f6cb665709e9fdc3768a37b850f0b1e6608670bc6d8bfe08928acad053b6d4b73a73472ecde8ea2d982
  • Korean text is hashed as UTF-8 bytes

    Input

    제킬로

    Output

    SHA-256: 5cce9ca1ef28cc2a90d7017fbe72bed2c61422c155c1d7ba8e06bacd440e8faf
  • HMAC with the key zekilo-secret

    HMAC is on and the key is zekilo-secret.

    Input

    ZEKILO

    Output

    HMAC-SHA256: 685de252cb7c60a51aedb9b4c14903d26efb4bb2a11c31531f4388f0badc270f
  • A file named abc.txt that contains abc with no line break

    Only the bytes of the file are hashed. The file name is not part of the hash.

    Input

    abc

    Output

    SHA-256: ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad

Examples use the reference cases this tool is tested against.

Hash Generator: frequently asked questions

Is my input sent to a server?

No. Your input and the result are processed only in this browser and are not stored. Reloading the page clears them.

Which algorithm should I use?

Use SHA-256 unless something else is required. MD5 and SHA-1 have known collisions and should not be used for signatures or password storage. Use a dedicated function such as bcrypt, scrypt, or Argon2 to store passwords.

Why is my hash different from the one a command-line tool prints?

The usual cause is a line break. The echo command adds one at the end, and a file saved on Windows may end lines with CRLF. A line break is a byte, so it changes the hash. This tool shows a note when the text ends with a line break.

How large a file can I hash?

Up to 2 GB. A file of up to 100 MB is processed as soon as you open it; above that, press Run. The file is read 4 MB at a time in the background with a progress bar and a Cancel button, so it is never loaded into memory in one piece.

Can a hash be turned back into the original text?

No. A hash keeps no copy of the input and cannot be reversed by calculation. Short or common inputs can still be found by trying candidates one by one, which is why passwords need a slow, salted function.

Is the HMAC key kept anywhere?

No. The key is used only for the calculation in this browser. It is not stored, not put in the page address, and not sent.

How it works · Standards

  • Processed in: this browser (your device). Nothing is sent or stored.
  • Standards: FIPS 180-4 · RFC 1321 · RFC 2104
  • Engine: Web Crypto API (SubtleCrypto digest and sign) (browser built-in) · hash-wasm 4.12.0 (MIT)
  • Empty input is hashed too. The SHA-256 of an empty input is e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855.
  • The file name is shown on this page only. It is not sent, stored, or included in the hash.
  • As of 2026.10.03
  • Changelog: 2026.10.03 First release
Open-source licenses →
Something wrong with the result? Report an issue(Your input is not attached)