Related tools
- HMAC GeneratorCompute and verify HMAC digests for a message and a secret key, in your browser.
- Bcrypt & Argon2 HasherHash and verify passwords with bcrypt, argon2, and scrypt, entirely in your browser.
- Hash IdentifierWork out which algorithm likely produced an unknown hash, ranked by likelihood.
- Certificate DecoderDecode PEM or DER X.509 certificates to read expiry, SANs, issuer, fingerprints, and chain order.
- Passkey TesterRegister and authenticate passkeys, then decode the attestation object, flags, and public key.
- Text EncrypterEncrypt and decrypt text with a passphrase using AES-256-GCM, entirely on your device.
What it does
Hashes text with MD5, SHA-1, SHA-256, SHA-384, and SHA-512 simultaneously, all computed locally. Paste a known-good hash into the verify field and it tells you which algorithm (if any) matches, so you can confirm a download or message checksum without guessing the algorithm.
How to use it
Type or paste text into the input and every digest updates immediately. To verify a checksum, paste the value you were given into the verify field: matching is case-insensitive, so it works whether the source used upper or lower case hex.
Why this one
Most online hash tools run one algorithm at a time and force you to pick it first. This one computes all five at once, never uploads your text anywhere, and works offline once the page has loaded.
FAQ
- What does hashing an empty input produce?
- The well-known empty-string digests: MD5 d41d8cd98f00b204e9800998ecf8427e, SHA-1 da39a3ee5e6b4b0d3255bfef95601890afd80709, and SHA-256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855. These are standard test vectors, not errors.
- Can I hash a file instead of text?
- You can drop or pick a text file and it is read in as text, then hashed like anything else you paste. Binary files are not supported yet: they would be decoded as text first, which changes the bytes and so changes the digest. Checksums over raw binary files are a planned follow-up.
- Is MD5 or SHA-1 safe to use?
- No, both are cryptographically broken and should never be used for security (password storage, signatures). They are included here only for legacy checksum verification, such as confirming an old download.
Keyboard shortcuts: press ? anywhere on this page to see them.