TanodTools

Hash generator

Work out the MD5, SHA-1, SHA-256, SHA-384 and SHA-512 hashes of text or a file, and check a download against its published checksum.

Runs entirely in your browser

Hash
Output

Text up to about 5 MB. Files up to 200 MB, read into memory on this device.

How to generate a hash

  1. Type or paste text, or switch to File and choose a file. All five hashes are worked out straight away.
  2. Pick lowercase hex, uppercase hex or Base64 for the output.
  3. To verify a download, paste the published checksum into Compare; the matching algorithm is highlighted. Copy a hash, or download them all as a .txt file.

What a hash is good for

A cryptographic hash turns any input, from one letter to a large file, into a short fixed-length fingerprint. The same input always gives the same fingerprint, and changing even one bit gives a completely different one. That makes hashes useful for checking that a file arrived unchanged, for spotting duplicate files, and as building blocks in signatures and version control.

To check a download, find the checksum its publisher lists next to it (often SHA-256), drop the file here and paste the checksum into Compare. If it matches, the file is byte-for-byte what the publisher hashed. A match only proves the file is the one they meant if you trust the page the checksum came from.

The SHA-1 and SHA-2 hashes (SHA-256, SHA-384, SHA-512) are calculated by your browser's Web Crypto functions. Browsers don't offer MD5, so this page includes its own MD5 code, which reads files in slices and shows progress for large ones. MD5 and SHA-1 are kept for compatibility with older checksums only.

Tips

Questions

Is my text or file uploaded?

No. The hashes are calculated in your browser: SHA hashes by its built-in Web Crypto functions and MD5 by code on this page. Nothing is sent or stored, and closing the tab clears it.

Is MD5 or SHA-1 safe to use?

Not for security. Both are broken: people can deliberately create two different inputs with the same MD5 or SHA-1 hash. They are still fine for spotting accidental corruption, such as checking that a download arrived intact. For anything where someone might tamper with the data, or for signatures, use SHA-256 or stronger.

Can I hash passwords with this?

You can see a password's hash, but a plain hash is the wrong way to store passwords: fast hashes like these can be guessed billions of times a second. Password storage needs a slow, salted algorithm such as Argon2, scrypt or bcrypt, run by your server.

Is hashing the same as encryption?

No. Encryption can be reversed with the key. A hash is a fixed-length fingerprint that cannot be turned back into the input; the only way to find an input is to guess and compare. The same input always gives the same hash, and a one-character change gives a completely different one.

Why doesn't my hash match the one from the command line?

Check for a trailing line break: echo "text" | sha256sum hashes the text plus a newline, while this box hashes exactly what you typed. Text is hashed as UTF-8 and line breaks in the box are single LF characters, so text copied from a Windows file (CRLF) can differ. For an exact match, hash the file itself in File mode.

What do hex and Base64 mean here?

They are two ways of writing the same hash bytes. Hex uses two characters per byte (a SHA-256 is 64 hex characters); Base64 is shorter (44 characters) and is used in places such as Subresource Integrity attributes. The Compare box accepts either.