What this tool does
A cryptographic hash turns any input into a fixed-length fingerprint. Change one character of the input and the digest changes completely, which is what makes hashes useful for verifying integrity, deduplicating data, and confirming that two files are identical. This tool computes SHA-1, SHA-256, SHA-384 and SHA-512 using the browser's built-in crypto library.
How it works
A hash function processes the input in fixed-size blocks and produces a digest that is always the same length for a given algorithm, regardless of input size. SHA-256 always returns 32 bytes, rendered as 64 hexadecimal characters. There is no way to reverse a digest back to the original input, which is the property that distinguishes hashing from encoding.
Real hashing is not what the browser provides. The Web Crypto API in the browser's secure context implements SHA-1, SHA-256, SHA-384 and SHA-512, which are the algorithms almost everything still needs. MD5 is deliberately excluded: it is broken for collision resistance and is only useful for matching legacy checksums.
Digest comparison is case-insensitive in practice, because digests are usually compared as lowercase hex. The important caveat is that a hash confirms an input matches a known value; it does not prove the input is trustworthy, since anyone can produce a matching hash for content of their choosing.
Worked example
Verifying that a downloaded file matches the checksum its publisher provided.
- Compute the digest of the file contents, not its filename
- Compare it to the published value as lowercase hex
- Any difference means the file is corrupt or was modified
A match confirms the file is byte-for-byte identical to what was published. A mismatch means stop and re-download, because a tampered file cannot be distinguished from a corrupted one by checksum alone.
Accuracy and limitations
- SHA-1 and MD5 are considered broken for any security purpose. Use SHA-256 or stronger unless you are matching a legacy checksum that already exists.
- Hashing a password with SHA-256 does not protect it. Passwords need a slow, salted algorithm such as Argon2, bcrypt, or scrypt.
- The Web Crypto API requires a secure context. On plain http the tool will report that hashing is unavailable rather than falling back to something weaker.
Frequently asked questions
- What is the difference between a hash and encryption?
- Encryption is reversible with a key; hashing is one-way. You cannot decrypt a SHA-256 digest back to the original input, which is exactly what makes it useful for verifying integrity. If you need to recover the original, you want encoding such as Base64, not a hash.
- Which algorithm should I use?
- SHA-256 unless you have a specific reason otherwise. It is the current default for file integrity, signing, and API request signing. SHA-512 is more conservative and costs nothing extra here. SHA-1 is only for verifying legacy checksums you already have.
- Why can't I hash MD5 here?
- MD5 is broken: it is practical to construct two different files that produce the same digest, which defeats its purpose for integrity and security. The Web Crypto API does not expose it. It is occasionally still needed to match an old checksum, which is the only case where a weak hash remains useful.
- Is my input sent anywhere?
- No. Hashing runs through the browser's SubtleCrypto interface on your device. This matters here specifically, because hashing is often applied to tokens, payloads, and other values you would not want pasted into a third-party form.