Hash Generator
Generate SHA-1, SHA-256, SHA-384 and SHA-512 hashes.
—
About this tool
Hash text or a file using the browser's native Web Crypto implementation. Paste a published checksum to compare against and the result is checked for you, rather than leaving you to eyeball sixty-four hex characters.
How to use it
- Enter text, or drop in a file.
- Pick the algorithms you want.
- Optionally paste an expected checksum to verify a match.
Why there is no MD5 option
The Web Crypto API deliberately omits MD5, and this tool is not going to work around that.
MD5 has been cryptographically broken since 2004. Collisions — two different inputs producing the same hash — can be generated in seconds on a laptop. Researchers have demonstrated colliding executables, colliding PDFs, and a forged certificate authority.
SHA-1 is also broken; the SHAttered attack produced two colliding PDFs in 2017. It is included here because verifying legacy checksums and Git object ids still requires it, but it should never be used for anything new.
For integrity checking, use SHA-256. It is fast, universally supported, and has no known practical attacks.
For passwords, use none of these. Cryptographic hashes are designed to be fast, which is exactly what an attacker wants when testing billions of guesses. Use Argon2id, scrypt or bcrypt — algorithms deliberately made slow and memory-hungry.
Verifying a download
A published checksum lets you confirm a file arrived intact and unmodified. The process is simple, and its limitation is important.
Drop the file in, pick SHA-256, paste the published value, and the comparison is done for you — which beats eyeballing sixty-four hex characters and missing a transposed pair.
What a matching hash proves: the file is byte-for-byte what the publisher hashed. No corruption in transit, no truncated download.
What it does not prove: that the file is safe. If an attacker controls the download page, they control the checksum printed on it too, and can serve a malicious file with a matching hash. Checksums protect against accidents and mirrors, not against a compromised source.
Signatures do prove authenticity. A GPG signature is verified against a key you already trust, so an attacker would need the private key rather than just write access to a web page. Where a project publishes signatures, prefer them.
Files here are hashed locally by your browser, so size is limited only by memory — nothing is uploaded.
Frequently asked questions
- Why is MD5 not offered?
- The Web Crypto API deliberately omits MD5 because it is cryptographically broken — collisions are trivial to produce. Use SHA-256 for anything security related.
- Can I hash large files?
- Yes. Files are read and hashed locally, so the practical ceiling is your available memory rather than any upload limit.
- Are my files uploaded to be hashed?
- No. Files are read with the FileReader API and hashed by the browser's own Web Crypto implementation, so even multi-gigabyte files never leave your disk.