Skip to main content
WizTools123
WizTools123
Free Online Tools

Tool Categories


Security Tools New Tool

Free Online Hash Identifier, Work Out What a Hash Is

Paste a hash and the page works out what it is likely to be, from its length, its character set and any prefix. A bcrypt or LDAP prefix gives a certain answer; a bare row of hex gives a family rather than one algorithm, and every candidate is listed with what uses it instead of a single confident guess.

Free Forever Nothing Uploaded Prefix And Length Confidence Stated
Free Online Hash Identifier, Work Out What a Hash Is
Share this tool
Advertisement Slot (Top Banner) Google AdSense Unit • Responsive Banner
Hash Identifier Everything happens in this tab. Nothing you paste is sent anywhere.
The hash
What it looks like
Paste a hash to begin.
What it could be How sure Where it is used

Reading
Part What it says
Buy Us A Coffee

Enjoying WizTools123? Help keep our server infrastructure 100% free and open for everyone.

Buy Us A Coffee
Sponsored Content (Below Tool) Google AdSense Placement

This Identifies a Hash. It Cannot Reverse One.

And neither can the sites that say they can.

A hash throws information away on purpose. There is no key, no trapdoor and no clever arrangement of the bytes that gets the original back, which is the entire reason hashes are used for passwords. A page offering to decrypt one is doing something else: looking the value up in a table of hashes it has already computed from common inputs, or running a cracker against it. If your input was a dictionary word or a popular password, it will be found. If it was random, it will not, no matter how long anyone waits.

Knowing which algorithm you are looking at is still worth a great deal, and it is a different question. It tells you whether a stored password is safe, because bcrypt and Argon2 are slow by design and a bare MD5 is not. It tells you which library call will reproduce the value when you are migrating a user table. And it tells you what a verification failure means: a 60 character string beginning with a dollar sign carries its own salt and cost, so it can be verified anywhere, while 32 characters of hex cannot be verified at all without knowing the salt and where it was joined on.

How to Identify a Hash

A few steps, and nothing is uploaded.

1
Paste one hash Not a list. The page reads the prefix, the length and the character set of the single value you give it.
2
Read the certain part first If the string begins with a dollar sign or a brace, the format names itself and the answer is certain, including the cost or the number of rounds.
3
Treat a bare hex string as a family Thirty two hex characters is MD5, and also NTLM, and also MD4. All of them are listed, because the length genuinely does not choose between them.
4
Look at the parts table Where a format has a salt, a cost and a digest, each one is pulled out and explained, which is usually what you actually needed to know.

What to Know About Identifying a Hash

Including why a length is never a certain answer.

A length identifies a family, never one algorithm. Sixty four hex characters is SHA-256, and equally SHA3-256, BLAKE2s-256, Keccak-256 and several others, because they all produce 256 bits. No tool can tell them apart from the value alone, and one that names a single algorithm is guessing while sounding certain. This page lists every candidate and says how sure it is, which is less satisfying and more honest.
A prefix, on the other hand, is a real answer. The modular crypt format puts the scheme in the string: 2a, 2b and 2y are bcrypt, 5 is sha256crypt, 6 is sha512crypt, argon2id is Argon2, and a brace at the start is the LDAP convention. These strings carry their own salt and work factor, which is why a bcrypt hash can be verified by any library without extra information.
A salt changes nothing about the shape of the digest. A salted MD5 is still 32 hex characters, so this page cannot tell you whether one was used, only that the format has no room for it. That is itself the useful finding: if the value is bare hex, the salt must be stored somewhere else, and whoever wrote the system had to decide how to join it on. Getting that order wrong is a common reason a migration fails to verify old passwords.
This page cannot crack, reverse or verify anything. It reads the shape of a string and tells you what makes that shape. It does not know the password, it cannot check a password against the hash, and it will not tell you whether the hash is of a word in a dictionary. Identification and cracking are different jobs, and only the first one belongs in a browser tab.

Key Features & Capabilities

What this tool does, and what it deliberately does not.

Certain where it can be bcrypt, Argon2, sha256crypt, sha512crypt, md5crypt, PBKDF2, scrypt, phpass and LDAP by prefix.
Every candidate listed For a bare hex or base64 string, all the algorithms that produce that length.
The parts pulled out Cost, rounds, salt and digest separated and explained where the format has them.
Says which are slow Whether the format is built for passwords, or is a fast hash that should not be.
Confidence on every row Certain, likely or possible, so a guess is never dressed up as a fact.
Nothing uploaded The whole thing is pattern matching in the page, with no lookup anywhere.

About Identifying Hashes

Hashes turn up without labels. A column in an old database, a line in a configuration file, a value in an API response, and no note anywhere saying what produced it. Identifying it matters for two ordinary reasons: you are migrating a user table and need the same function to reproduce the value, or you are assessing a system and need to know whether its stored passwords are protected by something slow or by a bare fast hash.

The identification itself is pattern matching, and how well it works depends entirely on the format. Anything in the modular crypt format announces itself: the scheme, the cost and the salt are all in the string, separated by dollar signs, which is what lets a bcrypt hash be verified by any library on any machine. The LDAP convention does something similar with braces. In those cases the answer is certain and the interesting part is the parameters, so this page pulls them out and says what they mean.

A bare row of hex is a different matter. The length narrows it to the output size, and several algorithms share every common size, so the honest answer is a list. That is the main design decision here: no single confident guess, a ranked set of candidates with a confidence on each and a note about what uses it. The alternative, picking the most popular one and presenting it as the answer, is how people end up migrating a table with the wrong function and discovering the problem when nobody can log in.

Frequently Asked Questions

Lengths, prefixes, and what this cannot do.

No, and nor can anything else. A hash discards information, so there is no way back. Sites that offer to decrypt one are looking the value up in a table of precomputed hashes of common inputs, which finds dictionary words and popular passwords and nothing else.

Because the length only tells you the output is 128 bits. MD5, MD4 and NTLM all produce that, and NTLM is simply MD4 of the password in UTF-16. The value alone cannot distinguish them, which is why all three are listed with where each is used.

They separate the fields of the modular crypt format: the scheme, then the cost, then the salt and digest together. So 2y names bcrypt, the number after it is the work factor as a power of two, and the rest is 22 characters of salt followed by 31 of digest, in bcrypt own base64 alphabet.

Not from a bare hex string, no. Salting does not change the length of the digest, so a salted MD5 looks exactly like an unsalted one. Formats designed for passwords put the salt inside the string, which is one of the reasons they are better.

No. The identification is pattern matching that runs in your browser, with no lookup service behind it. That is also why it cannot tell you anything about the original input: there is nothing to look the value up in.

Every Other Security Tool

10 more tools in this set. All free, all in your browser.

Advertisement Slot (Bottom Banner) Google AdSense Unit • Responsive Banner