Hash Generator

100% private — runs on your device, never uploaded. Works offline once loaded.

Generate cryptographic hashes (MD5, SHA-1, SHA-256, SHA-384, SHA-512) from any text instantly. Everything is computed locally in your browser.

What a hash function actually does

A cryptographic hash function takes any input — a single word, a password, or a 4GB video file — and produces a fixed-length string of hexadecimal characters called a digest. MD5 always outputs 32 hex characters (128 bits), SHA-1 outputs 40, and SHA-256 outputs 64, no matter how large or small the input is. Change a single character anywhere in the source text and the entire digest changes unpredictably; this is called the avalanche effect, and it's what makes hashes useful for spotting even tiny corruption or tampering.

Hashing is a one-way operation: there is no algorithm to turn a digest back into the original text. That's fundamentally different from encoding schemes like Base64, which are fully reversible. A hash only lets you confirm whether two pieces of data are identical by comparing their digests, not recover what the data was.

Where hashes show up in everyday development

Software vendors publish a SHA-256 checksum next to Linux ISO or installer downloads so you can confirm the file wasn't corrupted or swapped by a mirror server. Git uses SHA-1 hashes as commit IDs so it can detect if a single line in the entire repository history has changed. Databases store a salted hash of a password instead of the password itself, so a breach doesn't hand attackers plaintext credentials.

  • Verifying a downloaded file matches the checksum the publisher posted
  • Detecting duplicate files by comparing their hash instead of byte-by-byte
  • Generating short, deterministic cache keys or ETags for web assets
  • Fingerprinting data for digital forensics and audit trails

Choosing between MD5, SHA-1, and SHA-256

MD5 and SHA-1 are both considered cryptographically broken — researchers have demonstrated practical collision attacks, meaning two different inputs can be crafted to produce the same digest. That rules them out for anything security-sensitive, but they're still perfectly fine for non-adversarial checksums, like confirming a file transfer completed without corruption. SHA-256 and SHA-512 (part of the SHA-2 family) have no known practical collision attacks and are the standard choice for certificates, blockchain, and password-related work today.

Frequently asked questions

Is my text sent anywhere?

No — hashing happens entirely on your device.

Is MD5 secure for passwords?

No — use SHA-256 or bcrypt for password storage. MD5 is fine for checksums.

Is MD5 secure for storing passwords?

No. MD5 is fast and collision-prone, which makes it easy to brute-force or attack with rainbow tables; use a slow, salted algorithm like bcrypt or Argon2 for real password storage, not a raw hash of any kind.

Can a hash be reversed back into the original text?

Not by design — hashing is one-way. Short or predictable inputs (like common passwords) can sometimes be recovered via precomputed lookup tables, but the algorithm itself provides no reverse function.

Why do two different pieces of text almost never produce the same hash?

The digest space is enormous (2^256 possibilities for SHA-256), so accidental collisions are astronomically unlikely, even though they're mathematically possible for any fixed-length hash.

Are hashes case-sensitive?

The digest itself is just hex data, conventionally shown in lowercase, but when comparing two hashes for a match you should normalize case first since 'AB12' and 'ab12' represent the same bytes.

What's the difference between hashing and encryption?

Encryption is reversible with the right key, so you can get the original data back; hashing is deliberately one-way and only proves whether two inputs matched, never revealing what either input was.

Advertisement