Hash Generator
MD5, SHA-1, SHA-256, SHA-512 and CRC-32 of any text, computed in your browser.
Runs entirely in your browser. Nothing is uploaded, logged or stored.
A hash turns any amount of text into a short fixed-length fingerprint. The same input always gives the same digest, and changing one character anywhere changes the whole thing — which is what makes it useful for telling whether two things are identical without comparing them side by side.
How it works
The text is encoded as UTF-8 first, then hashed over those bytes. That matters for anything above ASCII: é is two bytes, so its digest is not the digest of a one-byte é in some other encoding. Two tools disagreeing about an accented string almost always disagree about this and not about the algorithm.
Everything is computed here, in the page. The five algorithms are written out rather than taken from the browser's crypto API, for three reasons: that API is unavailable over plain HTTP, it refuses to do MD5 at all, and it is asynchronous where the rest of these tools are not.
Digests are shown in lower-case hexadecimal, which is what command line tools print. The upper-case switch is there because some systems store them the other way and comparing across the two by eye is a good way to see a difference that is not there.
Examples
| Case | Input | Result |
|---|---|---|
| SHA-256 of a short string | hello | 2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824 |
| MD5 of the same string | hello | 5d41402abc4b2a76b9719d911017c592 |
| One character different, and nothing survives | hellp | d0763edaa9d9bd2a9516280e9044d885 |
Frequently asked questions
Can I get the original text back from a hash?
No, and no tool can. A hash is not encryption: the information is gone, and a digest of one character and a digest of a novel are the same length. Sites offering to "decrypt" a hash are looking it up in a table of digests somebody has already computed from common passwords — which works only for inputs that were on that list.
Should I hash a password with this?
No. Passwords need an algorithm designed to be slow — bcrypt, scrypt or Argon2 — with a random salt for each one, computed on your server. These five are fast, which is exactly the wrong property: a graphics card will try billions of MD5 candidates a second. Nothing you type here leaves your browser, but the result would still be the wrong thing to store.
What does "broken" mean for MD5 and SHA-1?
That someone can deliberately construct two different inputs with the same digest, which has been demonstrated for both. So neither can prove a file is the one you were promised, if somebody had a reason to substitute it. Both are still perfectly good for what they are mostly used for: noticing that a download arrived corrupted, or that two files are copies.
Why does my digest differ from another tool's?
Almost always a trailing newline or a different character encoding. Hashing a file that ends in a newline is not the same as hashing the text without it, and every byte counts. This tool hashes exactly the characters in the box, encoded as UTF-8, and nothing else.
Good to know
- Everything happens in your browser. What you paste is not uploaded, not logged and not stored.