Hash generator
Calculate the hash of a text or a file, compare it with the one you expect, and check that a download was not altered. Files are read in chunks, even the largest ones.
It is calculated on the exact text, including its spaces and line breaks.
Drop your files hereTap to choose your files
or click to chooseAny type of file · no size limit
Processed on your device: nothing is uploaded
Files are read in chunks on your device: they are not uploaded and do not use extra memory, so you can verify disk images of several GB.
Algorithms 4
Input, output, and HMAC
It is used as UTF-8 text. The key is not saved and never leaves your browser.
Type or paste some text to see its hashes instantly.
Choose at least one algorithm to see the result.
Works with hexadecimal or Base64, with or without a prefix like “sha256:”. With files you can also paste the contents of a checksum file (SHA256SUMS).
It is processed in your browser. It is not saved, not sent, and does not appear in the page address.
Each extra point doubles the calculation time, and also the time someone trying to guess the password would need.
Paste a complete bcrypt or Argon2 hash. We check whether the password above matches.
Type a password to get started.
How to use it
- Choose whether you will process a text, one or more files, or a password.
- Type or paste the text, or drag the files in. Hashes are calculated instantly with the algorithms you picked.
- Open “Algorithms” to turn on SHA-3, BLAKE3, CRC32, or others, and “Output format and HMAC” to switch between hexadecimal and Base64 or to sign with a key.
- Paste the hash the author published into “Compare with a known hash”. We tell you whether it matches and with which algorithm.
- Copy a single hash with its button, or use “Copy all” and “Download” to save the list.
Frequently asked questions
Are my texts and files uploaded to a server?
No. The calculation runs in your browser with WebAssembly. Files are read in chunks from your disk and never leave your device, so you can check private documents or multi-gigabyte disk images.
How do I check that a download is not corrupted?
Drag the file in, turn on the algorithm the site publishes (almost always SHA-256), and paste the official hash into “Compare with a known hash”. If it matches, the file is identical to the original. You can also paste the contents of a SHA256SUMS file to verify several files at once.
Are MD5 and SHA-1 still secure?
Not for security. Collisions have been demonstrated in both, so they are not suitable for signatures, certificates, or passwords. They are still useful for detecting copy or download errors. For security, use SHA-256 or higher.
What is HMAC and when is it used?
HMAC combines a hash with a secret key to check that a message was not altered and that it was signed by someone who knows the key. It is used in webhook signatures, JWT tokens (HS256), and APIs. Turn on “Sign with a secret key” and enter the key.
How do I store passwords securely?
Not with plain MD5 or SHA-256: they are too fast, and millions of guesses per second can be tried. Use a slow, salted algorithm such as Argon2id or bcrypt, which you can generate and verify in the “Passwords” tab.
Why does the hash of my text not match another tool’s?
Almost always it is an invisible character: a trailing newline, extra spaces, or a different encoding. Here the text is processed exactly as you type it, in UTF-8. In a terminal, use “echo -n” so no newline is added.
What is a hash
A hash is a digital fingerprint of a piece of data: a fixed-length string calculated from its contents. If you change a single character of the original, the hash changes completely. It also works one way only: you cannot recover the original from the hash.
What it is for
- Verifying downloads: comparing the published hash with your file’s hash proves it was not corrupted or tampered with.
- Finding duplicates: two files with the same hash are almost certainly identical.
- Signing messages: with HMAC, the hash includes a secret key.
- Storing passwords: with slow algorithms such as bcrypt or Argon2id.
Which algorithm to choose
SHA-256 is the default choice for almost everything. SHA-512 and SHA-3 offer a larger margin. BLAKE3 is very fast with large files. MD5 and SHA-1 are broken for security, but are still published for integrity checks. CRC32 detects transmission errors, not attacks.
Updated on September 29, 2026