Free Online Hash Generator for MD5, SHA-1, SHA-256, SHA-384 and SHA-512
Turn text or a file into an MD5, SHA-1, SHA-256, SHA-384 or SHA-512 hash, all of them at once. Useful for checking a download against a published checksum, for a cache key, or for comparing a value you were given. The hashing happens in your browser, so the file and the text never travel to a server.
Enjoying WizTools123? Help keep our server infrastructure 100% free and open for everyone.
MD5 and SHA-1 Are Broken. Use Them Anyway?
It depends entirely on what you are using them for.
| Hash | For security? | What it is still fine for |
|---|---|---|
| MD5 | No | A cache key, a checksum against accidental corruption, an ETag. Anywhere an attacker is not trying to fool you. |
| SHA-1 | No | Git still uses it for object names. Fine for identifying content, not for proving it was not tampered with. |
| SHA-256 | Yes | Everything the other two do, plus signatures, integrity checks and anywhere an attacker might try to forge a match. |
Where Your Input Goes
Nowhere. And you can check that yourself.
How to Generate a Hash
A few steps, and nothing is uploaded.
What to Know About Hashing
Including the things this tool cannot do.
Key Features & Capabilities
What this tool does, and what it deliberately does not.
About the Hash Generator
A hash turns any amount of text into a short fixed-length fingerprint. The same input always gives the same fingerprint, and any change to the input changes it completely. That makes hashes the quiet workhorse behind cache keys, checksums, file identity, ETags and content addressing, and it is why a developer reaches for one several times a week.
This gives you the five that come up most, MD5, SHA-1, SHA-256, SHA-384 and SHA-512, from the same input at once, and it will take a file as well as text. The first three are computed by code written out in the page and checked byte for byte against Node, which matters because the browser own hashing refuses to run on plain http or a local file. There is also a compare box, so a checksum someone published can be checked in one step.
It is honest about which hash to use. MD5 and SHA-1 are broken for anything security depends on, because an attacker can build a collision, but they are still perfectly good for a cache key or a checksum. SHA-256 is the one to reach for when it has to be trustworthy. And no hash is reversible, so a page offering to decrypt one is really just a lookup table of common inputs.
Frequently Asked Questions
Which hash to use, why you cannot reverse one, and what broken means.
Every Other Security Tool
10 more tools in this set. All free, all in your browser.