Hash Generator
Compute cryptographic hashes of text or any file, all at once. Paste an expected checksum to verify a download, or add a secret key to calculate an HMAC.
- Runs in your browser
- No sign-up
- Free to use
| Algorithm | Hash | Copy |
|---|
How to use Hash Generator
- Type text into the box, or choose Hash a file to select a file from your device.
- All hashes are calculated immediately and shown side by side.
- To verify a download, paste the published checksum into the Compare field; a matching hash is highlighted.
- Optionally enter a secret key to get HMAC values instead of plain hashes.
Hash Generator features
Five algorithms at once
MD5, SHA-1, SHA-256, SHA-384 and SHA-512.
Text or files
Hash typed text as UTF-8, or files of any type up to 2 GB.
Checksum comparison
Paste an expected value and see instantly whether it matches any algorithm.
HMAC mode
Keyed hashes for verifying API signatures and webhooks.
Hex or Base64 output
Switch the encoding to match the format you are comparing against.
Private
Files and text are hashed in your browser and never uploaded.
When to use Hash Generator
- Verifying that a downloaded installer or ISO image matches the publisher's checksum.
- Checking a webhook or API request signature during development.
- Detecting whether two files are identical without comparing them byte by byte.
- Generating fixed identifiers or cache keys from content.
Hash Generator FAQ
What is a hash?
A hash function turns input of any size into a fixed-length fingerprint. The same input always gives the same hash, and changing even one bit of the input gives a completely different result.
Which algorithm should I use?
Use SHA-256 or SHA-512 for anything security-related. MD5 and SHA-1 are broken for security purposes because collisions can be manufactured, though they are still used for simple integrity checks against accidental corruption.
Can I use these hashes to store passwords?
No. General-purpose hashes are designed to be fast, which makes guessing passwords fast too. Store passwords with a slow, salted algorithm such as Argon2, bcrypt or scrypt.
Why does my hash differ from another tool?
Check that the input is byte-for-byte identical. Trailing newlines, different line endings (Windows CRLF versus Unix LF) and text encoding all change the hash.
What is HMAC?
A hash-based message authentication code combines a secret key with the message. Only someone with the key can produce the same value, which is why APIs use it to sign requests.
Hashes, checksums and signatures
Cryptographic hash functions have three essential properties: it is easy to compute the hash of any input, infeasible to find an input that produces a given hash, and infeasible to find two inputs with the same hash. Those properties let a short hash stand in for a large file. If the hash of your download matches the one the publisher lists, the file is intact.
For that guarantee to mean anything, the checksum must come from a trustworthy source, ideally a different channel from the download itself. An attacker who can replace the file can usually replace a checksum published next to it. That is why software is increasingly signed with digital signatures, which build on hashes but depend on a key only the publisher holds.