SHA-256 Hash Generator

–SHA-256 computed in your browser - text never leaves the page
AlgorithmDigest lengthFirst 32 chars of "hello world"
SHA-1160 bits (40 hex)2aae6c35c94fcfb415dbe95f408b9ce9
SHA-256256 bits (64 hex)b94d27b9934d3e08a52e52d7da7dabfa
SHA-384384 bits (96 hex)fdbd8e75a67f29f701a4e040385e2e23
SHA-512512 bits (128 hex)309ecc489c12d6eb4cc40f50c902f2b4
The digest is computed with Web Crypto (crypto.subtle.digest) following NIST FIPS 180-4, the specification that defines the SHA family. Four algorithms are available: SHA-1 is included for legacy verification only (broken since 2017), while SHA-256, SHA-384 and SHA-512 are all currently secure. Bottom line: the SHA-256 of the empty string is e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 - a famous constant, because seeing it in output usually means you hashed nothing by accident. Text-tool neighbours: JSON formatter, Base64 encode decode, character codes ASCII table.

The SHA-256 hash is a one-way fingerprint: the same input always produces the same 256-bit output, but the output reveals nothing about the input. This tool computes it entirely in your browser using the Web Crypto API - no server round-trip, no network request, the text never leaves the page.

The table below shows the known SHA-256 values of common test strings, so you can verify the tool is working correctly before trusting it with real data.

How to use

  1. Type or paste text; the SHA-256 digest appears instantly as the page renders it.
  2. Copy the hash for use in integrity checks, commit messages or API signatures.
  3. Use the hello world chip to verify the tool matches the published standard test vector.

Frequently asked questions

What is the SHA-256 of the empty string?

e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855. This is the most famous test vector in cryptography - every correct implementation produces exactly this for zero-length input. If you see it in your output, your input was empty.

Can I use SHA-256 to store passwords?

No. SHA-256 is a fast general-purpose hash designed for integrity checking. Password storage needs a deliberately slow, salted construction - bcrypt, scrypt or Argon2 - because attackers can compute trillions of SHA-256 hashes per second on GPUs. The NIST SP 800-132 guidelines cover password hashing specifically.

What is the difference between SHA-256 and SHA-512?

The internal state size: SHA-256 uses 256-bit words and produces 64 hex characters; SHA-512 uses 512-bit words and produces 128 hex characters. SHA-512 is actually faster on 64-bit processors because it processes larger chunks. Both are currently secure per NIST.

What does collision-resistant mean?

No two known inputs produce the same SHA-256 output. This is different from unbreakable - mathematically, collisions must exist because the input space is larger than the output space. But no one has ever found one for SHA-256, despite decades of effort. SHA-1 lost this property in 2017.

Related tools