gazza.ltd

Hash Generator

MD5 — checksums only, not secure
…
SHA-1 — checksums only, not secure
…
SHA-256
…
SHA-384
…
SHA-512
…

Hashing happens in your browser — nothing you type is sent anywhere. MD5 and SHA-1 are both broken for security purposes and should not be used for passwords or signatures, but remain fine for verifying that a file downloaded intact.

Ad

Generate MD5, SHA-1, SHA-256, SHA-384 and SHA-512 hashes from any text, all five at once and updating as you type. Useful for verifying downloads, comparing checksums, or generating a fingerprint for a string.

How it works

A hash function takes input of any length and produces a fixed-length output. SHA-256 always returns 64 hexadecimal characters whether you feed it one letter or an entire book. The mapping is deterministic — identical input always gives identical output — but effectively impossible to run backwards.

The SHA hashes here come from the Web Crypto API, the same implementation the browser uses for HTTPS, so results are exact. MD5 is implemented in JavaScript because browsers deliberately exclude it from Web Crypto on the grounds that it is no longer cryptographically sound.

Text is converted to UTF-8 bytes before hashing, which is what makes accented characters and emoji hash consistently with other tools and programming languages.

Worked example

The string abc hashes to 900150983cd24fb0d6963f7d28e17f72 in MD5 and ba7816bf8f01cfea… in SHA-256. Those exact values appear in the published specifications for both algorithms, which makes them a quick way to confirm any hashing tool is behaving correctly.

Change the input to abd — a single letter — and every character of the output changes. That property, sometimes called the avalanche effect, is why a hash is a reliable fingerprint: two nearly identical files produce completely unrelated hashes.

Common questions

Which hash should I use?

SHA-256 is the sensible default for anything security-related. MD5 and SHA-1 are both broken — collisions can be produced deliberately — so they should never be used for passwords, signatures or certificates, though they remain perfectly serviceable for checking a download arrived intact.

Can a hash be reversed?

Not directly. Hashing is one-way by design. But short or common inputs can be found by brute force or looked up in precomputed tables, which is why passwords need a salt and a deliberately slow algorithm such as bcrypt or Argon2 rather than a raw SHA hash.

Why does an empty box still produce a hash?

Because the empty string is valid input. Its SHA-256 value, beginning e3b0c442, is one of the most recognisable constants in computing — you will see it whenever something hashed nothing at all, which is often a useful clue.

Does the same text always give the same hash?

Always, on any machine, in any language. That determinism is the entire point — it is what lets you verify a file matches the one someone else has. Change one character and the output changes completely.

Is my input sent to a server?

No. SHA hashing uses the Web Crypto API built into your browser, and the MD5 implementation runs in JavaScript on your machine. Nothing you paste leaves the page, which matters if you are hashing anything sensitive.

Why is MD5 included if it is insecure?

Because plenty of real work still needs it. Software vendors publish MD5 checksums, older systems store MD5 digests, and verifying those is a legitimate task. It is included with the warning attached rather than left out.

Related tools