Hash Tools
Generate cryptographic hashes from text in your browser.
Tools
What a cryptographic hash actually does
A hash function maps input of any size to a fixed-length output, deterministically and one-way: the same input always hashes to the same value, but there's no practical way to reverse the output back into the original input. A secure hash also makes it computationally infeasible to find two different inputs that produce the same output. That combination is what makes hashes useful for verifying a file wasn't altered, or confirming two pieces of data match without comparing them directly.
SHA-256 and SHA-512 for real security use
Both are part of the SHA-2 family and are currently considered secure, with no known practical way to find a collision. They're the right choice for file integrity checks, digital signatures, and verifying that downloaded data matches a published checksum. Hash Generator supports SHA-256, SHA-384, and SHA-512; pick whichever a spec, API, or existing system already expects, since all three are secure and the difference mostly comes down to output length and performance on 64-bit hardware.
Why MD5 and SHA-1 aren't offered
Both have practical, demonstrated collision attacks, meaning an attacker can craft two different inputs that hash to the same value. That breaks the core guarantee a security-sensitive hash needs to provide, so neither belongs in a signature, integrity check, or anything else where forging a match would matter. They're still acceptable for non-adversarial uses, like a quick checksum to catch accidental file corruption, but SHA-2 is the safer default even there.
Don't hash passwords directly
SHA-256/384/512 are fast by design, which is a problem specifically for passwords: speed is exactly what lets an attacker who steals a password database try billions of guesses per second against it. Password storage calls for an algorithm designed to be slow and to include a per-password salt, like bcrypt, scrypt, or Argon2, not a general-purpose hash applied on its own. Use this tool for integrity checks and fingerprints, not for storing or checking passwords.
Frequently asked questions
- What is a cryptographic hash, in practical terms?
- A one-way function that turns any input into a fixed-length string, deterministically: the same input always produces the same hash, but there's no way to run it backward to recover the input. Changing even one character in the input produces a completely different hash, which is what makes hashes useful for detecting changes.
- Is hashing the same as encryption?
- No. Hashing is one-way and irreversible by design; encryption is reversible with the correct key. If you need to get the original data back, you need encryption, not a hash.
- Why isn't MD5 or SHA-1 offered here?
- Both have known collision attacks, meaning two different inputs can be crafted to produce the same hash, which breaks the guarantee a hash is supposed to provide for integrity checks or signatures. They're still fine for non-security uses like a checksum to catch accidental corruption, but not for anything where an adversary might try to forge a match.
- Which algorithm should I use, SHA-256 or SHA-512?
- Both are considered secure with no known practical attacks. SHA-256 is the more common default and produces a shorter hash; SHA-512 is faster on 64-bit hardware and gives a larger margin of security. For most use cases, matching whatever a spec, API, or existing system already expects matters more than picking one over the other.
- Can I use this to hash passwords?
- Not directly, no. SHA-256/384/512 are fast by design, which is exactly wrong for passwords: it makes brute-forcing every possible password cheap for an attacker who gets the hash. Password storage needs an algorithm built to be slow and salted, like bcrypt, scrypt, or Argon2, not a general-purpose hash used on its own.