Hash Generator

Compute SHA hashes of text locally in your browser.

Input
TEXT input
Output
Result
Options

About this tool


A cryptographic hash maps input of any length to a fixed-size digest, deterministically and irreversibly. The same input always yields the same digest, and any change to the input, a single bit, produces a completely different one.

Hashing runs through the Web Crypto API on your own machine, so the text never leaves the browser. That matters here more than for most tools, since people hash things they care about keeping private.

How to use it

  1. Paste or upload your textDrop a file onto the input pane, use the file picker, or paste the text directly.
  2. Adjust the options if neededThe defaults suit most input; open Options to change the behaviour.
  3. HashPress Hash, or use Ctrl+Enter (Cmd+Enter on macOS).
  4. Copy or downloadCopy the result, or download it as a .txt file.

Worked examples


Each example below is executed against this tool by the test suite, so what you see is what the tool actually produces.

SHA-256 of "abc"

Input

abc

Output

ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad

This is the standard test vector for SHA-256, so you can verify the implementation against any reference.

What to watch for


The details that decide whether a conversion is correct, and where information can be lost without any error being raised.

Choosing an algorithm
SHA-256 is the sensible default and is what TLS certificates, Bitcoin and most signing schemes use. SHA-512 produces a longer digest and is actually faster on 64-bit hardware. SHA-384 is a truncated SHA-512. SHA-1 is included only for verifying legacy checksums and Git object IDs.
SHA-1 is broken for security purposes
Practical collision attacks against SHA-1 have been demonstrated, two different inputs producing the same digest, so it must not be used for signatures, certificates or any integrity check an attacker could influence. It remains adequate for non-adversarial checksums and for reading existing Git hashes.
Never use a plain hash for passwords
This is the most consequential misuse. SHA-256 is designed to be fast, which is exactly wrong for password storage: a modern GPU computes billions of SHA-256 hashes per second, so a stolen database of hashed passwords falls quickly. Use bcrypt, scrypt or Argon2, which are deliberately slow and salted per user.
Hashing is not encryption
There is no key and no way back, a digest cannot be reversed to recover its input. Sites that appear to "decrypt" a hash are looking it up in a table of precomputed common inputs, which works only because the input was guessable.
Requires a secure context
The Web Crypto API is only available over HTTPS or on localhost. On an insecure origin the browser withholds it entirely, and the tool reports that rather than falling back to a weaker implementation.

Limitations


  • Offers the SHA family only; MD5 is excluded because the Web Crypto API does not provide it.
  • Hashes text rather than files.
  • Requires HTTPS or localhost, since Web Crypto is unavailable on insecure origins.
  • Processing happens in your browser, so very large inputs are bounded by available memory. Files above roughly 10 MB are handled but will feel slower, and multi-hundred-megabyte files are better suited to a command-line tool.

Questions


Can a hash be reversed?
No. Hashing is one-way by design. Services claiming to reverse a hash are searching a precomputed table of common inputs, which only succeeds when the original was predictable.
Can I use SHA-256 to store passwords?
No. It is far too fast, so brute-forcing a stolen hash is cheap. Use bcrypt, scrypt or Argon2, which are intentionally slow and salted.
Is my text sent anywhere?
No. Hashing happens in your browser through the Web Crypto API. You can confirm this in the Network tab, no request carries your text or the generated hash.
Why is MD5 not offered?
The Web Crypto API deliberately excludes MD5 because it is thoroughly broken. Adding it would require bundling a separate implementation to support an algorithm nobody should use.