Hash Generator & Checksum Calculator

Type text or drop a file, press Compute and every algorithm returns in one table: hex and Base64 side by side, each row with its own copy button, so a checksum you only know in one notation is still easy to compare.

Runs in your browser Developer tools

Text to hash
File to hash

No file selected yet.

Or drop a file onto this box

Digests for your input, one row per algorithm
Algorithm Hex Base64 Copy
MD5 — —
SHA-1 — —
SHA-256 — —
SHA-384 — —
SHA-512 — —

MD5 is a legacy checksum with known collisions. Never use it for passwords or to prove integrity against an attacker.

How to use

  1. Pick the source: leave it on Text and type or paste the string — the five rows recompute themselves about a quarter of a second after you stop typing — or switch to File and choose one, which you can also drop straight onto the right-hand box.
  2. Press Compute when you want the digests right now. The table fills with five rows, and the status line tells you how many bytes they were taken over, which is the first thing to check when a checksum does not match.
  3. Compare against the value you expected in whichever notation you have: hex for most published checksums, Base64 for SRI-style and binary ones. Press Copy on that row to take the value out.
  4. To start over, press Clear, or switch source — the choice between Text and File is remembered for your next visit.

Frequently asked questions

Which algorithm should I use?

For a new checksum, use SHA-256: it is the current default, widely supported, and the value is short enough to paste into a config file. SHA-384 and SHA-512 are stronger but rarely needed and produce longer strings. MD5 and SHA-1 only make sense when you are verifying a digest somebody else already published, because both have known collision attacks — do not use them to prove a file is genuine in an adversarial situation, and never use any of these fast hashes to store passwords. Password hashing needs a deliberately slow, salted function such as Argon2id, scrypt, bcrypt or PBKDF2; SHA-256 is designed to be as fast as possible, which is exactly the wrong property there.

Why does it say the SHA digests are unavailable?

The SHA family comes from your browser’s Web Crypto API, and that API only works on a secure origin — https:// or localhost. On a plain http:// address the browser switches it off, so the page still gives you MD5 (that one is computed by code in this page, not by the API) and tells you the rest are blocked. Open the page over https://, or use it on localhost while developing, and all five rows fill in.

Is my file uploaded to a server?

No. The file is read into memory by your browser and digested here; the page makes no network request with your content, so you can confirm it by disconnecting after the page loads and computing again. The trade-off is memory rather than privacy: files above roughly 25 MB are read in one go, so the tool warns you first and asks for a second press of Compute. Very large archives can be slow or fail in a browser tab, where a command-line hash utility is the better tool.

Guides

Related tools