Hash Identifier
Identify what algorithm produced a hash from its length, character set and prefix. Covers MD5, SHA family, bcrypt, Argon2, scrypt, NTLM, PBKDF2 and the crypt formats.
Last reviewed by the Radiatus Cloud team
Need this handled by experts?
Radiatus runs VAPT, managed SOC & security engineering for regulated teams.
Hashes announce themselves by shape
A hash on its own has no metadata, but its format carries a great deal of information. Length narrows the field immediately: 32 hexadecimal characters is MD5 or NTLM, 40 is SHA-1, 64 is SHA-256. Modern password hashes go further and encode their algorithm explicitly in a prefix, so a string beginning with dollar-2b-dollar is bcrypt and one beginning with dollar-argon2id-dollar is Argon2id. Identifying the format correctly is the first step in any migration, audit or incident response involving credentials.
Length alone is ambiguous
Several algorithms produce identically shaped output. MD5, NTLM, MD4 and several others all produce 32 hexadecimal characters and cannot be distinguished by inspection at all. The correct answer in those cases is a list of candidates with the context that would disambiguate them: an NTLM hash comes from a Windows credential store, an MD5 from almost anywhere. A tool claiming certainty where none exists is worse than one presenting the ambiguity.
What the format tells you about security
The identification also answers whether the hash is suitable for passwords at all. A bare MD5, SHA-1 or SHA-256 with no salt and no work factor is a fast hash, and fast is exactly wrong for passwords: commodity hardware computes billions of SHA-256 hashes per second. Formats carrying a cost parameter, bcrypt, scrypt, Argon2 and PBKDF2, are deliberately slow and are what a password store should contain. This tool reports that assessment alongside the identification.
Related tools
- Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
- Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
- Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
- Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.
Frequently Asked Questions
Can a hash always be identified with certainty?
No. MD5, NTLM and MD4 produce identically formatted output, as do several 64 character variants. Where the format is ambiguous the tool lists every candidate rather than guessing, since context about where the hash came from is what resolves it.
What do the dollar-sign prefixes mean?
They are the Modular Crypt Format, which encodes the algorithm, its parameters and the salt alongside the hash. 2a, 2b and 2y are bcrypt variants, 5 is SHA-256 crypt, 6 is SHA-512 crypt, and argon2id, scrypt and pbkdf2 name themselves.
Is my hash sent anywhere?
No. Identification is pattern matching against format rules and runs entirely in your browser. That matters because the hashes people paste into these tools are frequently real credentials from a system they are investigating.
Which algorithms should store passwords?
Argon2id is the current recommendation, with scrypt and bcrypt both acceptable. PBKDF2 with a high iteration count remains acceptable where FIPS compliance is required. Plain MD5, SHA-1 and SHA-256 should never be used for passwords regardless of salting.
Can this reverse a hash?
No, and nothing can. Hashing is one way by design. Recovering a password from a hash means guessing candidates and hashing them until one matches, which is why the deliberate slowness of a proper password hash matters so much.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Paste a hash to see which algorithms could have produced it and how confident the match is.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Password Strength Checker
SecurityMeasure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
Password Generator
SecurityGenerate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
Hash Generator
SecurityGenerate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.