More
More
Hash Generator & File Checksum
SHA and MD5 hashes of text or files, HMAC signatures, and checking a download against its published checksum.
Free. Runs in your browser: nothing you enter or open is uploaded.
Text is encoded as UTF-8 before hashing, which is what nearly every tool and language does. Text hashes and HMAC signatures come from your browser's Web Crypto engine, with MD5 computed by a small script because browsers no longer offer it. Files are hashed in 4 MB pieces by a background worker on this page, so even very large downloads can be checked without uploading them.
How to use it
- For text, type or paste it: every hash updates as you type. Choose hex or Base64, and upper case if the place you compare against uses it.
- To check a download, open File checksum, drop the file, and paste the checksum published on the download page. The box says plainly whether it matches.
- To sign a message, open HMAC, enter the message and the secret key, and copy the signature, or paste one to compare.
Questions
Which hash should I use?
SHA-256 for checksums and general use. SHA-384 and SHA-512 where a standard asks for them. MD5 and SHA-1 only to match an old system, since both can be forced to collide and are not safe for security.
Can I hash passwords with this?
Not for storing them. Plain SHA and MD5 are far too fast, so stolen hashes can be guessed by the billion. Password storage needs a slow, salted method such as bcrypt, scrypt or Argon2.
Why does my hash differ from another tool?
Usually a hidden difference in the input: a trailing line break or space, Windows line endings, or a different text encoding. Hashes change completely when one byte changes.
Why check a download's checksum?
A matching SHA-256 proves the file is exactly the one the publisher released: not damaged in transfer and not swapped for a tampered copy on a mirror. Check it against the checksum on the official site, ideally over https, since a mirror that altered the file could alter its checksum too.
What is an HMAC?
A hash that mixes in a secret key. Payment providers, GitHub and many other services sign webhooks with HMAC-SHA256 so the receiver can prove a message came from them and was not changed. Anyone without the key cannot produce a matching signature.
Is a hash reversible?
No. A hash is a one way fingerprint. Short or common inputs can still be found by guessing, which is why a hash of a password or a phone number is not anonymous.