Hash Generator
Generate SHA-1, SHA-256, SHA-384, and SHA-512 hashes for text.
- SHA-1
- SHA-256
- SHA-512
- Copy Output
- Browser Crypto
Choose an action to generate output.
Generate exact text hashes, file checksums, and HMACs locally
Generate multiple cryptographic hashes or checksums from the exact UTF-8 bytes of text, or stream local files through chunked hashers without loading the complete file into browser memory.
HMAC combines a secret key with a compatible cryptographic hash for message authentication, while expected-value comparison verifies published digests without manual character-by-character checks.
How to generate or verify a hash
- Choose Text or File. Enter exact text with optional prefix and suffix, or browse or drop a local file.
- Choose Hash or HMAC, select one or more compatible algorithms, and enter an HMAC secret when required.
- Choose hexadecimal or Base64 output, plus optional uppercase or grouped hexadecimal display.
- Optionally paste an expected hash, generate the results, and review the explicit Match or No match state.
- Copy one result, copy all results, or export the exact result set and source metadata as JSON.
Choose the digest that matches the security requirement
- Use SHA-256 or a stronger modern digest for new integrity workflows and the exact algorithm named by a trusted checksum publisher for compatibility.
- Treat MD5 and SHA-1 as legacy integrity formats only because collision attacks make them unsafe for security decisions.
- Treat CRC32 as accidental-error detection rather than cryptographic tamper protection.
- Use HMAC only when the sender and verifier already share and protect the same secret key.
- Use Argon2, scrypt, bcrypt, or PBKDF2 rather than a fast hash or HMAC for password storage.
- Keep text, key material, and chunk-streamed files local; exported JSON never includes the HMAC secret.
Hash Generator FAQ
Which hash should I use?
SHA-256 is the practical default for general integrity checks. Use the exact algorithm required by the system or trusted checksum publisher when compatibility matters.
Are large files uploaded or loaded all at once?
No. Files stay local and are read in 4 MB chunks, so the browser never needs the whole file in memory as one buffer.
Why do line endings or spaces change a text hash?
A digest covers exact bytes. LF and CRLF line endings, whitespace, capitalization, Unicode representation, prefixes, and suffixes all change the byte sequence.
Does HMAC encrypt the input?
No. HMAC authenticates data with a shared secret but does not hide or encrypt that data.
Can expected hashes contain separators?
Hexadecimal comparison ignores letter case and common spaces, colons, and hyphens. The generated and exported digest remains exact.
Can MD5 or SHA-1 protect passwords or signatures?
No. They are present only for legacy checksum matching and must not be used for security-sensitive decisions.
Are files or HMAC keys sent to a server?
No. Hashing, HMAC, verification, formatting, copying, and export creation all happen locally in the browser.
Help us improve this tool
Please share what we should improve, add, or fix. You can write in the language you are comfortable with. We only save your suggestion and IP address to prevent misuse.