/tools/hash-generator

Hash Generator

Compute cryptographic hashes of text or a file, and compare them against an expected checksum to verify a download.

Hash GeneratorRuns in your browser
Computed locally. Hashing uses the Web Crypto API in your browser. Files are read from disk and never uploaded, so verifying a large download costs no bandwidth.
Input
Algorithms

How to use the Hash Generator

  1. Choose Text or File, then enter your text or pick a file.
  2. Tick the algorithms you need — SHA-256 is the standard choice.
  3. To verify a download, paste the publisher's checksum into the compare box before generating.

What a hash is for

A cryptographic hash turns any input into a fixed-length fingerprint. The same input always produces the same hash; changing a single bit produces a completely different one. Crucially, the process is one-way — you cannot recover the input from the hash.

That gives it two main uses. Integrity checking: hash a downloaded file and compare with the publisher's figure to confirm nothing was corrupted or tampered with in transit. Deduplication and identity: two files with the same SHA-256 are, for all practical purposes, the same file.

Which algorithm to use

AlgorithmOutputStatus
SHA-25664 hex charactersThe default. Secure and universally supported.
SHA-38496 charactersSecure. Used where a larger margin is specified.
SHA-512128 charactersSecure, and often faster than SHA-256 on 64-bit hardware.
SHA-140 charactersBroken. Practical collisions demonstrated in 2017. Offered only for reading legacy checksums.

MD5 is absent deliberately. It has been comprehensively broken for years and should not be used even for non-security checksums, since a stronger option costs nothing.

Hashing is not encryption — and not password storage

Encryption is reversible with a key; hashing is not reversible at all. If you need to get the data back, you need encryption.

Nor should a plain SHA hash be used to store passwords. Fast hashes are the problem: modern hardware computes billions of SHA-256 operations per second, so a leaked database of SHA-256 password hashes falls quickly to a dictionary attack. Password storage requires a deliberately slow, salted algorithm — Argon2, scrypt or bcrypt — which makes each guess expensive.

Frequently asked questions

Can a hash be reversed?

No. But a short or common input can be found by guessing — attackers compute hashes of billions of likely values and look for a match. That is why unique salts matter for password storage.

How do I verify a downloaded file?

Switch to File mode, choose the download, paste the checksum published on the official site into the compare box, and generate. A match confirms the file is byte-identical.

Is my file uploaded to check it?

No. The file is read locally and hashed with the Web Crypto API. Nothing crosses the network, which is why hashing a 100 MB file costs no bandwidth.

Why is MD5 not offered?

It is cryptographically broken — collisions can be produced in seconds. Since SHA-256 is available everywhere and just as easy, there is no reason to offer a weaker option.

Do the same bytes always give the same hash?

Yes, on any machine and in any implementation. That determinism is what makes checksums useful for verification.

Related tools