What is a hash function?

A hash function takes any input, a single character, a sentence, a multi-gigabyte file, and produces a fixed-length string of hex characters that depends on every byte of the input. Change one bit anywhere, and the entire output changes unpredictably. The same input always produces the same hash.

This makes hashes useful for two everyday jobs:

1. Integrity checks. "I downloaded a file. Did it arrive intact?" Hash the file, compare against the published value. Match → identical bytes; mismatch → corruption or tampering. 2. Deterministic IDs. "I need a short, stable identifier for this longer string." Hash it; use the first 8–12 hex chars as a cache key, ETag, or version tag.

Hashes are not encryption, there's no key, and you can't reverse a hash back to the original input. They're also not all created equal: MD5 and SHA-1 are broken for security purposes (collision attacks are practical) but remain useful as fast checksums where a malicious adversary isn't in scope.

How to use this tool

The tool runs in two modes, Generate and Identify, toggled by the segmented control at the top.

Generate mode

Type or paste any text into the input. As you type, four hashes update in the output rows below: MD5, SHA-1, SHA-256, SHA-512. Each row has its own copy button so you don't have to select-and-copy a long hex string by hand. The "Sample" button drops in a stable test phrase so you can sanity-check that the hashes match published reference values.

All four hashes are computed simultaneously, so the latency is dominated by SHA-512, usually under a millisecond for short text, a few milliseconds for longer text.

Identify mode

Paste a hash and the tool tells you which algorithm produced it, based on length:

  • 32 chars → MD5 (128 bits)
  • 40 chars → SHA-1 (160 bits)
  • 64 chars → SHA-256 (256 bits)
  • 96 chars → SHA-384 (256 bits, less common)
  • 128 chars → SHA-512 (512 bits)

If the input isn't valid hex, or the length doesn't match a known algorithm, the badge turns red. (Length-based identification is heuristic, NTLM hashes, for example, are also 32 chars and look identical to MD5.)

Which hash should I use?

For new code: SHA-256. It's the modern default, broadly supported, fast on every CPU made in the last decade, and has no known practical collisions.

For verifying a download where the publisher gave you an MD5 or SHA-1: use what they published. The hash you get from the publisher is the trust anchor, if MD5 from the publisher matches MD5 of the file you downloaded, the file wasn't corrupted in transit. (It doesn't prove the publisher wasn't compromised, just the in-transit integrity.)

For password storage: none of these. Use a password-derivation function, bcrypt, scrypt, or Argon2, designed to be slow and to incorporate a salt. Plain SHA-256 of a password is trivially crackable with a rented GPU.

Why is MD5 here if it's "broken"?

MD5's brokenness is specifically about collision resistance, given enough compute, an attacker can construct two different inputs that hash to the same MD5. This matters when MD5 is used as a digital signature or as the basis of a security check: a forger could craft a malicious file whose MD5 matches a benign file's.

For non-adversarial integrity checks (file corruption, accidental duplication, build cache keys), MD5 is fine and significantly faster than SHA-256. It also remains the most commonly published checksum on legacy software, so the tool would be incomplete without it.

Privacy

The text you hash and the hashes you identify are processed entirely in your browser via the Web Crypto API (and a small inline MD5 implementation, since Web Crypto removed MD5 for security reasons). No bytes are uploaded to any server.

Frequently asked

Are my hashes computed in the browser?

Yes. SHA-1, SHA-256, and SHA-512 use the browser's Web Crypto API (crypto.subtle.digest). MD5 uses a small inline JavaScript implementation because Web Crypto removed MD5 support for security reasons. Nothing is uploaded — your input never leaves the device.

Can I use MD5 to store passwords?

No. Use a password-derivation function designed for the job: bcrypt, scrypt, or Argon2. They are intentionally slow (to make brute-force expensive) and incorporate a per-user salt. Plain MD5 or SHA-256 of a password is crackable with a rented GPU in minutes.

Why include MD5 if it's cryptographically broken?

MD5's brokenness applies to collision resistance — relevant when MD5 is used as a security signature. For non-adversarial integrity checks (file corruption, build cache keys, deterministic IDs), MD5 is fine and faster than SHA-256. Most legacy software still publishes MD5 checksums, so the tool would be incomplete without it.

Why are the same hashes always the same length?

By design. A hash function maps any-length input to a FIXED-length output: MD5 = 128 bits = 32 hex chars, SHA-1 = 160 bits = 40 hex chars, SHA-256 = 64 hex chars, SHA-512 = 128 hex chars. The fixed length is what makes the value usable as a key, signature, or checksum.

What does 'identify' mode do?

It guesses which algorithm produced a hash based on its length. 32 chars likely means MD5; 40 = SHA-1; 64 = SHA-256; 96 = SHA-384; 128 = SHA-512. The match is heuristic — NTLM hashes, for example, are also 32 chars and indistinguishable from MD5 by length alone.

Can I hash a file?

Not in this tool — only text. To hash a file, paste its contents (works for small text files) or use your operating system's built-in command: 'shasum -a 256 file' on macOS/Linux, 'Get-FileHash -Algorithm SHA256 file' in PowerShell.

Why does the same input give a different hash on a different machine?

It shouldn't — hashes are deterministic. If you see different output, the most common cause is invisible whitespace (a trailing newline, a Windows CRLF vs Unix LF, a non-breaking space). Open the input in a hex viewer to spot it.

What's the difference between a hash and an HMAC?

An HMAC is a hash with a secret key mixed in. Without the key, you can't compute or verify the HMAC — so an HMAC proves both integrity (the message wasn't changed) AND authenticity (the message came from someone who has the key). A plain hash only proves integrity.