Tools

Hash Generator (MD5, SHA-256, SHA-512)

Create MD5, SHA-1, SHA-256 and SHA-512 hashes of text or files right in your browser, verify a download against its published checksum and compare two hashes. Nothing is uploaded, and there is no file size limit.

Text and files are processed in your browser; nothing is uploaded.
0 characters · 0 bytes
Encoding
Line endings
Trailing newline
Browsers keep line breaks as LF. Pick CRLF to match a Windows file, and add a trailing newline to match the output of echo.

MD5 and SHA-1 are open to collisions; use SHA-256 to verify files. Hashing alone is not enough to store passwords: use Argon2id or bcrypt. Need a strong password? Try the password generator.

Result

Result Output format

Empty text, 0 bytes: these are the hashes of an empty input.

Written by
  • Digital Marketing Expert
  • Google Partner
  • Full Stack Developer
Last updated
Based on
5 sources

How to use the Hash Generator (MD5, SHA-256, SHA-512)

  1. Pick a mode

    Use the strip at the top to switch between Text, File and Verify. Text mode hashes as you type; File mode reads the files you choose in small chunks.

  2. Type the text or choose files

    Then paste text into the box, or drag and drop one or more files. Files never leave your device, and there is no size limit.

  3. Set the algorithm and options

    In File mode, tick MD5, SHA-1, SHA-256 or SHA-512. In Text mode, the encoding and line ending options change the bytes. So match them to your source.

  4. Copy or compare the result

    Next, copy one hash with its row button or all of them with the bar below. In Verify mode, paste the expected value; the tool then says Match or No match.

  5. Use the command line if you need it

    Below the result, the tool also shows matching commands for Windows, PowerShell, macOS and Linux. For several files, you can download a SHA256SUMS style list.

Algorithms and output lengths

The tool runs all four algorithms on the same bytes. It also recognises an algorithm by its output length, so the length of an expected value is a clue for you too.

MD5128 bits = 16 bytes = 32 hex characters
SHA-1160 bits = 20 bytes = 40 hex characters
SHA-256256 bits = 32 bytes = 64 hex characters
SHA-512512 bits = 64 bytes = 128 hex characters
Base64 length4 × round up(bytes ÷ 3): 24, 28, 44 and 88 characters
Match ruleletter case and spaces are ignored; identical bytes give Match

One hex character carries 4 bits, which is why a 128 bit MD5 digest is 32 characters long. Base64 writes the same bytes more compactly and may end with = padding.

Example hash values

Enter these inputs with the same settings and you will see exactly the same result. The first row is the standard test input from RFC 1321 and the FIPS 180 examples.

InputSettingMD5SHA-256 (first 16 characters)Note
abcUTF-8900150983cd24fb0d6963f7d28e17f72ba7816bf8f01cfeastandard test input
hellono trailing newline5d41402abc4b2a76b9719d911017c5922cf24dba5fb0a30esame as printf
hellotrailing newlineb1946ac92492d2347c6235b4d26111845891b5b522d5df08output of echo; one byte changes everything
caféUTF-8, 5 bytes07117fe4a1ebd544965dc19573183da2850f7dc43910ff89modern systems
caféWindows-1252, 4 bytes961f50f6282239d09e48f812c1ca7276dafd66c0b98965e6older Windows software
empty text0 bytesd41d8cd98f00b204e9800998ecf8427ee3b0c44298fc1c14also the hash of an empty file

The table shows only the first 16 characters of each SHA-256 value; type the input into the tool to see the full digest.

Which algorithm for which job?

The right choice depends on the job. Checking that a download arrived intact and storing a password safely are two very different needs.

AlgorithmOutputCollision statusGood forNot for
MD532 hexpractical collisions since 2004legacy compatibility, spotting accidental corruptionsignatures, certificates, passwords
SHA-140 hexfirst practical collision in 2017; NIST phases it out by the end of 2030backward compatibilitynew signatures and security designs
SHA-25664 hexno known practical collisiondownload checks, signatures, DKIMstoring passwords on its own
SHA-512128 hexno known practical collisionsystems that want a longer digeststoring passwords on its own
Argon2id, bcryptconfigurablebuilt for password storagestoring passwordsfile checks (slow on purpose)

Collision facts follow RFC 6151, the SHAttered research and the NIST announcement of December 2022.

What does this hash generator do?

This hash generator turns any text or file into a short, fixed length fingerprint. People call that fingerprint a hash, digest or checksum. It looks like a string of hexadecimal characters: 32 for MD5, 64 for SHA-256. Whether the input is one letter or a 5 GB disk image, the output length stays the same. Change a single character, however, and almost the whole hash changes.

