Hash Generator

Generate MD5, SHA-1, SHA-256, SHA-512 hashes instantly. Hash text or files securely in your browser.

MD5
-
SHA-1
-
SHA-256 (Recommended)
-
SHA-512
-

Which hash should I use?

  • SHA-256 - Recommended for most uses
  • SHA-512 - When a publisher lists it
  • MD5/SHA-1 - Legacy only (not secure)

Common Uses

  • Verify file downloads (checksum)
  • Data integrity verification
  • Duplicate file detection
  • Checking backups and copies

How to Use the Hash Generator

  1. Text tab: type or paste into Enter Text to Hash. The MD5, SHA-1, SHA-256 and SHA-512 results update as you type, so there is no button to press.
  2. Tick UPPERCASE output if the system you are comparing with shows capital hex letters. It changes only how the result is written, not its value.
  3. Click Copy next to any result to put it on your clipboard.
  4. File tab: drop a file on the box, or click it and pick a file of any type up to 100 MB. The file name and size are shown and all four hashes are calculated. If you drop several files, only the first one is hashed.
  5. Compare tab: paste one hash into Hash 1 and the other into Hash 2. Spaces at the start and end are trimmed and letter case is ignored, then the tool shows Hashes Match! or Hashes Do NOT Match.

What a Hash Is, With a Real Example

A cryptographic hash function turns any input, from one word to a large installer, into a fixed-length fingerprint. The same input always gives the same output, the smallest change gives a completely different one, and the function cannot be run backwards.

Here is what this page produces for the five letters hello (no space, no line break):

MD5      5d41402abc4b2a76b9719d911017c592
SHA-1    aaf4c61ddcc5e8a2dabede0f3b482cd9aea9434d
SHA-256  2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824
SHA-512  9b71d224bd62f3785d96d46ad3ea3d73319bfbc2890caadae2dff72519673ca7
         2323c3d99ba5c11d7c7acc6e14b8c5da0c4663475c2e5c3adef46f73bcdec043

(The SHA-512 value is one 128-character string, split over two lines here.) Change only the first letter to a capital and the SHA-256 of Hello becomes 185f8db32271fe25f561a6fc938b2e264306ec304eda518007d1764826381969, which shares nothing recognisable with the lowercase version.

Text is hashed as UTF-8 bytes, the same as most programming languages and command-line tools, so Urdu, Hindi and other scripts work. For example, پاکستان is 7 letters but 14 bytes in UTF-8, and its SHA-256 here is 0ba5ffc136f811306fd341e33deef5ef18374d56133dbc217117af22f989565a, matching Python's hashlib.sha256("پاکستان".encode()).

Which algorithm should you pick?

Algorithm Output Use it for
MD5 128-bit, 32 hex characters Matching an old published checksum; never for security
SHA-1 160-bit, 40 hex characters Legacy systems only; a real collision was published in 2017
SHA-256 256-bit, 64 hex characters The default for download checksums and integrity checks
SHA-512 512-bit, 128 hex characters When a publisher or specification asks for it

How to Verify a Download Checksum

Linux distributions, open-source apps and many firmware publishers list a SHA-256 (sometimes MD5 or SHA-512) next to each download. If your copy's hash matches, the file arrived complete and unchanged, provided the checksum came from the publisher's official page and not from the same mirror or message that gave you the file.

  1. Copy the checksum from the publisher's website and note which algorithm it is (64 characters usually means SHA-256).
  2. Get the hash of your file: use the File tab above for files up to 100 MB, or one of the commands below for anything bigger, such as a multi-gigabyte ISO.
  3. Paste both values into the Compare tab. Case does not matter, so uppercase output from PowerShell compares correctly with lowercase output from Linux.

Checksum commands for any file size

Windows, Command Prompt (also accepts MD5, SHA1 and SHA512):

certutil -hashfile "C:\Users\You\Downloads\file.iso" SHA256

Windows, PowerShell (prints the hash in capitals):

Get-FileHash "C:\Users\You\Downloads\file.iso" -Algorithm SHA256

macOS, Terminal (use -a 512 for SHA-512, or md5 file.iso for MD5):

shasum -a 256 ~/Downloads/file.iso

Linux (md5sum, sha1sum and sha512sum work the same way). The second line checks automatically and prints file.iso: OK on a match; note the two spaces before the file name:

sha256sum file.iso
echo "PASTE_PUBLISHED_HASH_HERE  file.iso" | sha256sum -c

Why Your Hash Does Not Match

If two hashes of "the same text" differ, the inputs are not really the same. These four look alike on screen but give unrelated SHA-256 values:

What was hashed SHA-256 begins with
hello 2cf24dba5fb0a30e…
Hello (capital H) 185f8db32271fe25…
hello + a space 5e3235a8346e5a45…
hello + Enter 5891b5b522d5df08…
  • Hidden line break. Pressing Enter in the text box adds a newline character, and the text is hashed exactly as typed with nothing trimmed. The Linux command echo hello | sha256sum also adds a newline, so it gives 5891b5b5…, not 2cf24dba…. Use printf 'hello' | sha256sum to hash the word alone.
  • Windows line endings. Browsers store every line break in a text box as a single newline, even when the pasted text came from a Windows file with carriage return + newline. For a file's exact bytes, use the File tab instead of pasting.
  • Letter case of the input, not the output. hello and Hello are different inputs. The case of the hex result is not: 2CF24DBA… and 2cf24dba… are the same hash, which is why the Compare tab ignores case.
  • Hashing nothing. If another tool gives you e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855, that is the SHA-256 of empty input, so your variable or file was empty. This page shows a dash instead of hashing an empty box.
  • Finding the difference. Paste both versions of the text into the Text Diff tool to spot the extra space or character.

MD5 vs SHA-256: Security, Passwords and Encryption

Collisions (two different inputs with the same hash) were demonstrated for MD5 in 2004 and for SHA-1 in 2017. Both still catch a download that was damaged on the way, but an attacker can prepare two different files with the same MD5, so wherever tampering is possible, compare SHA-256 or SHA-512.

Hashing is not encryption. Encrypted data can be turned back into the original with a key; a hash cannot be turned back at all. It is also different from Base64 encoding, which anyone can decode and which hides nothing.

"Cannot be reversed" does not mean "cannot be guessed". The MD5 of hello above is published on countless pages, and common passwords or short, predictable values such as phone, CNIC or Aadhaar numbers can be found by hashing every likely candidate. That is why websites should store passwords with a slow, salted algorithm such as bcrypt, scrypt or Argon2, and why a long random password from the Password Generator is far harder to guess.

Practical Uses, Privacy and Limits

Where a hash helps

  • Checking an ISO, firmware or APK against the publisher's SHA-256 before installing it.
  • Confirming a backup or a copy on USB or a server is identical to the original.
  • Finding duplicate files: equal SHA-256 means equal content, whatever the names.
  • Debugging code: PHP md5('hello') and Python hashlib.sha256(b'hello') match this page. If your program disagrees, it is hashing different bytes, often an extra newline or another text encoding.

What the tool does and does not do

  • Text and files are hashed in your browser with the CryptoJS library; the page's code does not send them to a server.
  • Files are limited to 100 MB, one at a time. For bigger files use the commands above.
  • Algorithms offered: MD5, SHA-1, SHA-256 and SHA-512 only. There is no SHA-384, SHA-3, CRC32 or bcrypt.
  • It makes plain hashes, not HMAC signatures. Payment gateways and webhooks sign data with HMAC and a secret key, and those values will not match a plain SHA-256.

Frequently Asked Questions

Is MD5 still secure?

Not for security. Practical MD5 collisions (two different inputs with the same hash) were published in 2004, so MD5 must not be used for passwords, digital signatures or certificates. It is still fine for spotting accidental corruption, such as checking a download against an MD5 value the publisher lists.

How do I check a SHA-256 checksum on Windows?

Open Command Prompt and run certutil -hashfile "C:\path\to\file.iso" SHA256, or in PowerShell run Get-FileHash "C:\path\to\file.iso" -Algorithm SHA256. Paste the result and the publisher's checksum into the Compare tab of this tool, which ignores upper and lower case.

Can a hash be reversed or decrypted?

No. A hash is a one-way function and there is no key that turns it back into the original. However, hashes of short or common inputs can be found by guessing or by looking them up in precomputed tables, which is why the MD5 of a word like hello is effectively public knowledge.

What is the difference between hashing and encryption?

Encryption is two-way: anyone with the right key can get the original data back. Hashing is one-way and produces a fixed-length fingerprint used to check that data has not changed. Base64 is different again: it is plain encoding with no secret at all.

Why does the same text give a different hash?

A hash reacts to every byte, including capital letters, trailing spaces and line breaks. hello, Hello, hello with a trailing space, and hello followed by Enter all give completely different SHA-256 values. Look for an invisible newline or space first, then check the letter case.

Which is better, SHA-256 or SHA-512?

Both belong to the SHA-2 family and both are considered secure. SHA-256 gives a 64-character result and is the most common choice for published checksums, while SHA-512 gives 128 characters. Use whichever algorithm the publisher lists, because you can only compare a hash with one made by the same algorithm.

Is my file uploaded when I hash it here?

No. Although the drop zone says upload, the file is read by JavaScript in your browser and hashed on your device with the CryptoJS library; the page has no code that sends your file or text to a server. Files larger than 100 MB are refused so the browser tab does not freeze.

Should I use SHA-256 to store passwords?

Not on its own. MD5 and SHA-256 are designed to be fast, which also makes password-guessing attacks fast. For stored passwords use a dedicated slow algorithm such as bcrypt, scrypt or Argon2, which add a salt and an adjustable work factor.

Need help with your project?

Chat with us on WhatsApp