SHA-256 Hash Generator

–type text to hash it four ways - click a row to copy
AlgorithmHash (click row for full)
SHA-1-
SHA-256-
SHA-384-
SHA-512-
All four digests are computed in your browser with Web Crypto - the text never leaves the page - following NIST FIPS 180-4, the specification that defines the SHA family. MD5 is deliberately absent: it has been cryptographically broken since 2004 and Web Crypto refuses to implement it, and SHA-1 survives here only for verifying legacy systems - 2017's SHAttered attack produced the first practical collision. Bottom line: hashing is not encryption - a hash is a one-way fingerprint for integrity checks, and for passwords you need a slow, salted construction like bcrypt or Argon2, never a bare SHA digest. Character-level context: ASCII table, Unicode character inspector, identifiers UUID generator, bit-level binary powers table.

A hash is a one-way fingerprint: the same text always produces the same digest, but the digest reveals nothing about the text. This tool computes all four SHA family members of your input with the browserโ€™s own Web Crypto engine - your text never leaves the page - and each digest is verifiable against an expected value in the check box.

MD5 is deliberately missing from the table: it has been cryptographically broken since 2004, and the Web Crypto standard refuses to implement it. SHA-1 appears only because legacy systems still require verification against it.

How to use

  1. Type or paste the text; all four digests update as you type, computed locally.
  2. Paste an expected hash into the verify box - the note tells you which algorithm matches, or says none do.
  3. Click any table row to copy its full digest for a checksum file or an API comparison.

Frequently asked questions

Why is there no MD5 option?

MD5 has been practically broken since 2004 - researchers can craft two different inputs with the same MD5 digest, which means an MD5 "match" proves nothing about integrity. Web Crypto omits it by design; this tool follows the standard rather than exposing a footgun.

Can I use SHA-256 to store passwords?

No. A bare SHA digest computes in nanoseconds, so billions of guesses per second are affordable on commodity hardware. Password storage needs a deliberately slow, salted construction - bcrypt, scrypt or Argon2 - and most languages ship one in their standard library.

What does the empty string hash to?

The SHA-256 of the empty string is e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 - a famous constant worth knowing, because seeing it in output usually means you hashed nothing by accident.

Why do the digests have different lengths?

Each algorithm emits a fixed number of bits: SHA-1 is 160 bits (40 hex characters), SHA-256 is 256 bits (64 characters), SHA-384 and SHA-512 are 384 and 512 bits. Longer digests are not "more correct" - they just collide less often in theory, which matters only at planetary scale.

Related tools