Hash Generator
Type text or open a file to see five hashes at once. Everything is computed in this browser.
Stays in your browserFIPS 180-4RFC 1321RFC 2104As of 2026.10.03
Input
Output
| MD5 | —Known collisions. Not for security use. | |
|---|---|---|
| SHA-1 | —Known collisions. Not for security use. | |
| SHA-256 | — | |
| SHA-384 | — | |
| SHA-512 | — |
How to use Hash Generator
- 1Type or paste text into the input panel, or press Open file. You can also drop a file onto the card.
- 2Choose the output format (hex or Base64). Turn on HMAC and type a key if you need a keyed hash.
- 3Press the copy button on a row to copy that hash, or open Compare and paste an expected hash to check it.
Hash Generator options
- Input type
- Text is encoded as UTF-8 before it is hashed. File hashes the bytes of the file exactly as they are, up to 2 GB.
- Output
- hex in lowercase (default), HEX in uppercase, or Base64.
- HMAC
- Computes a keyed hash with the key you type. The key is read as UTF-8 and is not stored.
- Compare
- Paste an expected hash to see whether it matches one of the five results. Letter case and surrounding spaces are ignored.
Standards
SHA-1, SHA-256, SHA-384, and SHA-512 are defined in FIPS 180-4, MD5 in RFC 1321, and HMAC in RFC 2104. A hash is computed over bytes, not characters. Text is turned into bytes with UTF-8 first, so the same text always gives the same hash here and in any other tool that uses UTF-8.
All five results are shown together because checksums are published in different algorithms. Paste the published value into Compare and the tool tells you which of the five it matches.
How the hashes are computed
For text, the SHA family is computed by the browser itself through the Web Crypto API (crypto.subtle.digest, and crypto.subtle.sign for HMAC). MD5 is not part of Web Crypto, so it is computed by hash-wasm, a WebAssembly library.
A file is not read into memory at once. A background worker reads it 4 MB at a time and feeds each piece to hash-wasm, which keeps a running state for all five algorithms. That is why a 2 GB file can be hashed without holding all of it in memory, and why you can cancel halfway.
Hash Generator examples
Hashes of a short text
Input
ZEKILO
Output
MD5: f36f86467ce6ba1a1063f6e7019d5e6d SHA-1: 42d40f3480e77ccf59395369cc957ec5a2bf7c4b SHA-256: f1dfccaf4a395154a1b494c0f0e068765a099f596f3e79934dcc98a2fda67f26 SHA-512: 788d48bb5f283e6ece352c20c9e7fd494928df4417a90f6cb665709e9fdc3768a37b850f0b1e6608670bc6d8bfe08928acad053b6d4b73a73472ecde8ea2d982
Korean text is hashed as UTF-8 bytes
Input
제킬로
Output
SHA-256: 5cce9ca1ef28cc2a90d7017fbe72bed2c61422c155c1d7ba8e06bacd440e8faf
HMAC with the key zekilo-secret
HMAC is on and the key is zekilo-secret.
Input
ZEKILO
Output
HMAC-SHA256: 685de252cb7c60a51aedb9b4c14903d26efb4bb2a11c31531f4388f0badc270f
A file named abc.txt that contains abc with no line break
Only the bytes of the file are hashed. The file name is not part of the hash.
Input
abc
Output
SHA-256: ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad
Examples use the reference cases this tool is tested against.
Hash Generator: frequently asked questions
Is my input sent to a server?
No. Your input and the result are processed only in this browser and are not stored. Reloading the page clears them.
Which algorithm should I use?
Use SHA-256 unless something else is required. MD5 and SHA-1 have known collisions and should not be used for signatures or password storage. Use a dedicated function such as bcrypt, scrypt, or Argon2 to store passwords.
Why is my hash different from the one a command-line tool prints?
The usual cause is a line break. The echo command adds one at the end, and a file saved on Windows may end lines with CRLF. A line break is a byte, so it changes the hash. This tool shows a note when the text ends with a line break.
How large a file can I hash?
Up to 2 GB. A file of up to 100 MB is processed as soon as you open it; above that, press Run. The file is read 4 MB at a time in the background with a progress bar and a Cancel button, so it is never loaded into memory in one piece.
Can a hash be turned back into the original text?
No. A hash keeps no copy of the input and cannot be reversed by calculation. Short or common inputs can still be found by trying candidates one by one, which is why passwords need a slow, salted function.
Is the HMAC key kept anywhere?
No. The key is used only for the calculation in this browser. It is not stored, not put in the page address, and not sent.
Related tools
How it works · Standards
- Processed in: this browser (your device). Nothing is sent or stored.
- Standards: FIPS 180-4 · RFC 1321 · RFC 2104
- Engine: Web Crypto API (SubtleCrypto digest and sign) (browser built-in) · hash-wasm 4.12.0 (MIT)
- Empty input is hashed too. The SHA-256 of an empty input is e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855.
- The file name is shown on this page only. It is not sent, stored, or included in the hash.
- As of 2026.10.03
- Changelog: 2026.10.03 First release