Security Tools

Hash Identifier

Found a hash in a database, a config file or a log and need to know what it is? Paste it, and the identifier recognises structured formats such as bcrypt, Argon2, scrypt, SHA-crypt, phpass and Django PBKDF2 with certainty, and lists the likely algorithms for plain hexadecimal or Base64 hashes by length, with a note on how secure each is.

  • Runs in your browser
  • No sign-up
  • Free to use

Analysed in your browser. Nothing is sent.

Possible hash types
Possible typeLikelihoodNotes

How to use Hash Identifier

  1. Paste the hash.
  2. Read the possible types and how likely each is.
  3. Check the notes on security and parameters.
  4. Use the matching tool to generate or verify the hash.

Hash Identifier features

Structured formats

bcrypt, Argon2, scrypt, SHA-crypt, MD5-crypt, APR1, phpass, Django, passlib, LDAP, MySQL.

Parameters

Shows cost factors, iterations and memory settings.

Plain hashes

MD5, SHA-1, SHA-2, SHA-3 and others by length.

Base64 digests

Recognises encoded digests by decoded size.

Security notes

Explains which algorithms are weak.

Private

Nothing is sent anywhere.

When to use Hash Identifier

  • Auditing how an application stores passwords.
  • Migrating users between systems with different hash formats.
  • Understanding a checksum in a download page or API.
  • Learning to recognise hash formats.

Hash Identifier FAQ

Can the tool tell MD5 from NTLM?

Not with certainty: both are 32 hexadecimal characters. Context decides, such as a Windows system for NTLM. The tool lists both with likelihoods.

Why is bcrypt identified for certain?

Its format includes a marker ($2b$), the cost and a fixed length, which no other format shares.

Does identifying a hash reveal the password?

No. Identification only tells you the algorithm. Hashes cannot be reversed; weak ones can only be attacked by guessing.

Which password hashes are considered secure?

Argon2id, bcrypt and scrypt with appropriate parameters, and PBKDF2 with many iterations. Plain MD5, SHA-1 or SHA-256 are not suitable for passwords.

Is the hash sent anywhere?

No. Everything happens in your browser.

What if nothing matches?

The value may be truncated, encoded in an unusual way, or not a hash at all. Check that the whole value was copied.

Reading a hash like a label

Many hashes carry their own label. Modern password hashes use the modular crypt format: a dollar sign, an identifier, parameters and the salted hash, as in “$2b$12$…” for bcrypt with cost 12. Framework formats such as Django’s “pbkdf2_sha256$…” do the same. These can be identified with certainty, and their parameters tell you how strong the storage is.

Plain digests carry no label. A 64-character hexadecimal string is most likely SHA-256, but SHA3-256 and BLAKE2s produce the same length. Here the identifier can only rank candidates by how common they are. Context, the system the hash came from, usually settles it.

Identification has practical uses. Security reviews check that passwords are stored with a slow, salted algorithm and that work factors are adequate. Migrations need to know the old format so that users can be upgraded at their next login. Developers meeting a checksum in an API want to know which function to call.

If a password database uses unsalted MD5 or SHA-1, it should be upgraded: rehash each password with Argon2id or bcrypt when the user next logs in, or wrap the old hashes in a modern algorithm immediately. Identifying the format is the first step.

Other useful tools