Hash Generator: MD5, SHA-1, SHA-256, SHA-512 and HMAC

  • Free
  • No sign-up
  • Runs in your browser
  • Last updated 2026-10-07
Report a problem

Type text or choose a file to get its hash in five algorithms at once, or add a secret key to compute an HMAC.

Everything you enter is processed in your browser and is never sent to a server.

How to use

  1. Type or paste text, or choose a file with Or hash a file. The hashes update as you type.
  2. Tick HMAC with a secret key and enter a key if you need a keyed hash instead of a plain hash.
  3. Press Copy next to the algorithm you need. Tick Uppercase if you want capital letters.

Examples

abc
→ SHA-256: ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad
MD5 of the same text is 900150983cd24fb0d6963f7d28e17f72.
(empty text)
→ MD5: d41d8cd98f00b204e9800998ecf8427e
The SHA-256 of empty text is e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855.
Text: The quick brown fox jumps over the lazy dog. HMAC key: key
→ HMAC-SHA256: f7bc83f430538424b13298e6aa6fb143ef4d59a14946175997479dbc2d1a3cd8

How it works

Text is converted to bytes with UTF-8 and then hashed. SHA-1, SHA-256, SHA-384 and SHA-512 are computed with the browser’s built-in Web Crypto API. MD5 is not part of Web Crypto, so it comes from the open-source hash-wasm library.

The result is written as lowercase hexadecimal: two characters per byte, so MD5 gives 32 characters, SHA-1 gives 40, SHA-256 gives 64, SHA-384 gives 96 and SHA-512 gives 128.

With a key, the tool computes an HMAC with the same hash function, following RFC 2104. When you choose a file, the hash is computed over the raw bytes of the file.

Sources

Frequently asked questions

Which algorithm should I use?
For checking that data was not changed, use SHA-256 or stronger. MD5 and SHA-1 are broken for security purposes because different inputs with the same hash can be created on purpose, so use them only to match an existing checksum that was published with them.
Can I use these hashes to store passwords?
No. Fast hashes like SHA-256 are easy to brute-force. Passwords should be stored with a slow password hashing function such as Argon2, bcrypt or scrypt, with a unique salt.
What is HMAC?
HMAC mixes a secret key into the hash, so only someone with the key can produce or check the value. It is used to sign messages and API requests, for example in webhook signatures.
Why does my hash differ from another tool?
The most common reasons are a different text encoding (this tool uses UTF-8), a trailing newline or space, or Windows line breaks (CRLF) against Unix ones (LF). Hashing a file avoids these differences.
Is my text or file uploaded?
No. Hashing runs in your browser. Files up to 200 MB can be hashed, and they are never sent to a server.

Last updated: