Hash Calculator
MD5, SHA-1, SHA-256, SHA-384 and SHA-512 in one pass
Digest length 32 bytes
Last updated: 2026-10-09
About this tool
A hash maps content of any length onto a fixed-length fingerprint. It is used to check whether a file is intact, whether content has been tampered with, and as a basis for deduplication and caching. This tool computes all five common algorithms for the same text at once, and can also hash a file directly so you can verify a downloaded package.
Features
Five common algorithms
Covers the ones you actually run into: MD5 for checksums, SHA-1 in legacy systems and Git objects, SHA-256 as the current default, and SHA-384 / SHA-512 for higher strength.
File checksum verification
Pick a file to get its digest and check whether a download matches the value published by the vendor. The file is read locally and never uploaded.
All results in parallel
In text mode all five digests are listed at once, so you do not have to switch algorithms back and forth; each row has its own copy button.
Clear security guidance
MD5 and SHA-1 both have practical collision attacks. The interface says so directly, preventing them from being misused for signatures or password storage.
How to use
- 1
Pick a mode
Use Text to hash a string, or File to verify a downloaded file.
- 2
Pick an algorithm
Click an algorithm name. In text mode all five results are shown at once; in file mode switching recomputes from the already-read content without touching the disk again.
- 3
Provide the input
Type or paste in text mode; choose a file in file mode, where large files show a computing indicator first.
- 4
Copy and compare
Copy the result and compare with the published value. Comparison is case-insensitive; this tool emits lowercase hex.
Options
- Digest length
- MD5 is 16 bytes, SHA-1 20, SHA-256 32, SHA-384 48 and SHA-512 64. In hex the string is twice as many characters as bytes.
- Where MD5 stands
- MD5 collisions can be deliberately constructed, so it must not be used for signatures or password storage. It remains useful as a fast "did the content change" checksum, and many systems still use it for ETags.
- File size limit
- Browser memory bounds the practical size; keeping files under 100MB is recommended. For anything larger, use a command-line tool such as sha256sum to avoid a sluggish page.
Common use cases
- Verify a downloaded installer against the SHA-256 published by the vendor
- Check whether two files hold identical content (faster than a byte-by-byte diff)
- Generate a fingerprint for a build artifact to drive cache invalidation
- Confirm nothing changed unexpectedly during a data migration
- Compute a digest of a text block to use as a deduplication key
- Quickly tell whether a local file and a server copy are in sync
FAQ
Questions you may have about this tool
What is the difference between hashing and encryption?
Hashing is one-way: you can compute a digest from content but cannot recover the content from the digest, and collisions are theoretically possible. Encryption is reversible with the right key. So hashing is for verification and fingerprints, encryption for confidentiality.
Can MD5 still be used?
It depends on the purpose. As a file checksum or a deduplication key it is still usable, but it must never be used for digital signatures or password storage, because collisions can be deliberately constructed. Use SHA-256 or stronger for security.
Should I choose SHA-256 or SHA-512?
SHA-256 is the most widely compatible choice with good performance. SHA-512 is comparable or even faster on 64-bit platforms and gives a longer, stronger digest. Unless a system you integrate with specifies otherwise, SHA-256 is the sensible default.
Why does changing one character change the whole digest?
That is the avalanche effect, a core property of hash functions. Flipping any input bit flips roughly half the output bits, so a digest tells you only "it changed", never how much or where.
Can a hash be reversed to the original?
No. Hashing is a one-way function. What is loosely called "cracking" is really guessing common inputs (such as weak passwords) via rainbow tables or brute force; recovering an arbitrary input from its digest is not possible.
What encoding is used for Chinese text?
The bytes after UTF-8 encoding. The same Chinese string hashes completely differently under another encoding such as GBK, so both sides must agree on an encoding when comparing across systems. UTF-8 is the current default.
What is the hash of empty content?
It is a fixed non-empty value, for example the SHA-256 of an empty string begins with e3b0c44298fc. This tool shows nothing for empty input; type a single space to watch the value change.
Does hashing upload my file?
No. Reading and computing happen entirely in the browser. The SHA family uses the native WebCrypto API for speed; MD5 is implemented in this tool because the native API does not provide it.