Hash Generator

Hash text with SHA-1, SHA-256, SHA-384 or SHA-512 using your browser's WebCrypto. Computed locally — input never leaves the page.

Note: MD5 is not provided here — it is broken for security purposes. Use SHA-256 or higher for new applications.
Enter input above to see the result.
Enter input above to see the result.
Enter input above to see the result.
Enter input above to see the result.

Choosing an algorithm: SHA-256 vs SHA-512

A cryptographic hash takes any input and produces a fixed-length fingerprint. Two identical inputs always hash to the same digest; changing a single bit changes the digest entirely. Hashes underpin file-integrity checks, content-addressable storage, digital signatures, and password-hashing pipelines (where they're combined with a slow function like Argon2 or bcrypt).

All hashing here uses the browser's crypto.subtle.digest — the same primitives that power TLS. Your input never leaves the page.

SHA-256 for almost everything, SHA-1 for almost nothing

One-way, not confidential — and other boundaries

The collision-resistance ladder and HMAC

The avalanche effect in four hex lines

Type hello and it instantly shows four hex digests at once — SHA-1, SHA-256, SHA-384 and SHA-512. The SHA-256 of hello is 2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824. Change a single character and every digest changes completely (the avalanche effect), which is exactly what makes hashes useful for verifying that a file or string hasn't been altered.

Missing MD5, text vs bytes, password hashing, and browser privacy

Which algorithms are here, and why not MD5? SHA-1, SHA-256, SHA-384 and SHA-512 — computed with the browser's native Web Crypto engine. MD5 and plain SHA-1 are cryptographically broken for security use; SHA-1 is included for legacy checksum matching only. For anything security-sensitive, use SHA-256 or stronger.

Is the input hashed as text or bytes? Your text is encoded as UTF-8 bytes first, then hashed — so the digest matches what command-line tools produce for the same UTF-8 string, including non-Latin characters and emoji.

Can I hash a password with this? You can, but you shouldn't store passwords as a bare SHA hash — those are designed to be fast, which helps attackers. Password storage needs a slow, salted algorithm like bcrypt, scrypt or Argon2. Use this tool for integrity checks and fingerprints, not credential storage.

Does my input leave the browser? No — hashing happens entirely locally via crypto.subtle. You can safely hash sensitive strings; nothing is uploaded.

Deterministic, one-way, and avalanche-prone

A hash function maps any input to a fixed-length digest, deterministically and one-way: the same input always yields the same output, but the output reveals nothing about the input and can't be reversed. The avalanche property means flipping a single input bit changes about half the output bits, which is why hashes make good integrity checks — any tampering is obvious. Critically, the right function depends on the job: MD5 and SHA-1 are fast and broken for security (collisions are findable), fine only for non-adversarial checksums; SHA-256 is the safe general integrity choice; and passwords need deliberately slow functions like bcrypt or Argon2.

Why speed is the enemy of password hashing

Hashing passwords with a fast general-purpose function like SHA-256. Speed is exactly wrong for passwords — it lets an attacker try billions of guesses per second against a stolen database. Passwords need a slow, salted function (bcrypt, scrypt, Argon2) built to resist brute force. Using MD5 or SHA-1 for anything security-sensitive is the other trap: both are cryptographically dead and must not guard integrity against a motivated adversary.

Related

Generate unique IDs with the UUID generator, create strong secrets with the password generator, and encode raw bytes with the Base64 encoder. Choosing the function: which hash function to use, and for logins, salting and hashing passwords.