We use hashes for three everyday jobs:

  • Integrity checks: you find out whether a download arrived intact.
  • Duplicate detection: two files with identical content give the same hash, even under different names.
  • Change tracking: one line tells you whether a configuration file changed since yesterday.

The tool computes MD5, SHA-1, SHA-256 and SHA-512 side by side, entirely in your browser. The built in Web Crypto API cannot do this job alone. According to MDN, its digest method offers no MD5 and needs the whole input in memory. Instead, our own code reads large files in 4 MB chunks, so there is no size limit. Our team uses this check most at launch time. It confirms that the file on the server matches the one on our machine.

MD5, SHA-1, SHA-256 or SHA-512: which one should you use?

All four do the same kind of work; they differ in output length and safety margin. Ronald Rivest published MD5 in 1992 in RFC 1321, and it produces 128 bits. SHA-1 gives 160 bits, SHA-256 gives 256 and SHA-512 gives 512. The current definition of the SHA family lives in the NIST standard FIPS 180-4.

A longer digest makes collisions harder to find. In other words, it gets harder to find two different inputs with the same hash. Put simply, random trial needs about 2^(n/2) attempts to find a collision in an n bit hash. Cryptographers call this the birthday bound.

  • MD5 and SHA-1: fast and still everywhere, but practical collisions exist for both.
  • SHA-256: the default today for download checks, TLS certificates and email signatures.
  • SHA-512: a longer digest with an even larger safety margin.

Our rule of thumb is simple: use SHA-256 for anything new. Choose MD5 only when the other side publishes nothing else, or when an old system demands it. Curious which algorithm signed your own certificate? The SSL checker shows it; on a current certificate you should see SHA-256 or something stronger.

How to verify a download with a hash generator

Vendors often print a file's hash next to the download link. Linux distributions ship a SHA256SUMS file, while some older projects still publish a single MD5 value. In practice, you check a file with this hash generator in four steps:

  1. Switch to Verify at the top.
  2. Paste the value from the download page into Expected hash. The tool detects the algorithm from the length: 32 characters means MD5, 64 means SHA-256.
  3. Choose the downloaded file or drop it on the box.
  4. Match means the file did not change on the way; No match means you should download it again.

To check many files at once, paste the whole SHA256SUMS content and select all listed files together. The tool pairs every line with a file by name and lists matches, mismatches and files you did not select. If you also select the SHA256SUMS file itself, the tool reads the list for you.

One warning: a hash only proves that the file equals the published value. If an attacker replaced both the file and the value on the page, the two still match. So when a project offers a signed checksum file, check the signature too. We follow the same logic in the prelaunch file checks of our web design projects.

Why does the same text give a different hash?

A hash works on bytes, not on the letters you see. If two texts that look identical turn into different bytes, their hashes differ completely. Three causes explain almost every case:

  • Trailing newline: on Linux, echo hello | md5sum adds a hidden newline. That is why you get b1946ac92492d2347c6235b4d2611184 for "hello" instead of 5d41402abc4b2a76b9719d911017c592.
  • Line ending style: Windows ends lines with CRLF (two bytes), Linux and macOS with LF (one byte).
  • Character encoding: "café" takes 5 bytes in UTF-8 but 4 bytes in the older Windows-1252 encoding. As a result, the MD5 values differ: 07117fe4a1ebd544965dc19573183da2 and 961f50f6282239d09e48f812c1ca7276.

The encoding, line ending and trailing newline options in the tool let you try each of these with one click. In Verify mode with the Text option, the tool tries them on its own. It then explains the result, for example "it matches with a trailing newline". Browsers keep line breaks in a text box as LF. So try CRLF for text that came from Windows. If you want to count characters and bytes separately, the word counter helps.

Is MD5 still secure?

We expect two things from a hash function. First, nobody should get from the hash back to the input. Second, nobody should find two inputs with the same hash. The second property is collision resistance, and that is exactly where MD5 and SHA-1 fail.

  • MD5: researchers published the first MD5 collision pairs in 2004. RFC 6151 states that MD5 is no longer acceptable where collision resistance matters, for example in digital signatures.
  • SHA-1: on 23 February 2017, Google and the CWI institute in Amsterdam showed the first practical SHA-1 collision. Their proof was two different PDF files with one hash. In December 2022, NIST told users to move from SHA-1 to SHA-2 or SHA-3 by 31 December 2030.

That does not make MD5 useless for every job. It still catches accidental damage, such as a download that stopped halfway. The real risk appears when someone deliberately crafts a fake file with the same hash. Therefore, base security decisions, signatures and certificates on SHA-256 or stronger.

Can you decrypt an MD5 hash?

Short answer: no. MD5 is not encryption but a one way digest. No key or formula leads from the hash back to the text. Endless possible inputs squeeze into the same 128 bit space, so information disappears.

