Hash Generator

Generate SHA-1, SHA-256, SHA-384 and SHA-512 hashes of any text or file instantly, using your browser's native Web Crypto API.

All hashing happens locally in your browser using the Web Crypto API. Your data never leaves your device.

Or drop a file to hash

Any file type · click or drag & drop

—
SHA-1
—
SHA-256
—
SHA-384
—
SHA-512
—

About Hashing

Hashing turns any amount of data into a fixed-length digest — a fingerprint of the input. Change even one byte and the digest changes completely, which makes hashes ideal for verifying that data is exactly what it claims to be. The process is one-way: no amount of computing can turn a digest back into the original input.

Why hash at all
To verify integrity. If two copies of data produce the same hash, they are almost certainly identical. Widely used for file checksums, password storage, digital signatures and git commit IDs.
SHA-1 (160-bit digest)
Broken for collision resistance — practical attacks exist. Still seen in legacy systems, but avoid it for anything security-sensitive.
SHA-256 (256-bit digest)
The workhorse of modern security. Used in TLS certificates, HTTPS, Bitcoin, digital signatures and most checksum tools. Considered secure with a large margin.
SHA-384 / SHA-512 (384 / 512-bit digests)
Longer digests with extra collision resistance, built for 64-bit systems and high-assurance applications such as WPA3 and some government standards.

Frequently Asked Questions

Is SHA-256 secure?

Yes. As of today, no practical attack has broken SHA-256. It is the NIST-recommended hash for digital signatures, TLS, blockchains and most modern security applications. Only SHA-1 is considered broken for collision resistance and should be avoided for new designs.

Can I hash large files?

This tool reads the entire file into memory, so practical limits depend on your browser's available memory. Files of a few hundred megabytes usually work fine; beyond that you may see slowdowns or failures. For very large files, a streaming hasher is the right tool.

Is hashing reversible?

No. Hash functions are one-way by design: from the digest you cannot recover the original input. Any input change — even a single byte — produces a completely different digest, which is what makes hashes useful for verifying integrity.

Why does this tool need a secure context?

The Web Crypto API (crypto.subtle) is only exposed in secure contexts: HTTPS or localhost. If you open the page over plain HTTP on another host, the browser hides crypto.subtle and hashing will fail with an error message.

Does the file get uploaded?

No. The file is read directly from your disk into your browser's memory and hashed there. No data is ever transmitted to any server.