What is a hash function?
A hash function takes any input, a single character, a sentence, a multi-gigabyte file, and produces a fixed-length string of hex characters that depends on every byte of the input. Change one bit anywhere, and the entire output changes unpredictably. The same input always produces the same hash.
This makes hashes useful for two everyday jobs:
1. Integrity checks. "I downloaded a file. Did it arrive intact?" Hash the file, compare against the published value. Match → identical bytes; mismatch → corruption or tampering. 2. Deterministic IDs. "I need a short, stable identifier for this longer string." Hash it; use the first 8–12 hex chars as a cache key, ETag, or version tag.
Hashes are not encryption, there's no key, and you can't reverse a hash back to the original input. They're also not all created equal: MD5 and SHA-1 are broken for security purposes (collision attacks are practical) but remain useful as fast checksums where a malicious adversary isn't in scope.
How to use this tool
The tool runs in two modes, Generate and Identify, toggled by the segmented control at the top.
Generate mode
Type or paste any text into the input. As you type, four hashes update in the output rows below: MD5, SHA-1, SHA-256, SHA-512. Each row has its own copy button so you don't have to select-and-copy a long hex string by hand. The "Sample" button drops in a stable test phrase so you can sanity-check that the hashes match published reference values.
All four hashes are computed simultaneously, so the latency is dominated by SHA-512, usually under a millisecond for short text, a few milliseconds for longer text.
Identify mode
Paste a hash and the tool tells you which algorithm produced it, based on length:
- 32 chars → MD5 (128 bits)
- 40 chars → SHA-1 (160 bits)
- 64 chars → SHA-256 (256 bits)
- 96 chars → SHA-384 (256 bits, less common)
- 128 chars → SHA-512 (512 bits)
If the input isn't valid hex, or the length doesn't match a known algorithm, the badge turns red. (Length-based identification is heuristic, NTLM hashes, for example, are also 32 chars and look identical to MD5.)
Which hash should I use?
For new code: SHA-256. It's the modern default, broadly supported, fast on every CPU made in the last decade, and has no known practical collisions.
For verifying a download where the publisher gave you an MD5 or SHA-1: use what they published. The hash you get from the publisher is the trust anchor, if MD5 from the publisher matches MD5 of the file you downloaded, the file wasn't corrupted in transit. (It doesn't prove the publisher wasn't compromised, just the in-transit integrity.)
For password storage: none of these. Use a password-derivation function, bcrypt, scrypt, or Argon2, designed to be slow and to incorporate a salt. Plain SHA-256 of a password is trivially crackable with a rented GPU.
Why is MD5 here if it's "broken"?
MD5's brokenness is specifically about collision resistance, given enough compute, an attacker can construct two different inputs that hash to the same MD5. This matters when MD5 is used as a digital signature or as the basis of a security check: a forger could craft a malicious file whose MD5 matches a benign file's.
For non-adversarial integrity checks (file corruption, accidental duplication, build cache keys), MD5 is fine and significantly faster than SHA-256. It also remains the most commonly published checksum on legacy software, so the tool would be incomplete without it.
Privacy
The text you hash and the hashes you identify are processed entirely in your browser via the Web Crypto API (and a small inline MD5 implementation, since Web Crypto removed MD5 for security reasons). No bytes are uploaded to any server.