Hash Generator

Get the MD5, SHA-256 or any of twelve other hashes of a text or a file — several at once — and check a download against the checksum its publisher lists.

  • 12 algorithms
  • Files up to 4 GB
  • Checksum compare
  • No upload
Source

Drop files here

or

Any file type, up to 4 GB each, 20 files at a time

Files are read on your device and are never uploaded.

Algorithms
Output

With a key, a keyed hash (HMAC) is calculated instead. The key is not stored.

Hashes

Enter text or add a file to see its hashes.

How it works

How to generate a hash

Text or file, same steps.

  1. 1

    Enter text or add files

    Type or paste text, or switch to Files and drop one or several files of any type.

  2. 2

    Choose the algorithms

    Tick as many as you need; all of them are calculated in one pass.

  3. 3

    Copy or compare

    Copy a hash, or paste the expected checksum to see instantly whether it matches.

Why ToolCMB

Checksums without the command line

The same values sha256sum, certutil or openssl would print.

Twelve algorithms at once

From legacy MD5 and SHA-1 through the SHA-2 and SHA-3 families to fast modern BLAKE3 and xxHash64.

Large files, small memory

Files are read in 8 MB pieces, so a multi-gigabyte ISO image is hashed without loading it into memory.

Compare with one paste

Paste the checksum from the download page; the matching hash lights up green, in any algorithm you ticked.

HMAC

Add a secret key to get a keyed hash, as used for webhook signatures and API authentication.

Checksum files

Hash several files and save the list in the standard “hash filename” format of sha256sum.

WebAssembly speed

Hashing runs in compiled WebAssembly code — several hundred megabytes per second on a current laptop.

Private by design

Everything runs in your browser. What you type or open is not sent to a server.

Free, no sign-up

No account, no limits, no watermark — on a phone, tablet or computer.

What a hash is and which one to use

A hash function turns any input — one letter or a 4 GB file — into a short, fixed-length fingerprint. The same input always gives the same hash, the tiniest change gives a completely different one, and the function cannot be run backwards to recover the input. That makes hashes ideal for checking that a download arrived intact, detecting duplicates and signing data.

Not all algorithms are equally safe. MD5 and SHA-1 are broken for security purposes: attackers can construct two different files with the same hash. They are still fine for spotting accidental corruption or matching old checksum lists, but anything security-related should use SHA-256 or stronger. CRC32 and xxHash are checksums built for speed, not for security.

For passwords, none of these fast hashes is appropriate on its own: precisely because they are fast, billions of guesses per second are possible. Password storage needs deliberately slow, salted algorithms such as Argon2, scrypt or bcrypt. An HMAC combines a hash with a secret key and proves that a message comes from someone who knows the key — the mechanism behind most webhook signatures.

Common algorithms

AlgorithmHash lengthUse it for
MD5128 bit (32 hex characters)Legacy checksums only — not secure
SHA-1160 bit (40 hex characters)Git object IDs, legacy systems — not secure
SHA-256256 bit (64 hex characters)Download verification, signatures, the general default
SHA-512512 bit (128 hex characters)As SHA-256 with a larger margin; fast on 64-bit CPUs
BLAKE3256 bit (64 hex characters)Very fast modern hashing of large data
CRC3232 bit (8 hex characters)Error detection in ZIP, PNG and networks

Tips

  • Need a random unique ID instead of a fingerprint? Use the UUID Generator.
  • Convert a hash between hex and Base64 with the Base64 Encoder.
  • Verify an HMAC-signed token with the JWT Decoder.
  • When verifying a download, take the checksum from the publisher’s own HTTPS site — a checksum from the same mirror as the file proves nothing.
FAQ

Frequently asked questions

Can’t find your answer? Contact us — we reply quickly.

Are my files uploaded to calculate the hash?

No. The file is read by your browser and hashed on your device with WebAssembly. Nothing is sent to a server, which is also why it works with very large and confidential files.

How do I verify a downloaded file?

Switch to Files, drop the file, and paste the checksum published by the software vendor into “Compare with a known hash”. A green match means the file is identical to the original.

Can a hash be decrypted?

No. Hashing is one-way; there is no key that turns a hash back into the input. Short or common inputs can only be found by guessing and comparing, which is why unsalted password hashes are unsafe.

Is MD5 still safe?

Not for security. Collisions can be produced in seconds, so MD5 must not be used for signatures, certificates or passwords. It remains acceptable for detecting accidental file corruption.

What is the difference between a hash and an HMAC?

A plain hash can be computed by anyone. An HMAC mixes a secret key into the calculation, so only someone who knows the key can produce or verify it — it proves both integrity and origin.

Why does my hash differ from another tool’s?

Usually because the input differs invisibly: a trailing line break, Windows versus Unix line endings, or a different text encoding. This tool hashes text as UTF-8 exactly as entered.

More free developer tools

Encode, format, test, convert and generate — small tools that run in your browser and keep your data on your device.

Browse all tools