Hash Generator

Compute MD5, SHA-1, SHA-224, SHA-256, SHA-512 and RIPEMD-160 digest values for text or files — useful for file integrity checks, password hashing tests and more. Drag in multiple files at once for batch hashing.

Runs 100% in your browser — your text and files are never sent to a server.
Drop the files you want to hash, or click to select
You can select multiple files — computing may take a few seconds for large files

What Is a Hash Function, and What Is It Used For?

A hash (digest) function is a one-way mathematical operation that always produces a fixed-length output — the digest — no matter whether the input is a single character or a multi-gigabyte file. This property is deterministic: the same input always yields the same digest, regardless of which device or when it's run; but changing even a single character in the input (thanks to the avalanche effect) results in a hash that's completely different, with no resemblance to the original.

Critical distinction: Hashing is NOT encryption. Encryption involves a "decrypt" operation that reverses the data using a key; hash functions have no such reverse defined — there's no mathematical way to go from the digest back to the original data. That's why hashes aren't used to "hide" something, but to verify a piece of data's integrity or produce a unique fingerprint for it.

The most common use is file integrity checking: when you download a piece of software, you can compare the hash you compute yourself against the official value published on the site to confirm the file wasn't corrupted or maliciously altered during download. It's also widely used in version control systems (Git commit hashes), for detecting duplicate content in large datasets (deduplication), and for taking a "fingerprint" of a file to track whether it changes afterwards.

Security note: MD5 and SHA-1 are now considered cryptographically broken — researchers have found practical collision attacks that let two different inputs produce the same hash. This is still fine for harmless uses like file integrity, but SHA-256 or higher should be preferred for security-critical work like password storage or digital signatures. In this tool, SHA-1/256/512 are computed using the browser's built-in Web Crypto API (crypto.subtle), MD5 via SparkMD5, and SHA-224 and RIPEMD-160 (which Web Crypto does not support) via crypto-js — your input is never sent to a server at any stage.

Try This Next

Finished here? These might be your next step.

Frequently Asked Questions

For file integrity checks (verifying a downloaded file isn't corrupted), SHA-256 is usually enough. MD5 and SHA-1 are still widely used but are considered broken from a security standpoint — don't use them for security-critical work like password storage or signature verification.

Yes — this is a fundamental property of these hash functions (deterministic). The same input always produces the same output, regardless of which device or when it's run. Changing even a single character results in a completely different hash.

No, absolutely not. Encryption involves an operation that decrypts data back using a key; hash functions have no such "reverse" operation defined — the digest is mathematically derived from the input, but there's no way back from the digest to the input (a one-way function). This is why hashes are used to "digest" data like passwords, not to "encrypt" it.

For MD5 (2004) and SHA-1 (2017), cryptographic researchers found practical collision attacks that let two different inputs produce the same hash. This doesn't affect harmless uses like file integrity checks, but they're no longer considered secure for work whose security depends on that property — digital signature verification, certificate generation, or password storage. SHA-256 or the SHA-3 family should be preferred for that kind of work.

Most software download pages publish the file's official SHA-256 (sometimes MD5) value. Drag the file you downloaded into this tool and compare the computed hash against the value published on the site; if they match exactly, the file wasn't corrupted or tampered with during download. Even a single differing byte produces a completely different hash, so the comparison is very reliable.

No, this isn't recommended. A raw SHA-256 (or any general-purpose hash) is computed very fast, which means attackers can try and match billions of candidate passwords within seconds (brute-force/rainbow tables). Password storage should use algorithms specifically designed for it — deliberately slow and salted, such as bcrypt, scrypt, or Argon2.

Last updated: