Hash Generator
Get the MD5, SHA-256 or any of twelve other hashes of a text or a file — several at once — and check a download against the checksum its publisher lists.
- 12 algorithms
- Files up to 4 GB
- Checksum compare
- No upload
Drop files here
or
Any file type, up to 4 GB each, 20 files at a time
Files are read on your device and are never uploaded.
With a key, a keyed hash (HMAC) is calculated instead. The key is not stored.
Hashes
Enter text or add a file to see its hashes.
How to generate a hash
Text or file, same steps.
- 1
Enter text or add files
Type or paste text, or switch to Files and drop one or several files of any type.
- 2
Choose the algorithms
Tick as many as you need; all of them are calculated in one pass.
- 3
Copy or compare
Copy a hash, or paste the expected checksum to see instantly whether it matches.
Checksums without the command line
The same values sha256sum, certutil or openssl would print.
Twelve algorithms at once
From legacy MD5 and SHA-1 through the SHA-2 and SHA-3 families to fast modern BLAKE3 and xxHash64.
Large files, small memory
Files are read in 8 MB pieces, so a multi-gigabyte ISO image is hashed without loading it into memory.
Compare with one paste
Paste the checksum from the download page; the matching hash lights up green, in any algorithm you ticked.
HMAC
Add a secret key to get a keyed hash, as used for webhook signatures and API authentication.
Checksum files
Hash several files and save the list in the standard “hash filename” format of sha256sum.
WebAssembly speed
Hashing runs in compiled WebAssembly code — several hundred megabytes per second on a current laptop.
Private by design
Everything runs in your browser. What you type or open is not sent to a server.
Free, no sign-up
No account, no limits, no watermark — on a phone, tablet or computer.
What a hash is and which one to use
A hash function turns any input — one letter or a 4 GB file — into a short, fixed-length fingerprint. The same input always gives the same hash, the tiniest change gives a completely different one, and the function cannot be run backwards to recover the input. That makes hashes ideal for checking that a download arrived intact, detecting duplicates and signing data.
Not all algorithms are equally safe. MD5 and SHA-1 are broken for security purposes: attackers can construct two different files with the same hash. They are still fine for spotting accidental corruption or matching old checksum lists, but anything security-related should use SHA-256 or stronger. CRC32 and xxHash are checksums built for speed, not for security.
For passwords, none of these fast hashes is appropriate on its own: precisely because they are fast, billions of guesses per second are possible. Password storage needs deliberately slow, salted algorithms such as Argon2, scrypt or bcrypt. An HMAC combines a hash with a secret key and proves that a message comes from someone who knows the key — the mechanism behind most webhook signatures.
Common algorithms
| Algorithm | Hash length | Use it for |
|---|---|---|
| MD5 | 128 bit (32 hex characters) | Legacy checksums only — not secure |
| SHA-1 | 160 bit (40 hex characters) | Git object IDs, legacy systems — not secure |
| SHA-256 | 256 bit (64 hex characters) | Download verification, signatures, the general default |
| SHA-512 | 512 bit (128 hex characters) | As SHA-256 with a larger margin; fast on 64-bit CPUs |
| BLAKE3 | 256 bit (64 hex characters) | Very fast modern hashing of large data |
| CRC32 | 32 bit (8 hex characters) | Error detection in ZIP, PNG and networks |
Tips
- Need a random unique ID instead of a fingerprint? Use the UUID Generator.
- Convert a hash between hex and Base64 with the Base64 Encoder.
- Verify an HMAC-signed token with the JWT Decoder.
- When verifying a download, take the checksum from the publisher’s own HTTPS site — a checksum from the same mirror as the file proves nothing.
Frequently asked questions
Can’t find your answer? Contact us — we reply quickly.
Are my files uploaded to calculate the hash?
No. The file is read by your browser and hashed on your device with WebAssembly. Nothing is sent to a server, which is also why it works with very large and confidential files.
How do I verify a downloaded file?
Switch to Files, drop the file, and paste the checksum published by the software vendor into “Compare with a known hash”. A green match means the file is identical to the original.
Can a hash be decrypted?
No. Hashing is one-way; there is no key that turns a hash back into the input. Short or common inputs can only be found by guessing and comparing, which is why unsalted password hashes are unsafe.
Is MD5 still safe?
Not for security. Collisions can be produced in seconds, so MD5 must not be used for signatures, certificates or passwords. It remains acceptable for detecting accidental file corruption.
What is the difference between a hash and an HMAC?
A plain hash can be computed by anyone. An HMAC mixes a secret key into the calculation, so only someone who knows the key can produce or verify it — it proves both integrity and origin.
Why does my hash differ from another tool’s?
Usually because the input differs invisibly: a trailing line break, Windows versus Unix line endings, or a different text encoding. This tool hashes text as UTF-8 exactly as entered.
More free developer tools
Encode, format, test, convert and generate — small tools that run in your browser and keep your data on your device.