🔨

Hash Generator

Generate SHA-256, SHA-1 and CRC32 hashes from any text using the Web Crypto API. Free, instant, and processed entirely in your browser.

✓ Free forever✓ No signup✓ 100% private — runs in your browser
Hash Generator
Generate cryptographic hashes using SHA-256, SHA-512, SHA-1, and MD5-like (CRC32) algorithms.
Input Text
Verify Hash
SHA-256
—
SHA-512
—
SHA-1
—
CRC32
—

A hash function turns input of any length into a fixed-length fingerprint. The same input always produces the same hash; changing a single bit produces a completely different one. That makes hashes useful for verifying integrity and detecting change.

How to use the Hash Generator

  1. Paste the text you want to hash
  2. Pick an algorithm — SHA-256 unless you have a specific reason not to
  3. Copy the resulting hash
  4. To verify a file or message, hash both and compare the strings

Choosing an algorithm

  • SHA-256 — the current default for anything security-related. No practical attacks exist. Use this unless something specifically requires otherwise.
  • SHA-1 — cryptographically broken. A practical collision was demonstrated in 2017. Fine for non-security uses such as Git object naming or cache keys; never for signatures or certificates.
  • CRC32 — a checksum, not a cryptographic hash. Fast, 32 bits, designed to catch accidental transmission errors. Trivially forgeable, so never use it for anything adversarial.

Hashing is not how you store passwords

This deserves emphasis because the mistake is still widespread. A plain SHA-256 of a password is not safe storage.

SHA-256 is designed to be fast, which is exactly wrong for passwords — a modern GPU computes billions per second, so an attacker with your hash table can brute-force weak passwords almost immediately. Unsalted hashes are also vulnerable to rainbow tables, and identical passwords produce identical hashes, which leaks information.

Password storage needs a deliberately slow, salted algorithm designed for the job: bcrypt, scrypt or Argon2. These have a tunable work factor so you can keep them slow as hardware improves.

Frequently asked questions

Can a hash be reversed?

No. Hashing is one-way by design. Short or common inputs can be found by brute force or lookup tables, but the function itself cannot be inverted.

Should I use this to hash passwords?

No. Use bcrypt, scrypt or Argon2 on your server. General-purpose hashes are far too fast to resist brute-force attacks on passwords.

Is SHA-1 still safe?

Not for security. A practical collision was demonstrated in 2017, so it must not be used for signatures or certificates. It remains acceptable for non-adversarial uses like content addressing.

Why do I get a different hash for seemingly identical text?

Almost always a trailing newline, a trailing space, or different line endings — \r\n versus \n. Hashes are byte-exact, so any invisible difference changes the output completely.