Choose language

Hash Generator

Generate SHA-256, SHA-512, SHA-1, MD5 and CRC32 hashes of text or files, and check a download against its published checksum.

Hash GeneratorHow it works ↓
Hashed as UTF-8 exactly as typed, including spaces and line breaks
Compared with every result, ignoring letter case and extra spaces
Mehmet Demiray Published Updated
Share

What the Hash Generator Does

The Hash Generator computes several hashes of the same input in one pass, so you don't have to know in advance which algorithm a download page or an API used.

  1. Under Input, choose Text to hash what you type or paste into Text to hash, or File to drop a file from your device.
  2. Under Algorithms, pick what to compute. MD5, SHA-1, SHA-256, SHA-384 and SHA-512 are on by default, and CRC32 can be switched on when you need it.
  3. Set the Output format to Hex or Base64. For hex output, Letter case chooses between Lowercase and Uppercase.
  4. Optionally paste a published checksum into Expected checksum.
  5. Press Generate hashes.

The Hashes table shows one row per algorithm with its digest, ready to copy. When you filled in an expected checksum, a Check column marks each row Match or No match, and a headline above the table names the algorithm that matched, for example "The expected checksum matches SHA-256".

A footnote under the table confirms what was hashed: the file name and size, or the size of your text in UTF-8 bytes. That is a quick way to spot a truncated file or an invisible extra character. The results can be exported as CSV, Excel, PDF or an image.

For work that is only about MD5, our dedicated MD5 tools go further: the text to MD5 generator has line ending and trim options plus HMAC-MD5, and the bulk text MD5 tool hashes a whole list of strings at once.

Verifying a Download With a Checksum

Software publishers often list a checksum next to an ISO image, an installer, firmware or a .wasm build. Comparing it with the hash of the file you received tells you whether the download arrived intact.

  1. Copy the checksum from the publisher's page. It is usually labeled SHA-256, sometimes SHA-512, SHA-1 or MD5.
  2. Choose File and drop the downloaded file. A progress bar shows the file being read.
  3. Paste the checksum into Expected checksum. A whole line copied from sha256sum output or a .sha256 file also works, because only the first token is used.
  4. Press Generate hashes and look for the Match row.

If one row says Match, your file is identical, byte for byte, to the file the checksum was made from. If every row says No match, the file differs or the checksum belongs to another file or version.

A single changed byte produces a completely different hash. This is called the avalanche effect: the SHA-256 of hello is 2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824, while Hello with a capital H gives 185f8db32271fe25f561a6fc938b2e264306ec304eda518007d1764826381969. No partial similarity survives, so you can trust a match and you cannot "almost" match.

Know what a match proves. A checksum published on the same server as the file only shows that the download was not damaged on the way. If an attacker controls that server, they can replace both. A checksum file signed with the publisher's PGP key, or one listed on a separate trusted site, goes further. A match never proves a file is free of malware, only that it is the same file the publisher hashed.

On the command line the equivalents are sha256sum on Linux, certutil -hashfile on Windows and shasum -a 256 on macOS.

Which Hash Algorithm to Choose

All six algorithms turn any input into a fixed length digest, but they differ in length and in how well they resist deliberate attacks.

Algorithm Output Hex characters Status
MD5 128 bits 32 Collisions are practical (RFC 6151); integrity checks only
SHA-1 160 bits 40 Collisions demonstrated; retired by NIST
SHA-256 256 bits 64 Current standard (FIPS 180-4)
SHA-384 384 bits 96 Current standard (FIPS 180-4)
SHA-512 512 bits 128 Current standard (FIPS 180-4)
CRC32 32 bits 8 Error detection code, not a cryptographic hash

A collision means two different inputs with the same digest. For MD5 and SHA-1, researchers can produce such pairs on purpose, which breaks any use where an attacker chooses the input: digital signatures, certificates, or proving that a file has not been swapped.

The practical rule:

  • Accidental corruption (a broken download, a bad copy, a flaky disk): any algorithm works, including MD5 and CRC32. Use whatever the publisher listed.
  • Anything an attacker could tamper with: use SHA-256 or stronger. SHA-256 is the safe default and by far the most widely published checksum today.
  • New systems: pick SHA-256 or SHA-512, never MD5 or SHA-1.

CRC32 is the checksum inside zip, gzip and PNG files. It is fast and catches transmission errors well, but anyone can craft data with a chosen CRC32 value, so it is off by default here.

When a download page lists only MD5, that is fine for spotting damage. For MD5 of a single file with an HMAC key, the file MD5 tool is the better fit.

Hashing Is Not Encryption

Encryption is two-way: data is locked with a key and can be unlocked with the right key. A hash is one-way. It has no key, its output has a fixed length no matter how large the input is, and there is nothing to decrypt. A 1 GB ISO image and a single word both give a SHA-256 digest of 64 hex characters.

That does not make every hash secret. Short or common inputs can be found by guessing: an attacker hashes millions of likely words and passwords and compares the results, or looks the digest up in a precomputed table. The MD5 of hello is 5d41402abc4b2a76b9719d911017c592, and searching for that string online reveals the input in seconds. Nothing was reversed; the answer was simply guessed or already listed.

This is why passwords must not be stored as plain SHA-256 or MD5 hashes. Both algorithms are built to be fast, and fast is exactly what a password guesser wants. Password storage needs a deliberately slow, salted algorithm such as bcrypt, scrypt or Argon2. The salt is a random value stored with each hash, so two users with the same password get different hashes and precomputed tables become useless.

General purpose hashes like the ones on this page are right for:

  • file and download checksums
  • detecting duplicate files or changed content
  • cache keys and ETags
  • checking test vectors when you implement or debug an algorithm

Why Your Hash Might Not Match

A hash depends on the exact bytes of the input. Two texts that look the same on screen can produce completely different digests.

