What the hash generator does

A cryptographic hash function turns data of any length into a fixed-length fingerprint. Change a single byte of the input and the output changes completely. The tool computes every selected algorithm at once and lists the results side by side.

Typical jobs: confirming that a downloaded installer matches the SHA-256 checksum its publisher lists, testing the HMAC signature an API or webhook expects, checking whether two files are identical, or verifying a Subresource Integrity value such as sha384-….

How to use it

  • In text mode the results update as you type. Text is encoded as UTF-8 bytes.
  • In file mode pick a file; the tool reads it in 4 MiB chunks and shows the progress as a percentage. You can cancel at any time.
  • Tick the algorithms you need. At least one must be selected.
  • Tick HMAC to enter a key as plain text (UTF-8) or hex; every algorithm is then computed as HMAC-….
  • Paste the publisher’s value into the expected-hash field. Case does not matter; sha256sum style “hash filename” lines and sha384- prefixed Base64 values are accepted too.

Algorithms and security level

The SHA family is computed with the browser’s built-in Web Crypto API. Web Crypto has no MD5, so MD5 uses an implementation written for this page from RFC 1321 and tested against the RFC’s test suite.

AlgorithmOutputStatus
MD5128 bits, 32 hexCollisions can be produced; do not use for security
SHA-1160 bits, 40 hexPractical collision demonstrated; legacy compatibility only
SHA-256256 bits, 64 hexThe common choice for checksums and signatures
SHA-384384 bits, 96 hexOften seen in SRI and TLS
SHA-512512 bits, 128 hexCan be faster than SHA-256 on 64-bit CPUs

MD5 and SHA-1 rows are flagged in the result table. They still catch accidental corruption, but they do not protect you from a file an attacker prepared on purpose. No plain hash is suitable for storing passwords; that needs a slow, salted scheme such as Argon2, bcrypt or scrypt.

HMAC and expected-hash comparison

HMAC (RFC 2104) hashes a message together with a secret key, so nobody without the key can produce the same value. Webhook signatures and API request signing usually rely on HMAC-SHA256. HMAC with the SHA family runs through Web Crypto; HMAC-MD5 uses the local MD5 code. Web Crypto rejects empty keys, so the key field is required.

For the comparison the expected value is first decoded to bytes, then checked against every result of the same length by walking all bytes rather than stopping at the first difference. If the length points to an algorithm you did not select (64 hex characters means SHA-256, for example), the tool says so.

Line endings and encoding

Two texts that look identical can be different bytes. A Windows line break, CRLF (\r\n), is two bytes; a Unix line break, LF (\n), is one, so the hash differs. Browsers turn textarea line breaks into LF, so the tool hashes with LF; when you check the text of a file created on Windows, switch the line-ending option to CRLF. For an exact answer use file mode, which never alters the bytes.

Non-ASCII characters take several bytes in UTF-8: the Turkish ü is c3 bc. A single trailing newline also changes the result, which is why command-line examples use printf '%s' or echo -n instead of plain echo.

Example and interpretation

The example button loads the abc message from FIPS 180-4 together with its expected SHA-256 value. The result is ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad and the SHA-256 row is marked as a match. The MD5 of the same input equals the RFC 1321 value 900150983cd24fb0d6963f7d28e17f72.

The Turkish phrase Merhaba dünya followed by LF hashes to SHA-256 300c120e…1b0b9fd5; followed by CRLF it becomes cd876c3b…51165519. Same visible text, two digests: when a checksum does not match, check line endings and trailing spaces first.

Limits and privacy

Files are limited to 200 MiB and text to one million characters. Web Crypto cannot hash a stream, so when a SHA algorithm is selected the whole file is held in memory for a moment; with only MD5 selected the file is processed chunk by chunk. Very large files can fail on low-memory devices.

No data is sent over the network. A share link contains the text, options and expected hash only if you tick the box; the file and the HMAC key are never included. A matching hash does not prove a file is safe, only that it equals the expected value, so take that value from a source you trust. If you need random secrets, the WordPress salt generator or the UUID generator fits better.

Frequently asked questions

Can I recover the original text from a hash?

No, hashing is one-way. Short or predictable inputs can still be found with a dictionary attack, so publishing the hash of a secret does not keep it secret.

Why does my command-line result differ?

Most often it is the trailing newline that echo appends. Next come CRLF line endings and a different character encoding. File mode hashes the bytes exactly as they are.

Is MD5 still usable?

For catching accidental corruption or matching what a legacy system expects, yes. For protection against deliberate tampering, signatures or password storage, no; use SHA-256 or stronger.

Is my file uploaded?

No. The file is read with the browser’s File API and hashed on your device.

When do I need Base64 output?

Subresource Integrity (integrity="sha384-…"), some API signatures and HTTP digest headers expect Base64. Hex and Base64 look different but encode the same bytes.

Published: · Updated: