Free online hash generator — SHA-1, SHA-256, SHA-384, SHA-512

Uses Web Crypto in your browser—paste text, generate digests.

  • SHA family
  • No upload
  • Instant

How this tool fits your workflow

More in this category →

MD5, SHA-1, SHA-256, SHA-512: when to use which

MD5 produces a 128-bit (32 hex character) digest. It was once widely used for checksums and password hashing but is now considered cryptographically broken — collisions can be found in seconds on modern hardware. Use MD5 only for non-security purposes like quick file change detection in trusted environments, never for passwords or digital signatures.

SHA-1 produces a 160-bit (40 hex character) digest. Like MD5, it has known collision vulnerabilities demonstrated in practice (the SHAttered attack in 2017 produced two different PDFs with the same SHA-1 hash). SHA-1 is deprecated for certificate signing and security-critical uses but still appears in Git (for historical reasons) and legacy systems.

SHA-256 is part of the SHA-2 family and produces a 256-bit digest. It is the current standard for most security applications: TLS certificates, digital signatures, Bitcoin proof-of-work, and password hashing schemes like PBKDF2 and scrypt use SHA-256 internally. No practical attacks exist against SHA-256.

SHA-512 provides a 512-bit digest — double the output of SHA-256. It offers a larger security margin and is slightly faster than SHA-256 on 64-bit processors due to wider integer operations. Use SHA-512 when you need extra collision resistance or are designing a system expected to remain secure for many decades.

Using hashes for file integrity

Software distribution sites publish SHA-256 hashes alongside download links so you can verify the file you downloaded matches the official release. After downloading, generate the hash of your file with this tool and compare it against the published value. If they match, the file arrived intact and unmodified.

This verification protects against corrupted downloads, man-in-the-middle substitution, and tampered mirrors. It does not prove the software is safe — it only proves your copy is identical to whatever the publisher hashed. Always verify the hash from the official source, not from a third-party mirror that could post a matching hash for a malicious file.

Hashing passwords: what NOT to do

Never use MD5, SHA-1, SHA-256, or SHA-512 directly to hash passwords — even with a salt. General-purpose hash functions are designed to be fast, which makes them vulnerable to brute-force and dictionary attacks using GPUs. An attacker with modern hardware can compute billions of SHA-256 hashes per second.

For password storage, use a purpose-built slow hash function: bcrypt, scrypt, Argon2, or PBKDF2. These functions are deliberately computationally expensive and have tunable cost factors, making brute-force attacks impractical even with specialized hardware. Argon2 is the current recommended choice for new systems.

The hash generator on this page is the right tool for checksums, data integrity verification, deduplication keys, and content-addressable storage — not for password security.

Frequently asked questions

Can this tool generate MD5 hashes?
This page currently generates SHA-1, SHA-256, SHA-384, and SHA-512 in your browser. MD5 is discussed for education and compatibility context, but MD5 output is not generated on this page.
What is an MD5 hash?
MD5 maps input data to a 128-bit fingerprint represented as 32 hex characters. The same input always gives the same output. It is useful for checksums and legacy compatibility, but not recommended for password security.
Is MD5 encryption?
No. MD5 is a one-way hash function, not encryption. Hashes are designed for integrity and fingerprinting, while encryption is designed for reversible confidentiality with a key.
Why use SHA-256 or SHA-512 instead of MD5?
MD5 has known collision weaknesses. SHA-256 and SHA-512 are much stronger choices for modern integrity and security-sensitive workflows.