Free Online Hash Identifier, Work Out What a Hash Is
Paste a hash and the page works out what it is likely to be, from its length, its character set and any prefix. A bcrypt or LDAP prefix gives a certain answer; a bare row of hex gives a family rather than one algorithm, and every candidate is listed with what uses it instead of a single confident guess.
| What it could be | How sure | Where it is used |
|---|
Enjoying WizTools123? Help keep our server infrastructure 100% free and open for everyone.
This Identifies a Hash. It Cannot Reverse One.
And neither can the sites that say they can.
A hash throws information away on purpose. There is no key, no trapdoor and no clever arrangement of the bytes that gets the original back, which is the entire reason hashes are used for passwords. A page offering to decrypt one is doing something else: looking the value up in a table of hashes it has already computed from common inputs, or running a cracker against it. If your input was a dictionary word or a popular password, it will be found. If it was random, it will not, no matter how long anyone waits.
Knowing which algorithm you are looking at is still worth a great deal, and it is a different question. It tells you whether a stored password is safe, because bcrypt and Argon2 are slow by design and a bare MD5 is not. It tells you which library call will reproduce the value when you are migrating a user table. And it tells you what a verification failure means: a 60 character string beginning with a dollar sign carries its own salt and cost, so it can be verified anywhere, while 32 characters of hex cannot be verified at all without knowing the salt and where it was joined on.
How to Identify a Hash
A few steps, and nothing is uploaded.
What to Know About Identifying a Hash
Including why a length is never a certain answer.
Key Features & Capabilities
What this tool does, and what it deliberately does not.
About Identifying Hashes
Hashes turn up without labels. A column in an old database, a line in a configuration file, a value in an API response, and no note anywhere saying what produced it. Identifying it matters for two ordinary reasons: you are migrating a user table and need the same function to reproduce the value, or you are assessing a system and need to know whether its stored passwords are protected by something slow or by a bare fast hash.
The identification itself is pattern matching, and how well it works depends entirely on the format. Anything in the modular crypt format announces itself: the scheme, the cost and the salt are all in the string, separated by dollar signs, which is what lets a bcrypt hash be verified by any library on any machine. The LDAP convention does something similar with braces. In those cases the answer is certain and the interesting part is the parameters, so this page pulls them out and says what they mean.
A bare row of hex is a different matter. The length narrows it to the output size, and several algorithms share every common size, so the honest answer is a list. That is the main design decision here: no single confident guess, a ranked set of candidates with a confidence on each and a note about what uses it. The alternative, picking the most popular one and presenting it as the answer, is how people end up migrating a table with the wrong function and discovering the problem when nobody can log in.
Frequently Asked Questions
Lengths, prefixes, and what this cannot do.
Every Other Security Tool
10 more tools in this set. All free, all in your browser.