Security

Hash Generator

Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.

Last reviewed by the Radiatus Cloud team

Hash Generator

Generate cryptographic hashes (MD5, SHA-1, SHA-256, SHA-512) for any text.

Need this handled by experts?

Radiatus runs VAPT, managed SOC & security engineering for regulated teams.

Book a free security consult

What a hash is for

A cryptographic hash maps input of any length to a fixed-length digest. The same input always produces the same digest, and any change to the input produces a completely different one. That makes hashes useful for verifying data has not changed in transit or storage, for deduplication, and as a building block in signatures and message authentication codes.

Which algorithm to use

SHA-256 is the sensible default for new work. SHA-512 is not meaningfully more secure for most purposes but is faster than SHA-256 on 64-bit hardware, so it suits hashing large volumes. SHA-1 has been practically broken since the 2017 SHAttered collision and the 2020 chosen-prefix attack, and must not be used where collision resistance matters. MD5 has been broken since 2004 and collisions can be produced in seconds on a laptop.

MD5 and SHA-1 still have legitimate non-adversarial uses: verifying an accidentally corrupted download, cache keys, or matching a legacy checksum published years ago. The distinction is whether an attacker could benefit from crafting a collision. If yes, use SHA-256.

Hashing is not encryption

A hash is one-way. There is no key and no decryption. When a service claims to decrypt an MD5 hash, it is looking the digest up in a table of precomputed hashes of common inputs. That works precisely because unsalted hashes of predictable inputs are trivially reversible by lookup.

Never use these for passwords

General-purpose hashes are designed to be fast, which is exactly wrong for password storage. Modern hardware computes billions of SHA-256 digests per second, so a stolen table of unsalted password hashes is cracked at enormous rates. Password storage needs a deliberately slow, memory-hard, salted algorithm: Argon2id is the current recommendation, with scrypt and bcrypt as accepted alternatives. Use this tool for integrity checking, not credentials.

Verifying a download

Publishers commonly post a SHA-256 checksum beside a release. Hash the file you received and compare, or paste the expected value here to have the comparison done for you. This detects corruption reliably. It only detects tampering if you obtained the expected checksum over a channel the attacker does not control, which is why signed checksum files exist.

Local computation

Hashing runs in your browser via the Web Crypto API. Files are read locally and never uploaded, which matters when checksumming something confidential.

Related tools

  • Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
  • Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
  • Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.
  • JWT Decoder — Decode JWT header and payload, inspect claims and expiry, and spot common security flaws. Runs locally, your tokens are never transmitted.

Frequently Asked Questions

Is MD5 still safe to use?

Not where an adversary is involved. MD5 collisions have been practical since 2004 and can be generated in seconds. It remains acceptable for detecting accidental corruption or as a cache key, but never for signatures, certificates, or anything security-relevant.

Can a hash be reversed?

Not mathematically. Services claiming to reverse MD5 are looking the digest up in precomputed tables of common inputs. That succeeds for predictable inputs like ordinary passwords, which is exactly why password hashing requires a salt and a deliberately slow algorithm.

Should I hash passwords with SHA-256?

No. General-purpose hashes are built for speed and modern hardware computes billions per second. Use a slow, memory-hard, salted algorithm designed for the job: Argon2id is the current recommendation, with scrypt and bcrypt as accepted alternatives.

What is the difference between SHA-256 and SHA-512?

Digest length and internal word size. SHA-512 operates on 64-bit words so it is often faster on 64-bit CPUs despite the longer digest. Both are secure; SHA-256 is the more common default and produces shorter digests.

Does a matching checksum prove a file is authentic?

It proves the file matches the checksum you compared against. If an attacker could alter the file they could usually alter a plain checksum published alongside it. Authenticity requires a signature, or obtaining the checksum through an independent trusted channel.

Are my files uploaded to check their hash?

No. Hashing uses the browser's Web Crypto API and reads the file locally. Nothing is transmitted, so you can safely checksum confidential material.

Privacy & Security

Text is hashed client-side. No input sent to server.

Data: None
Client-side-Side
Active
v1.0

How to Use

Enter your text, select the hashing algorithm (MD5, SHA1, etc.), and click Generate.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.