Get the SHA-256 of any file or text in seconds

Verifying downloads shouldn't need a command line. Drop a file or paste text for instant SHA-1, SHA-256, SHA-384 and SHA-512 digests. Use and copy results free — no account needed.

abcSHA-256ba7816bf8f01cfea414140de

Paste text to hash…

or drop any file — get all four SHA digests to copy

What you can do with Hash Generator

Everything this tool helps you accomplish — no learning curve, no setup.

  • Generate SHA-256 hashes from any text
  • Create SHA-1, SHA-384 and SHA-512 digests
  • Verify file integrity with a checksum
  • Compute hashes for uploaded files
  • Fingerprint passwords or tokens as hex
  • Compare downloads against expected checksums

Settings information

Every control in Hash Generator, explained — what it does and when to use it.

Settings

SourceDropdown
Switches what gets hashed between pasted text and a chosen file — pick File to verify a download's checksum or Text to fingerprint a pasted string.Options: TextFile
FileFile input
Choose file picker shown when Source is set to File; selecting a new file instantly recomputes all five checksums for that file.
Uploads are encrypted in transitRemoved under our retention policy

Done with Hash Generator? Try these next

Hand-picked tools that pair well with Hash Generator. Keep going without losing your file.

View all tools

Frequently Asked Questions

SHA-1, SHA-256, SHA-384 and SHA-512 — every algorithm exposed by the browser's Web Crypto API. The digest is shown as a lowercase hexadecimal string, which is the format expected by checksum files, package manifests and HMAC tooling.

features

They differ in output length and design generation. SHA-256 is the modern default for integrity checks and most blockchain use. SHA-384 and SHA-512 produce longer digests that resist length-extension attacks. SHA-1 is shown for legacy compatibility but is no longer considered safe against collision attacks.

technical

No — both are broken against deliberate collision attacks, so never use them for passwords, signatures or any security-sensitive work. They are included here purely for legacy compatibility: verifying old download checksums, ETags and existing manifests. For anything new, use SHA-256 or longer; for non-security uses like cache keys, SHA-256 truncated to the size you need works well.

technical

Both. Paste a string or drop a file into the input box — the tool reads the file as a binary stream and feeds it directly to the hashing API, so the digest matches the one produced by sha256sum, openssl dgst or PowerShell's Get-FileHash.

features

No. Cryptographic hashes are one-way functions: given a digest, there is no efficient way to recover the input. That is the entire point — integrity checks, password storage and signatures all rely on this property.

technical

No. The Web Crypto API runs the hash inside your browser, so the input never crosses the network. That makes the tool safe for secrets, private keys and any file you would not want to upload.

privacy

Yes. Switch the Source toggle to Text to hash a pasted string, or to File to drop in any file. Either way the tool computes SHA-1, SHA-256, SHA-384 and SHA-512 at once and lets you copy any of them, so a file digest matches what sha256sum or PowerShell's Get-FileHash would produce.

features

Each algorithm row (MD5, SHA-1, SHA-256, SHA-384, SHA-512) has its own Copy button next to the hex digest. The large primary button at the bottom is a shortcut for SHA-256 specifically since it's the most commonly requested value, but every other digest can be copied individually the same way.

usage

Yes — MD5 is shown alongside SHA-1, SHA-256, SHA-384 and SHA-512 even though the browser's built-in Web Crypto API doesn't implement MD5. The tool includes its own pure-JavaScript MD5 implementation specifically so you can match checksums against old downloads, ETags and manifests that still publish MD5 — it's included for legacy compatibility, never for anything security-sensitive.

technical

Click Clear at any time to wipe the pasted text or dropped file — the previous digests disappear immediately so you're never comparing a stale hash by accident. You can also just switch the Source toggle between Text and File; each source keeps its own input independently.

usage

Switch the Source toggle to File, drop the download (installer, ISO, archive) into the tool, and compare the SHA-256 row against the checksum published on the publisher's site — use the one-click Copy SHA-256 button to paste it straight into a comparison instead of retyping the long hex string. Because hashing runs locally via Web Crypto, the file itself never leaves your device during the check.

tips

No — this tool computes fixed digests: MD5, SHA-1, SHA-256, SHA-384 and SHA-512. Bcrypt, scrypt and Argon2 are deliberately slow, salted algorithms designed for storing login passwords, and they belong in your backend code, not in a converter. You can still hash any text here with SHA-256 for checksums or cache keys, but never store user passwords as plain unsalted digests.

technical

A hash value is a fixed-length fingerprint computed from your input: SHA-256 always yields 64 hex characters whether you hash one word or a 2 GB file. The same input always produces the same value, while a one-byte change produces a completely different one — which is exactly what makes a hash value generator useful for integrity checks and duplicate detection.

technical

How Hash Generator helps you get it done

Real problems it solves every day — for businesses, creators, and everyday tasks. Find the use case that fits you and start in seconds.

Everyday Use

Verify File Integrity After Download

Compute the SHA-256 digest of an ISO, installer or release artifact and compare it with the publisher's checksum to confirm the file was not corrupted or tampered with

Everyday Use

Detect Duplicates in Large Image Libraries

Hash files to find duplicate photos, documents or assets across folders, NAS shares and cloud drives without comparing them byte-by-byte every time

For Developers

Sign & Validate Webhook Payloads

Generate the SHA-256 digest of a webhook body to validate Stripe, GitHub, Shopify and Twilio HMAC signatures during local integration work and debugging

For Business

Fingerprint Software Releases for Auditing

Produce SHA-512 fingerprints for binaries, container images and release tarballs so compliance teams can audit which exact build shipped to which customer

Web & SEO

Generate Cache Keys & ETags

Hash request bodies, query parameters or file contents to derive deterministic cache keys for Redis, Cloudflare Workers and CDN ETag headers

Everyday Use

Confirm Backup Integrity Over Time

Store SHA-256 digests of monthly backups and re-hash them later to confirm bit-rot has not silently corrupted critical archives on long-term storage media

For Developers

Check Legacy MD5 Checksums From Old Downloads

Some older software manifests and mirror sites still only publish an MD5 checksum. Drop the file into File mode and compare against the published MD5 row — included specifically for matching those legacy listings, not for anything security-sensitive.

Privacy & Security

Password & Secret Fingerprinting for Config Audits

Paste a config value, API key or password into Text mode to get its SHA-256 fingerprint for audit logs and diff comparisons — prove two environments hold the same secret without ever exposing the secret itself, since hashing runs entirely in your browser.

Publishing

Timestamp Proof for Written Work

Hash a manuscript, contract draft or design file with SHA-256 and publish or email just the digest before revealing the finished document — later you can prove the exact content existed at that time, since anyone with the file can verify it matches your published hash.

For Business

Data Migration Verification

Hash export files before and after a database or cloud migration to prove byte-for-byte fidelity — compare the SHA-256 digests of the CSV/JSON exports on both ends instead of eyeballing millions of rows.

Education

Classroom Integrity Checks for Submitted Files

Instructors can hash a released dataset or starter-code file and ask students to report the matching digest alongside their submission, confirming nobody edited the starting material before beginning the assignment.

For Developers

Verify Software Downloads and OS Images Before You Install Them

Drop a freshly downloaded installer, Linux ISO or archive into File mode and compare the SHA-256 row against the checksum the publisher lists on their official download page — this is the single most common reason people reach for a hash generator, and it catches a corrupted download or a tampered mirror before you run anything untrusted on your machine.