Skip to content
Browser tool Runs locally

Hash Generator

Generate SHA-256, SHA-384, and SHA-512 digests from text using your browser's native Web Crypto API.

Text / data input
Algorithm
Whitespace and line breaks are included. Input is hashed exactly as entered.
Hash
The hash will appear here.

How to generate a hash

  1. Paste or type the text you want to hash into the input box.
  2. Pick an algorithm - SHA-256, SHA-384, or SHA-512.
  3. Click Generate to compute the digest.
  4. Copy the resulting hex string, or click Example first if you just want to see the tool in action.

What is a cryptographic hash?

A cryptographic hash is a fixed-length value - a digest - derived from an input of any size by a one-way function. The same input always produces the same digest, but changing even a single character produces a completely different one, and there's no practical way to work backward from the digest to recover the original input. That combination makes hashes useful for verifying that data hasn't changed, identifying duplicate content, indexing large datasets, and building blocks like digital signatures, version-control systems (Git commit hashes), and blockchain ledgers - anywhere you need a compact, reliable fingerprint for something larger.

SHA-256 vs. SHA-512

SHA-256 and SHA-512 (along with SHA-384, a truncated variant of SHA-512) are both members of the SHA-2 family and are considered secure by current cryptographic standards. SHA-256 produces a 256-bit digest as 64 hex characters and is the most widely used of the three - it's the default for TLS certificates, package checksums, Git's newer hashing mode, and most APIs that ask for "a SHA hash" without specifying further. SHA-512 produces a 512-bit digest as 128 hex characters; on 64-bit systems it can actually hash faster than SHA-256 despite the longer output, and it's often preferred where a larger digest is wanted for extra collision resistance, such as some certificate and password-storage schemes. For everyday use - checksums, deduplication, general-purpose fingerprinting - SHA-256 is the more common default.

Why MD5 and SHA-1 aren't offered here

MD5 and SHA-1 are older hash algorithms that are still seen in legacy systems, but both have well-documented security weaknesses: researchers have demonstrated practical collision attacks against each, meaning two different inputs can be crafted to produce the same digest. That breaks the guarantee a hash is supposed to provide in any security-sensitive context - checksums used only to catch accidental corruption are a lower-stakes exception, but for integrity verification, digital signatures, or anything where someone might deliberately try to fake a match, MD5 and SHA-1 should be treated as unsafe. This tool only offers SHA-256, SHA-384, and SHA-512, which have no known practical collision attacks.

Hashing vs. encryption

Hashing and encryption solve different problems. Encryption is two-way by design: it transforms data into ciphertext that's meant to be decrypted back into the original using a key. Hashing is one-way by design: it's not meant to be reversed at all, and there's no key involved. Use encryption when you need to protect data and get the original back later; use hashing when you need to verify data hasn't changed or fingerprint it without ever needing the original value back from the digest itself.

Don't use a general-purpose hash for passwords

SHA-256 and SHA-512 are fast - that's a feature for checksums and a serious liability for passwords. Speed is exactly what lets an attacker who steals a password database try billions of guesses per second against it using off-the-shelf hardware. Dedicated password-hashing algorithms like Argon2, bcrypt, and scrypt are deliberately slow and memory-hungry, and they build in salting automatically, which makes large-scale guessing and precomputed lookup-table attacks impractical. If you're storing passwords, reach for one of those instead of a general-purpose hash like the ones this tool generates.

Verifying file integrity with a checksum

A common use of hashing is confirming a downloaded file wasn't corrupted or tampered with in transit. The publisher computes a hash of the original file (typically SHA-256) and posts that digest next to the download link. After downloading, you hash your local copy the same way and compare the two digests character by character - a match means the file is byte-for-byte identical to what was published, while any mismatch means something changed along the way. This tool hashes the text you type or paste into it rather than uploaded files directly; to check an actual file, you'd typically use your OS's built-in checksum utility or a command-line tool and compare its output against the published digest.

Runs locally in your browser

This generator computes every digest on your device using the browser's built-in Web Crypto API (crypto.subtle.digest) - nothing you type is sent to a server. That API is only exposed in a secure context, meaning it requires HTTPS (or localhost) and a reasonably modern browser; if it isn't available, the Generate button stays disabled rather than falling back to a weaker method.

Frequently asked questions

Is hashing the same as encryption?
No. Encryption is designed to be reversed with the correct key, so the original data can be recovered. Hashing is designed to be one-way - there is no key, and no supported way to turn a hash back into the input that produced it. Use encryption when data needs to be recovered later; use hashing when you only need to verify or identify data.
Can I decrypt or reverse a hash?
Not in the way you'd decrypt ciphertext. A cryptographic hash discards information, so there is no calculation that maps a digest back to its input. In practice, short or predictable inputs (like common passwords) can sometimes be found through lookups against precomputed tables or brute-force guessing, but that is guessing, not decryption - it's exactly the weakness dedicated password-hashing algorithms are built to resist.
Why does this tool only offer SHA-256, SHA-384, and SHA-512?
These are the SHA-2 family algorithms with no known practical collision or preimage attacks, which is why they remain the standard choice for checksums, digital signatures, and data integrity checks. MD5 and SHA-1 are older and are excluded here because both have demonstrated collision weaknesses that make them unsuitable for security-sensitive use, even though they still appear in legacy systems.
Should I use SHA-256 to store passwords?
No. General-purpose hashes like SHA-256 are fast by design, which is exactly wrong for passwords - it lets an attacker with a stolen password database try billions of guesses per second. Dedicated password-hashing algorithms such as Argon2, bcrypt, or scrypt are deliberately slow and memory-intensive, which makes large-scale guessing impractical.
How can I use a hash to verify a file wasn't corrupted or tampered with?
A file's publisher computes a hash of the original file and shares that digest alongside the download. After downloading, you compute the hash of your local copy the same way and compare it to the published value character by character. Any difference - even a single changed bit in the file - produces a completely different digest, so a match gives strong confidence the file arrived intact, while a mismatch means it was altered or corrupted in transit.

Related tools