Your country

Tools that support it use your country for local currency, number formats, units and paper size. Your choice is saved only in this browser.

Type a name or a two-letter code. Use the up and down arrow keys to move through the countries, Enter to choose one and Escape to close.

Hash Generator

Hashes and HMACs of text or huge files, plus checksum verification.

Developer No upload Works offline Free, no sign-up

Hashed exactly as typed, as UTF-8. Line breaks count as \n (LF). To hash a file byte-for-byte, use the Files tab.

Algorithms

Any case, hex or Base64. Lines like “SHA256 (file.iso) = …” or “… file.iso” work too.

Hashes

Type some text above to see its hashes.

Next steps

About the Hash Generator

A hash function turns any input into a short fixed-size fingerprint: change one bit and the fingerprint changes completely. This tool calculates MD5, SHA-1, SHA-256, SHA-384, SHA-512, SHA3-256 and SHA3-512 for text as you type, or for files of any size — even multi-gigabyte disk images. Files are read in small chunks by background workers, with a progress bar and an estimate of the time left, so the page stays responsive.

Paste the checksum published by a download site into Compare with an expected hash and the tool tells you whether the file matches. It understands hex in any case, Base64, Subresource Integrity values (sha384-…) and lines copied from sha256sum or BSD-style checksum files. Turn on HMAC to calculate keyed hashes for API signatures and webhooks.

How to use it

  1. Choose Text and type or paste, or choose Files and drop one or more files.
  2. Tick the algorithms you need. For big files, fewer algorithms finish sooner.
  3. Optionally paste the expected hash to check a download, or turn on HMAC and enter the key.
  4. Copy any value, or download a checksum file that sha256sum -c can check later.

Examples

Text
Input
The quick brown fox jumps over the lazy dog
Result
MD5: 9e107d9d372bb6826bd81d3542a419d6
SHA-1: 2fd4e1c67a2d28fced849ee1bb76e7391b93eb12
SHA-256: d7a8fbb307d7809469ca9abcb0082e4f8d5651e46d3cdb762d02d0bf37c9e592
HMAC-SHA-256 (RFC 4231 test case 2)
Input
Key: Jefe
Message: what do ya want for nothing?
Result
5bdcc146bf60754e6a042426089575c75a003f089d2739839dec58b964ec3843
Check a download
Input
Expected: SHA256 (installer.iso) = 3f1c…
Result
✓ Matches the expected SHA-256 hash.

Hex, Base64, SRI and checksum-file lines are all recognised; letter case does not matter.

Common uses

  • Verifying that an ISO, installer or firmware file downloaded completely and was not altered.
  • Generating Subresource Integrity (integrity="sha384-…") values for scripts and stylesheets on a CDN.
  • Computing or checking HMAC signatures of webhook payloads and API requests.
  • Comparing two files without uploading them: if their SHA-256 hashes match, the files are identical.
  • Creating checksum files to ship next to your own releases.

Which algorithm should I use?

  • SHA-256 is the standard choice for checksums, signatures and integrity checks. SHA-384 and SHA-512 are the same family (SHA-2, FIPS 180-4) with longer output.
  • SHA3-256 / SHA3-512 (FIPS 202) are a newer, completely different design — useful when a standard or protocol asks for SHA-3.
  • MD5 and SHA-1 are broken for security: practical collisions exist (for SHA-1 since the 2017 "SHAttered" attack). They still detect accidental corruption, so many download pages publish them, but do not use them to protect against deliberate tampering.

Hashes are not encryption and are not suitable for storing passwords on their own — password storage needs a slow, salted function such as Argon2, scrypt or bcrypt.

Verifying downloads properly

A checksum proves the file you have is the file the checksum was made from. If the checksum comes from the same server as the download, it protects against corruption but not against an attacker who replaced both. For real assurance, get the checksum from a different trusted place (such as the project's release notes over HTTPS) or verify a signed checksum file.

To cross-check on the command line: sha256sum file on Linux, shasum -a 256 file on macOS, and Get-FileHash file -Algorithm SHA256 in Windows PowerShell.

HMAC

An HMAC (RFC 2104) mixes a secret key into the hash, so only someone with the key can produce the same value. Services such as webhook providers use HMAC-SHA-256 to sign requests: compute it over the exact raw request body with the shared secret and compare. Keys can be entered as text, hex or Base64.

Limitations

  • Text is hashed exactly as it appears in the box, as UTF-8. Browsers turn Windows line endings (CRLF) in pasted text into LF, so to hash a file byte-for-byte, use the Files tab.
  • For files up to 64–256 MB (depending on your device's memory), SHA-1 and SHA-2 use the browser's built-in engine and finish in moments. Everything else is hashed in JavaScript: on a fast laptop SHA-256 takes about 10 seconds per gigabyte, SHA3-512 and MD5 several times longer, and phones are slower.
  • SRI output is only available for SHA-256, SHA-384 and SHA-512, the algorithms browsers support for Subresource Integrity.

Privacy

Everything happens in your browser. What you enter or open here is not uploaded or stored by MySmartCoPilot.

Frequently asked questions

Are my files uploaded?

No. Files are read and hashed on your device by your browser; nothing is sent to a server. You can disconnect from the internet after the page loads and it still works.

Why is my hash different from echo "text" | sha256sum?

echo adds a newline at the end, so the command hashes "text\n". Use echo -n "text" | sha256sum (or printf %s "text") to hash exactly what you typed.

Does letter case matter when comparing hashes?

Not for hex: AB12… and ab12… are the same value, and the comparison here ignores case. Base64 values are case-sensitive.

How large a file can I hash?

There is no fixed limit: files are read in 4 MB pieces, so memory use stays small even for files of several gigabytes. The time depends on the file size, the algorithms you select and the speed of your device.

Can a hash be reversed to get the original text?

No — a hash is a one-way fingerprint. Short or common inputs (like "password123") can be found by guessing and comparing, which is why hashes alone are not a safe way to protect passwords.

Quick answers and tool search

Type to search tools or to get a quick answer, for example 18% of 2500. Use the up and down arrow keys to move through the results, Enter to choose, and Escape to close.