Skip to main content
QUIETLYTIC
Developer

Hash Generator

Produce SHA-1, SHA-256, SHA-384 and SHA-512 digests of text or a file.

Local · nothing leaves this browser Waiting for input
Esc Clear
Digests

Type text, or choose a file.

How it works

Four digests at once — SHA-1, SHA-256, SHA-384, SHA-512 — over text you type or a file you pick, computed by WebCrypto inside your own tab. The file is read locally and never uploaded, which matters more here than on most tools: the thing you want a hash of is usually the thing you are least willing to send somewhere.

There is no MD5, deliberately

WebCrypto does not implement it, so offering MD5 would mean shipping a hand-written one. MD5 has been collision-broken since 2004, which removes the only property a generator is used for — establishing that two files are the same. Where you need to recognise an MD5 someone else produced, the Hash Identifier reads it instead.

Hex and Base64 are the same digest

Hex is what advisories, malware repositories and sha256sum print. Base64 is what a Subresource Integrity attribute wants, after the sha384- prefix. Both are shown because both get asked for, and converting between them by hand is a pointless source of error.

When a digest does not match the advisory

Usually the file genuinely differs: an archive re-compressed on the way down, a text file whose line endings were converted, a sample defanged before sharing. A hash covers bytes, not intent. Compare the byte count reported here against the one the advisory gives before concluding the hash is wrong.

Example

abc gives SHA-256 ba7816bf…f20015ad. Hashing café covers five bytes rather than four characters, because é is two bytes in UTF-8 — the byte count is shown alongside for exactly that reason.

Frequently asked questions

Is my file uploaded anywhere?

No. The file is read by your own browser and hashed by WebCrypto in the same tab. This page makes no network request at all while hashing, which you can confirm with the devtools network panel open — a property that matters more here than on most tools, because the thing being hashed is often the thing you are least willing to send somewhere.

Why is there no MD5?

WebCrypto does not implement it, so offering MD5 would mean shipping a hand-written implementation. MD5 has been collision-broken since 2004 and should not be used to establish that two files are the same, which is the only reason anyone reaches for a generator. Where you need to recognise an MD5 someone else produced — a hash from a malware report — the Hash Identifier reads it.

Which digest should I use?

SHA-256 unless something specific asks otherwise. It is what CISA advisories, vendor bulletins and malware repositories publish, so a SHA-256 is the digest most likely to match something you can look up. SHA-1 is here to verify legacy artefacts, not to protect new ones.

What is the Base64 output for?

Subresource Integrity. A script or stylesheet tag can carry integrity="sha384-…" with a Base64 digest, and the browser refuses to execute the file if it does not match. Hex is what you want everywhere else.

The hash does not match the one in the advisory — why?

Most often the file differs: an archive re-compressed on download, a text file whose line endings were converted, or a sample that was defanged before being shared. A digest covers bytes, not intent, so any of those is a genuinely different file. Check the byte count shown here against the one the advisory reports before assuming the hash is wrong.

Related tools

From the intelligence desk