So how do "MD5 decrypt" websites return results? They keep huge tables of hashes they computed in advance. When you paste a hash, they look it up. If it belongs to a common word, they show that word. Rainbow tables apply the same idea with less storage. The MD5 of "password", 5f4dcc3b5aa765d61d8327deb882cf99, sits in every one of these tables.

In other words, common passwords such as "123456" fall to such a lookup in seconds. The hash of a long random string, however, appears in no table. To create a strong random password, use our password generator. Even a random password should never go into a database as plain MD5, though; the next section explains why.

Why shouldn't you store passwords as MD5 or SHA-256?

SHA-256 still resists collisions well, so why is it not enough for passwords? Because it is fast. A modern graphics card can compute billions of SHA-256 hashes per second. If your database leaks, an attacker tries every dictionary word and every known password at that speed.

Password storage needs algorithms that are slow and memory hungry by design. The OWASP Password Storage Cheat Sheet recommends the following minimums.

  • Argon2id with at least 19 MiB of memory, 2 iterations and 1 degree of parallelism.
  • Scrypt, if Argon2id is not available, with N=2^17, r=8, p=1.
  • Bcrypt for legacy systems, with a work factor of 10 or more. Note that bcrypt only uses the first 72 bytes of a password.
  • PBKDF2 with HMAC-SHA-256 and at least 600,000 iterations if you need FIPS 140 compliance.

A unique salt per user is also essential, and modern libraries add it for you. We describe how we protect passwords, forms and data on business sites in our website data security guide. On sites that handle personal data, this is also a GDPR matter. Our guide on building a GDPR compliant website covers it.

How do you get a file hash on Windows, macOS and Linux?

On a server where you cannot open this tool, the operating system can compute the same hash. Pick a file in File mode and the tool fills its name into these commands.

  • Windows Command Prompt: certutil -hashfile file.iso SHA256 (MD5, SHA1 and SHA512 work too).
  • PowerShell: Get-FileHash file.iso -Algorithm SHA256; SHA256 is also the default.
  • macOS: shasum -a 256 file.iso, or md5 file.iso for MD5.
  • Linux: sha256sum file.iso and md5sum file.iso; to check a whole list, run sha256sum -c SHA256SUMS.

PowerShell prints the result in capitals and Linux in lowercase. The difference does not matter, because letter case carries no meaning in hex. The output format switch gives you either view. In Text mode we also show the matching printf command for short, single line text.

A member of the same family protects your email too: RFC 8301 requires SHA-256 for DKIM signatures and forbids SHA-1. You can inspect your domain's DKIM record with the SPF, DKIM and DMARC checker.

Common hash generator mistakes

  • MistakeStoring passwords as MD5 or SHA-256.Do this insteadUse a slow algorithm such as Argon2id, scrypt or bcrypt with a salt per user, and follow the OWASP minimums.
  • MistakeHashing with echo and forgetting the trailing newline.Do this insteadPass the text with printf '%s', or set Trailing newline to Add when you compare with echo.
  • MistakeComparing two texts in different encodings.Do this insteadFind out whether the other side used UTF-8 or Windows-1252, then produce the same bytes with the encoding option.
  • MistakeTreating a hash on the same page as a signature.Do this insteadA hacked site can change the file and the value together. Check the signature whenever a project offers a signed checksum file.
  • MistakeTreating an MD5 match as proof of security.Do this insteadA match rules out accidental damage. Two different files can share an MD5, so compare with SHA-256 or stronger when you cannot trust whoever prepared the file.

Frequently Asked Questions

The name and the team behind this free tool.

The tools are open to everyone and free. If you have a business or brand, take a look at what we do to grow it digitally; 14+ years in digital marketing and a team of experienced specialists.

Explore Services

Related Tools

All Tools (71)
Gross to Net Germany CalculatorCalculate your 2026 net salary in Germany from gross pay with tax class, church tax and social security, plus the employer cost.
Euro Converter (ECB Rates)Convert euros and 30 currencies with official ECB reference rates, look up any past date since 1999 and see monthly averages.
Fuel Cost CalculatorWork out trip fuel cost per litre, per km and per person, and price a European road trip country by country with official EU weekly petrol, diesel.
Inflation Calculator EuropeFind what a past amount is worth today with official Eurostat HICP data for every EU country, the euro area, Türkiye and UK CPI, and compare.
Working Hours CalculatorCalculate daily and weekly working hours after breaks, in hours and decimals, and check legal breaks and rest periods for the UK and EU.
Compound Interest CalculatorSee how savings grow with compound interest and monthly contributions, year by year, with tax and inflation adjusted real value and the monthly.