Hash Generator
Paste text or choose a file to see its MD5 and SHA-family hashes side by side, optionally as HMACs with a secret key, and check them against a published checksum.
Overview
Hashing produces a fixed-length, deterministic fingerprint of input text — the same input always produces the same hash, and even a one-character change produces a completely different one. That makes hashes useful for checksums (confirming a file or string wasn't altered), for comparing two values without revealing either, and for generating stable identifiers from arbitrary text.
Examples & Sample Data
Every algorithm at once
Adikya
SHA-256: 8ad45d866401c5ede55291cac4ff580d2767e5c47f726ddbd709ee240ccdfb83 (MD5, SHA-1, SHA-384, and SHA-512 are listed alongside it)
HMAC with a secret key
Text: what do ya want for nothing? Key: Jefe
HMAC-MD5: 750c783e6ab0b503eaa86e310a5db738
How It Works
- Choose Text and type or paste your input, or choose File and pick a file (you can also drop one onto the tool).
- Read the MD5, SHA-1, SHA-256, SHA-384, and SHA-512 hashes, which update as you type.
- To create an HMAC, enter a secret key. Every row switches to HMAC-MD5, HMAC-SHA-256, and so on.
- Pick hex or Base64 output, then copy any row.
- To verify a download, paste its published checksum into the compare field. The matching algorithm is highlighted.
Tips & Best Practices
- An HMAC proves a message came from someone holding the key; a plain hash only proves it wasn't changed. Webhook signatures (for example X-Hub-Signature-256) are usually HMAC-SHA-256 of the raw request body.
Frequently Asked Questions
No. Hashing runs entirely in your browser, using the Web Crypto API for the SHA family and a built-in implementation for MD5. Nothing you type or choose is transmitted anywhere.
Not for security. MD5 collisions can be produced cheaply, so never rely on it for signatures or passwords. It's still fine as a quick checksum against accidental corruption, which is why it's included here next to SHA-256.
No. A plain hash without salting and a slow key-derivation function (like bcrypt or Argon2) is unsafe for password storage — this tool is for checksums and general-purpose hashing, not authentication.
SHA-256 is the standard default for most checksum and integrity-check use cases — it balances output length and collision resistance well for general purposes.
Yes. Choose File, or drop a file onto the tool. It's read and hashed locally in your browser, up to 512 MB, and never leaves your device.
Choose the file, then paste the checksum from the download page into the compare field. Hex in any case or Base64 both work, and the row whose hash matches is highlighted.
Related Tools
Explore more high-performance utilities.