Hash / digest calculator

Computes MD5, SHA-1, SHA-256, SHA-384 and SHA-512 in one pass. Every digest is produced in your browser; the text you enter is never uploaded.

Text to hash

0 characters

What a hash is — and what it is not

A hash function takes an input of any length and produces a fixed-length digest. Change one byte of the input and roughly half the output bits flip; feed the same input again and you get exactly the same digest. That pair of properties — determinism and avalanche — is what makes hashes useful for verifying integrity: publish the digest of a file, and anyone can confirm their copy matches.

Hashing is one-way by design: there is no key and no inverse operation. That makes it fundamentally different from encryption, which is reversible if you hold the key, and from encoding (Base64 and friends), which is reversible by anyone. If you ever see a product describe Base64 as encryption, that is a red flag.

The algorithms here differ mainly in output size and current standing. MD5 produces 128 bits and was widely used for decades, but practical collisions have been demonstrated since 2004, so it is acceptable only for non-adversarial checksums and cache keys. SHA-1 produces 160 bits and was broken in practice in 2017 — treat it the same way. SHA-256, SHA-384 and SHA-512 are the SHA-2 family and remain the default choice for signatures, certificates and integrity checks.

For passwords, none of these are the right tool. A fast hash can be tested billions of times per second on commodity GPUs, so a stolen password database gets cracked quickly. Password storage needs a deliberately slow, salted function — Argon2id, scrypt or bcrypt — where each guess costs real time and memory, and where a per-user salt prevents attackers from reusing work across accounts.

Everything here runs locally: SHA digests come from the browser’s own crypto.subtle implementation and MD5 from a small bundled routine, and the input text is discarded when you close the tab. That means it is safe to hash production data, tokens or anything else you would rather not paste into a service that logs requests.

Frequently asked questions

Is it safe to paste sensitive text here?

Yes. The digests are computed with the browser SubtleCrypto API and a local MD5 implementation; the text never leaves your device and is not stored.

Is MD5 encryption?

No. Hashing is one-way and has no key; encryption is reversible with a key. MD5 is also cryptographically broken for security use — collisions can be produced deliberately.

What should I use for passwords?

A slow, salted password-hashing function: Argon2id, scrypt or bcrypt. Fast digests like MD5 and SHA-256 are designed for throughput, which is exactly what makes them cheap to attack.

Why do two different texts sometimes share a digest?

That is a collision. It is expected to be astronomically rare for SHA-256, and deliberately constructible for MD5 — one of the reasons MD5 is no longer trusted for integrity guarantees.