Get SHA-256, SHA-1, SHA-384 and SHA-512 of text or a file. Runs on your device.
A hash is a short fingerprint of some data. The same input always gives the same hash, and changing a single byte gives a completely different one. The text abc has the SHA-256 hash ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad, and abd gives a different value that looks unrelated. That is why a site that offers a download publishes a checksum beside it: you hash your copy and compare the two. A hash checks that a file arrived intact. It is not encryption, and you cannot turn a hash back into the data. A matching checksum shows the file was not changed in transit only if the expected value came from a source you trust, separate from the download itself. A checksum published on the same page as a compromised download proves nothing, because whoever changed the file can change the number next to it as well. A checksum checks integrity. It does not confirm who made the file.
SHA-256 is the usual choice for a checksum, and it is the one to use when a site does not say. SHA-1 is only for matching an old checksum that a site still publishes as SHA-1. It is not safe for security, because two different inputs with the same SHA-1 hash have been produced on purpose. SHA-384 and SHA-512 are longer versions: a SHA-1 hash is 40 hex digits, SHA-256 is 64, SHA-384 is 96 and SHA-512 is 128. This page shows all four at once, so you can copy the one that matches the length of the value you were given. MD5 is not offered. The only source of hashes on this page is the browser's built-in crypto, and it does not include MD5. MD5 is also not safe for security. This page has no hash code of its own, so there is no MD5 to fall back on. For an MD5 checksum, use a command-line tool such as md5sum.
Text is turned into UTF-8 bytes before it is hashed, so héllo ✓ is hashed as the ten bytes 68 c3 a9 6c 6c 6f 20 e2 9c 93. A text box uses one newline for every line break, so text pasted with Windows line endings is hashed as if it had single newlines. A file is hashed byte for byte, and a file saved with different line endings has a different hash, which is the usual reason a result does not match a website. Text can be up to 1,000,000 characters. A file can be up to 100 MB on a computer and up to 50 MB on a phone, because the browser reads the whole file into memory before it hashes it. The four hashes are worked out one after another from that one copy, and the page names the one that is running. For a 4 GB disk image, use a command-line tool such as sha256sum, which reads a file in pieces. This page hashes one file at a time. It does not do HMAC, salted password hashing or SHA-3.
The hashing is done by your browser's own crypto in this tab. There is no upload step and no server that receives your text or your file. A file you choose is read into memory, hashed, and then the page drops its reference to the bytes. The text, the file name, the hashes and the expected value are not put in the address bar, not saved and not sent to analytics. The page counts visits with Google Analytics, using coarse event fields such as the name of the tool, which page you came from, whether a result appeared and whether a Copy button was pressed. It never receives your text, file, file name, hashes, expected value or exact sizes. Only the input mode and the output format are remembered on this device. The browser's crypto is available only on a secure connection, so over plain http the page shows a message asking you to open it over https instead of hashing.
The page takes its hashes only from the browser's built-in crypto, and that does not include MD5. Adding a hand-written MD5 would mean this page carries its own hash code, which it deliberately does not. MD5 is also not safe for security. For an MD5 checksum use md5sum on the command line; for anything new, SHA-256 is the usual choice.
Usually the input is not the same bytes. A file saved with Windows line endings (CRLF) has a different hash from the same file with Unix endings (LF), and one extra space or a different download changes it entirely. Check that you copied all of the hash: SHA-256 is 64 hex characters, and a shorter value is reported as not a hash.
A matching checksum shows the file was not changed in transit only if the expected value came from a source you trust, separate from the download itself. A checksum published on the same page as a compromised download proves nothing, because an attacker can change both. It checks integrity. It does not authenticate the site.
Not for security. Two different inputs with the same SHA-1 hash have been produced on purpose, so SHA-1 should not be used to sign or protect anything. It is still fine for matching an old checksum that a site publishes as SHA-1, which is what the 40-character result here is for.
No. The browser reads the whole file into memory first, so the limit is 100 MB on a computer and 50 MB on a phone. A file over that shows a message and is not read. For a 4 GB image use sha256sum on Linux, shasum -a 256 on macOS, or Get-FileHash in PowerShell on Windows.
No. The file is read in this tab and hashed by your browser, and no part of the file is sent anywhere. The file name appears on this page only as the title of your result. Analytics counts that a result appeared, never the file, its name, its size or the hash.
No. SHA-256 is fast on purpose, which makes guessing fast too, and this page adds no salt. Passwords need a slow, salted method made for them, such as Argon2 or bcrypt, in the software that stores them. To keep your own passwords safe, use a password manager.