Hash generator
Enter a text and the hashes are calculated with four algorithms at once.
0 characters · 0 bytes
Hashes
- SHA-1160 bits
Type something in the field above.
- SHA-256256 bits
Type something in the field above.
- SHA-384384 bits
Type something in the field above.
- SHA-512512 bits
Type something in the field above.
The text never leaves your browser. The hashing uses the browser’s own crypto function.
How it works
A cryptographic hash turns a text of any length into a fixed number of characters. The same text always gives the same hash, while the smallest change gives an entirely different one.
The function only works one way. There is no way to compute the text back from the hash, which is the whole point of it.
Hashes are used to compare files, to detect that something has changed, and as a building block in signatures and certificates.
SHA-1 is no longer considered secure. Since 2017 there have been practical ways to construct two different inputs with the same SHA-1 hash, so use it only to compare against older systems.
Passwords should not be stored with these functions. They are built to be fast, which makes them easy to guess through. Passwords call for deliberately slow functions such as Argon2id, scrypt and PBKDF2. OWASP recommends bcrypt only for legacy systems where neither Argon2id nor scrypt is available.
The text is encoded as UTF-8 before hashing, so accented characters give the same hash here as in any other correct tool.
How the tool works
The text is turned into UTF-8 and passed to the browser’s crypto.subtle.digest, which computes SHA-1, SHA-256, SHA-384 and SHA-512 at once. The hashes are written in lower-case hexadecimal, two characters per byte: 40 characters for SHA-1, 64 for SHA-256, 96 for SHA-384 and 128 for SHA-512. They are recomputed with every character you type.
The same bytes always give the same hash in any correct tool, but the same text can become different bytes. In UTF-8 the £ sign is two bytes, C2 A3, but in the older Latin-1 encoding it is a single byte, A3. A price in pounds therefore hashes differently here than in a program working in Latin-1.
Worked example
abc gives the SHA-256 hash ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad, the same value NIST gives in its test example for the algorithm. If abc is followed by a line break, as the echo command adds, the hash becomes edeaaff3f1774ad2888673770c6d64097e391bc362d7d6fb34982ddf0efd18cb instead. The line break does not show in the text, but the hash is different.
Edge cases
The tool hashes text, not files. The checksum of a downloaded file is computed over the file’s bytes, for example with certutil -hashfile on Windows or sha256sum on Linux. Pasting the file’s contents gives the same hash only if the text is identical byte for byte.
Line endings are the commonest reason for hashes not matching. The HTML Standard requires a text box to turn every line ending into a bare LF, so text from a file with Windows line endings, CR LF, gets a different hash here than in certutil. Spaces at the end of a line and a final line break count too.
On 15 December 2022 NIST announced that SHA-1 is to be phased out by 31 December 2030 and replaced with SHA-2 or SHA-3. Of the functions here, SHA-256, SHA-384 and SHA-512 belong to SHA-2.