Verifying a downloaded file's checksum
Publishers list a SHA-256 for their release. Hash the text form of a value or compare tool output character for character; any difference at all means the content differs.
Produce SHA-1, SHA-256, SHA-384, or SHA-512 digests from text in your browser using Web Crypto.
Maintained by Roshan.
Produces a SHA digest from text using your browser's own Web Crypto implementation. The text never leaves the tab.
Find related browser-local tools for nearby tasks without starting another search.
Browse all generatorsA hash turns any amount of text into a fixed-length fingerprint. The same input always yields the same digest, a single changed character produces a completely different one, and the process cannot be run backwards. That combination makes hashes useful for checking that something arrived unaltered and for comparing values without storing them. Because the text is often exactly the kind of thing you would not want to paste into a stranger's server - a token, a config fragment, a snippet of a document - this page computes the digest in your browser using the same Web Crypto implementation that secures your connections.
Publishers list a SHA-256 for their release. Hash the text form of a value or compare tool output character for character; any difference at all means the content differs.
Two configuration blocks that should be identical are tedious to diff by eye. Hash both and compare sixty-four characters instead of thousands.
Hashing a long parameter string gives a short, fixed-length key that is safe to use in a filename or storage bucket.
No. So-called reverse lookup services simply search precomputed tables of common inputs. For anything unpredictable, the original cannot be recovered from the digest.
SHA-256 unless something specific requires otherwise. Choose SHA-384 or SHA-512 when a longer digest is specified, and SHA-1 only when matching a legacy checksum.
Web Crypto does not provide it, and implementing it by hand for a broken algorithm would be a poor trade. Use a command-line tool if a legacy system still demands MD5.
You should not. Password storage needs a deliberately slow algorithm with a salt, such as Argon2 or bcrypt. SHA functions are fast by design, which benefits an attacker running billions of guesses.
Generate strong passwords in your browser using crypto.getRandomValues, with entropy shown in bits. Nothing is transmitted, logged, or stored.
Generate one or a thousand version 4 UUIDs in your browser using a cryptographic random source. Copy them all at once, with nothing requested from a server.
Encode UTF-8 text to standard Base64 or decode Base64 back to Unicode text locally in your browser, with strict malformed and non-text error handling.
Turn a JSON object into .env format in your browser, with keys upper-cased and values quoted where a shell needs it.
Convert a date and time to a Unix timestamp in your browser.