MD5 and SHA Hash Generator

Checksum text or a file with CRC32, MD5, SHA-1, SHA-224, SHA-256, SHA-384, SHA-512 or SHA3-256, SHA3-384, SHA3-512. Text uses the character encoding you pick; a file is hashed as raw bytes. Add a key for HMAC, except CRC32.

A checksum, not a password store

MD5 and the SHA family reduce text or a file to a short digest. The same input always gives the same digest, and a one-bit change should scramble it. People use that to check a download, to key a cache, or to see whether two files match without sending the files.

These algorithms are not a place to store passwords. MD5 and SHA-1 are broken for collision resistance. SHA-256 is fine as a checksum and too fast, by itself, as a password hash. Password storage needs a slow function such as bcrypt or Argon2, which this page does not pretend to be.

How to use it

  1. Type text, or choose a file. A file is hashed as bytes and ignores the character encoding. Text is hashed in the encoding you pick. UTF-8 is the default, so a trailing newline still changes the digest. GBK and UTF-16 are different bytes for the same characters.
  2. Pick CRC32, MD5, SHA-1, SHA-224, SHA-256, SHA-384, SHA-512 or SHA3-256, SHA3-384, SHA3-512. SHA-256 is the usual choice for a new checksum. CRC32 is a short checksum and cannot take an HMAC key.
  3. Choose lowercase hex, uppercase hex, or Base64. Hex is what download pages publish. The letters a–f are the same checksum in either case; the compare box ignores case.
  4. Fill HMAC key only when the other side also uses HMAC with that key. An empty key means a plain hash, not HMAC with an empty string.
  5. Paste an expected digest to see whether it matches. A mismatch means different bytes, a different algorithm, or a different encoding. It does not mean the math failed.

What changes the result

  • Character encoding. UTF-8, GBK and UTF-16 are not the same bytes. The HMAC key stays UTF-8; only the text uses the menu. If a server hash disagrees, match its encoding or compare the bytes with string to bytes.
  • A BOM, a final newline, or Windows \r\n versus \n.
  • HMAC versus a plain hash. They are different operations even with the same algorithm name.
  • SHA-384 and SHA-512 use the browser’s crypto API and need https or localhost. CRC32, MD5, SHA-1, SHA-224, SHA-256 and SHA3-256, SHA3-384, SHA3-512 are computed on the page itself. CRC32 cannot take an HMAC key.

A known check: the SHA-256 of the five letters hello, with no newline, starts with 2cf24dba. If you do not get that, the box contains extra whitespace.

Questions

Can I reverse a hash to get the text back?

No. A digest is not an encoding. Base64 is reversible; a hash is not. See Base64 if you actually need to decode.

Why does the file hash differ from an online tool that asks me to paste?

Pasting a file into a text box changes the bytes. Use the file control so the hash covers the file itself.

Is MD5 still useful?

For accidental corruption, yes. For security, no. Do not use MD5 to sign a package or to store a password.