The usual causes:

  • A trailing newline. Many command line examples hash text with a line break at the end. echo hello | sha256sum hashes hello plus a newline and gives 5891b5b522d5df086d0ff0b110fbd9d21bb4fc7163af34d08286a2e846f6be03, while this tool hashes exactly hello and gives 2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824.
  • Spaces. A leading or trailing space copied by accident changes everything.
  • Line endings. Windows uses a carriage return plus line feed, Unix and macOS only a line feed. Multi-line text pasted from different sources can differ here.
  • Text encoding. This tool always encodes text as UTF-8. Another tool using UTF-16 or Latin-1 gives a different result for any character outside basic ASCII, such as é or ü.
  • Wrong algorithm. Comparing an SHA-256 checksum with an SHA-512 result never matches. With every algorithm enabled, the Check column shows which one fits.
  • Incomplete file. An interrupted download hashes differently. Compare the size in the footnote with the size the publisher lists.

The Hash Generator never trims or normalizes your text, so what you type is what gets hashed. The Input size footnote shows the byte count, which reveals an invisible extra character.

Letter case in hex output does not matter: ABC123 and abc123 are the same value, and the Expected checksum comparison ignores case for hex. Base64 is different, because upper and lower case letters are distinct digits there, so a Base64 checksum has to match exactly.

If you need MD5 with a choice of line endings or trimming, the text to MD5 generator has those options.

Private, Free File Hashing in Your Browser

Your file is never uploaded. The Hash Generator reads it from your disk into the browser tab and hashes it there, using the browser's built-in Web Crypto API for the SHA algorithms. No copy reaches a server, which matters when the file is a contract, a database dump or an unreleased build. Once the page has loaded, hashing works even without an internet connection.

Files can be up to 1 GB. The limit exists because Web Crypto has no streaming mode: the whole file has to sit in memory as one block before it can be hashed. That covers typical installers and most ISO images on a desktop computer. On phones and tablets with less memory, very large files may still fail, and the tool then suggests trying a smaller one. For bigger files, the command line tools sha256sum, certutil and shasum read in chunks and have no such ceiling.

The tool is free, needs no account and has no daily limit or size-based paywall. You can hash as many files and texts as you like.

To hash many files at once, the bulk file MD5 tool computes MD5 checksums for a whole batch, useful when comparing a folder before and after a copy.

The ones we answer the most.

How do I generate a SHA-256 hash?

Choose Text and type or paste your text, or choose File and drop a file, keep SHA-256 selected under Algorithms, and press Generate hashes. The SHA-256 row shows a digest of 64 hex characters, or 44 characters in Base64.

How do I verify a downloaded file's checksum?

Choose File, drop the downloaded file, paste the publisher's checksum into Expected checksum and press Generate hashes. A Match row means the file is identical to the one the checksum was made from. A line copied straight from sha256sum output works too.

What is the difference between MD5, SHA-1 and SHA-256?

Output length and resistance to attacks. MD5 gives 128 bits, SHA-1 160 bits and SHA-256 256 bits. Collisions can be produced on purpose for MD5 and SHA-1, but not for SHA-256, which makes SHA-256 the safe default.

Is MD5 or SHA-1 still safe to use?

For catching accidental corruption, yes. A damaged download will not match its MD5 or SHA-1 checksum. For signatures, certificates, password storage or any input an attacker can choose, no: use SHA-256 or stronger. For MD5-specific tasks such as HMAC-MD5 or hashing many files, see the file MD5 tool and the bulk file MD5 tool.

Can a hash be decrypted back to the original text?

No. Hashing is not encryption: there is no key and the original data is not stored in the digest. Short or common inputs can still be found by guessing and comparing hashes, which is why passwords need a slow, salted algorithm such as bcrypt or Argon2.

Should I use hex or Base64 output?

Use hex for checksums, since almost every download page and command line tool publishes them that way. Base64 is shorter and appears in Subresource Integrity attributes and some APIs. Both encode the same digest bytes.

Why doesn't my hash match the published one?

The most common reasons are a different algorithm, an incomplete or wrong file version, or, for text, an extra space or trailing newline. This tool hashes text as UTF-8 exactly as typed. With all algorithms enabled, the Check column shows whether any of them match.

Does uppercase or lowercase matter in a hash?

Not for hex. A1B2 and a1b2 are the same value, and the expected checksum comparison ignores case and surrounding spaces. Base64 is case-sensitive, so a Base64 checksum must match exactly.

Is there a file size limit?

Yes, 1 GB. The browser's Web Crypto API needs the whole file in memory at once, so larger files could crash the tab. On phones, files well below the limit may still fail if memory is short.

SHA-256 or SHA-512: which is better?

Both are secure members of the SHA-2 family. SHA-512 gives a longer digest and often runs faster on 64-bit processors. SHA-256 is the most widely published checksum, so it is the one to use when you need to compare with others.

Is the Hash Generator free, and is my file uploaded?

It is free and needs no sign up. Files and text are hashed locally in your browser and never uploaded or stored.

References

  1. FIPS 180-4: Secure Hash Standard (SHS) · NIST
  2. RFC 1321: The MD5 Message-Digest Algorithm · IETF
  3. RFC 6234: US Secure Hash Algorithms (SHA and SHA-based HMAC and HKDF) · IETF
  4. RFC 6151: Updated Security Considerations for the MD5 Message-Digest and the HMAC-MD5 Algorithms · IETF
  5. NIST Transitioning the Use of Cryptographic Algorithms and Key Lengths (SP 800-131A Rev. 2) · NIST
  6. NIST Retires SHA-1 Cryptographic Algorithm · NIST
  7. SubtleCrypto: digest() method · MDN Web Docs