Skip to content
TabBench

Hash Generator

Hash text or files of any size with MD5, SHA-256, SHA-512, SHA-3 and more, check them against a published hash, and create HMAC signatures.

Runs in your browser. Nothing you add is uploaded.

What the Hash Generator does

A cryptographic hash reduces any input to a fixed-length fingerprint. The same input always produces the same hash, and any change — even a single bit — produces a completely different one. Hashes are used to verify downloads, detect changes, deduplicate content and sign messages. This generator hashes text or files of any size with MD5, SHA-1, SHA-256, SHA-384, SHA-512, SHA-3 and CRC32, and checks the result against a hash you paste from a download page. It can also produce HMAC signatures for checking webhooks. Files are read a few megabytes at a time in your browser, so even a multi-gigabyte download is never uploaded or held in memory at once.

How to check a file's hash

  1. Choose File and drop in the download, or choose Text and type or paste what you want to hash.
  2. Turn on the algorithms you need. SHA-256 is the usual choice; the one the publisher used is the one to compare.
  3. Paste the published hash into Check against a published hash. The matching row turns green, or you are told it doesn't match.
  4. Copy any hash in hex, upper-case hex or Base64. For webhook signatures, turn on HMAC and enter the secret key.

The Hash Generator runs entirely in your browser — nothing you enter is uploaded, stored, or logged.

When to use it

Verifying a downloaded file

Projects publish a SHA-256 checksum alongside their releases. Computing the hash of what you downloaded and comparing confirms the file arrived intact and was not tampered with.

Detecting whether content changed

Comparing hashes of two versions is far faster than comparing the content itself, and works regardless of size.

Deduplicating records

Hashing a normalised representation of a record gives a compact key for identifying exact duplicates across a large dataset.

Good to know

  • Hashing is one-way by design. There is no operation that recovers the input from the digest.
  • MD5 and SHA-1 are both cryptographically broken — collisions can be constructed deliberately. Use them only for non-security checks like cache keys, never for signatures or integrity guarantees.
  • Hashes are case-insensitive in hex representation but compare them exactly; a single differing character means a different input.
  • A text hash that doesn't match is usually a line break: echo "text" | sha256sum hashes the text plus a newline. Use echo -n, or printf, to match what you type here.
  • Never hash passwords with a plain hash function. Password storage requires a slow, salted algorithm such as bcrypt, scrypt, or Argon2.

Frequently asked questions

Can a hash be decrypted?

No, cryptographic hash functions are one-way functions.

How do I verify a downloaded file's checksum?

Choose File, drop in the download, and paste the SHA-256 (or other) hash from the download page into the check box. If it matches, the file is exactly the one that was published; if not, download it again from the official source.

Can a hash be reversed or decrypted?

No. Hashing is a one-way function — the digest is a fixed size regardless of input length, so information is necessarily discarded. What sites advertising 'hash decryption' actually do is look the digest up in a precomputed table of common inputs. That works for 'password123'; it does not work for arbitrary data.

Which hash algorithm should I use?

SHA-256 for essentially all new work — it is fast, widely supported, and has no known practical weakness. SHA-512 is a reasonable choice on 64-bit systems. Avoid MD5 and SHA-1 for anything security-relevant: practical collision attacks exist for both, meaning an attacker can construct two different files with the same digest.

Why is MD5 still available if it is broken?

Because collision resistance is not always what you need. MD5 remains perfectly serviceable as a fast checksum for cache keys, deduplication, or detecting accidental corruption — situations with no adversary. It is unsuitable wherever someone might deliberately engineer a collision.

Should I use this to hash passwords?

No. Fast hashes are the wrong tool for password storage precisely because they are fast, which lets an attacker test billions of guesses per second against a leaked database. Use a deliberately slow, salted algorithm — bcrypt, scrypt, or Argon2 — which is designed to make that expensive.

Is my input sent anywhere?

No. Hashing runs in your browser using the Web Crypto API, and the input never leaves your device.