Skip to content
Bai
EspañolEnglishEuskara Get started →

Tools

SHA hash generator

SHA and MD5 hash generator

Compute the SHA-1, SHA-256, SHA-512 or MD5 hash of any text in your browser.

Private by design

Algorithms: MD5, SHA-1, SHA-256 and SHA-512 (UTF-8 input, hexadecimal output).

MD5: 128-bit, fast but cryptographically broken. Use it for checksums only.

SHA-1: 160-bit, deprecated for security use.

SHA-256: 256-bit, secure for most applications.

SHA-512: 512-bit, the strongest of the four.

About this tool

A hash function turns any text into a fixed-length fingerprint: change a single letter and the result is completely different. It is useful for checking that two strings are identical without eyeballing them, verifying a webhook signature, generating cache keys, debugging an API that asks for a SHA-256, or finding out what hash a system expects for a given value.

Type or paste into “Text to hash” and, a moment later, you’ll see all four results in hexadecimal: MD5, SHA-1, SHA-256 and SHA-512. Each row has its own copy button. Below them is a short summary of each algorithm’s length and strength to help you pick the right one. The hashes update automatically whenever you change the text.

Hashes are computed in your browser using the crypto-js library; the text never leaves your device, which matters if you’re testing with real data. Text is encoded as UTF-8 before hashing, so results match what you’d get in most programming languages. It accepts text only, not files, and doesn’t compute HMACs or password hashes such as bcrypt.

Frequently asked questions

Can a SHA-256 hash be decrypted?

No. A hash isn’t encryption and can’t be reversed. The only option is to try candidate inputs until one produces the same hash, which is only feasible for short or very common strings.

Which should I use: MD5, SHA-1 or SHA-256?

For anything security-related, SHA-256 or SHA-512. MD5 and SHA-1 have known collisions and are only fit for low-stakes checksums or compatibility with older systems.

Why doesn’t my hash match another program’s?

It is nearly always the input: a trailing newline, extra spaces, different capitalisation or an encoding other than UTF-8. Also check you are comparing hex output rather than Base64.

Can I use this to store passwords?

Not directly. Plain SHA-256 is too fast and vulnerable to dictionary attacks; passwords call for slow, salted algorithms such as bcrypt, scrypt or Argon2.

Related tools