LocalDevTools

Hash Generator

Compute SHA-256, SHA-512, SHA-1 and MD5 hashes of text or a file, and check a download against its published checksum. Files are hashed on your device, so even large or private files never leave it.

Runs entirely in your browser. Your input is never uploaded or stored on a server.

How to generate a hash or verify a checksum

  1. Type or paste text, or choose a file. All supported hashes are calculated at once and update as you type.
  2. Pick the output format. Hex is what most download pages and command-line tools show. Base64 is common in HTTP headers and Subresource Integrity attributes.
  3. To verify a download, choose the file and paste the checksum from the publisher's site into Compare. The tool tells you which algorithm matches, or warns you if none do.
  4. Enter an HMAC key to compute keyed hashes (HMAC-SHA-256 and so on) instead, for example to debug webhook signatures.

Which hash algorithm should I use?

SHA-256The default choice for checksums, content addressing, signatures and webhook HMACs. 64 hex characters.
SHA-384 / SHA-512Longer outputs from the same SHA-2 family. SHA-384 is popular for Subresource Integrity (integrity="sha384-…").
SHA-1Broken for collision resistance since 2017. Still seen in Git object IDs and legacy systems. Do not use for new security designs.
MD5Broken for security. Still fine for non-adversarial uses such as cache keys, deduplication or detecting accidental corruption.

Never use any of these alone to store passwords. They are designed to be fast, which helps attackers guess billions of passwords per second. Use Argon2id, scrypt or bcrypt.

Examples

Input: hello world
MD5:     5eb63bbbe01eeed093cb22bb8f5acdc3
SHA-1:   2aae6c35c94fcfb415dbe95f408b9ce91ee846ed
SHA-256: b94d27b9934d3e08a52e52d7da7dabfac484efe37a5380ee9088f7ace2efcde9

Changing a single character, for example to hello world!, produces a completely different hash. This "avalanche effect" is what makes hashes useful for detecting changes.

Command-line equivalents

printf 'hello world' | sha256sum        # Linux
shasum -a 256 file.iso                  # macOS
Get-FileHash file.iso -Algorithm SHA256 # Windows PowerShell

Watch out for trailing newlines: echo "hello world" | sha256sum hashes hello world\n and gives a different result. Use printf or echo -n.

Frequently asked questions

Are my files uploaded to compute the hash?

No. Files are read with the FileReader API and hashed by your browser's Web Crypto API (SHA family) or a local JavaScript implementation (MD5). You can verify in the Network tab of your developer tools.

Why doesn't my hash match the one from the command line?

Usually a trailing newline or different text encoding. This tool hashes the exact UTF-8 bytes of the text box. echo adds a newline unless you use -n, and Windows files may contain CRLF line endings.

Can a hash be reversed to get the original text?

Not mathematically, but short or common inputs (like passwords) can be found by guessing and comparing, which is why fast hashes are unsuitable for passwords.

What is HMAC?

A hash combined with a secret key. Services like Stripe, GitHub and Slack sign webhooks with HMAC-SHA-256 so you can verify the request came from them. Enter the key and the raw request body here to compare signatures while debugging.

Is there a file size limit?

Files are read into memory, so very large files (several gigabytes) may fail on devices with little RAM. Files up to a few hundred megabytes work fine on a typical computer.

Related tools

Last updated: