Skip to content

SHA-256 Hash Generator

Get the fingerprint (hash) of a text or a file, to check that it has not changed.

  • Free, no account
  • Nothing uploaded
  • 13 tools
Digest (hex)
SHA-256
…
SHA-384
…
SHA-512
…
SHA-1 · legacy, not collision-resistant
…
Computed by crypto.subtle in this tab, no request made. Text, key and file are held in memory only.

Nothing you paste is uploaded. The server sends connect-src 'self', so your browser blocks this page from contacting any other host. Check it yourself

Compute SHA-256, SHA-384, SHA-512 and SHA-1 digests and HMACs of text or a file with the Web Crypto API of your browser. The input is not stored.

What a SHA-256 hash tells you

A hash function maps any input to a fixed-size digest: 256 bits for SHA-256, written as 64 hex characters. The same input always gives the same digest, and changing one bit of the input changes about half of the digest. That makes it a fingerprint: compare the digest of a downloaded file with the one the publisher lists and you know whether the bytes are identical.

sha256("abc") = ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad

The digests here come from crypto.subtle.digest, the Web Crypto implementation built into your browser. No hashing library is shipped with the page.

HMAC

Enter a key and the page also computes an HMAC, a hash that can only be produced by someone who knows the key. Webhook signatures (the X-Signature style headers) and HS256 tokens are HMACs. To check a token's signature, use the JWT decoder.

Text is hashed as UTF-8, exactly as typed

A trailing line break or a different line ending gives a different digest. If your result does not match one computed on a command line, check for a final newline: echo adds one, printf does not.

Questions

Short answers to what people ask most.

Can a SHA-256 hash be reversed?

Not by computation, but short or common inputs can be found by guessing: a hash of a weak password is looked up in precomputed tables in seconds. A hash proves that two inputs are the same; it does not hide a guessable input.

Should I store passwords as SHA-256?

No. Fast hashes are the wrong tool for passwords. Use a password hashing function designed to be slow and salted, such as Argon2id, scrypt or bcrypt.

Why is SHA-1 still offered?

For checking legacy checksums and Git object ids. SHA-1 is broken for collision resistance (practical collisions exist since 2017), so do not use it for signatures or anything an attacker could influence.

Is the file I hash uploaded?

No. The browser reads the file with the File API and passes the bytes to crypto.subtle.digest in the same tab. The digest is computed in one pass, so a file larger than the available memory will fail.