Developer Tools

Hash Generator — MD5 and SHA

Generate MD5, SHA-1, SHA-256, SHA-384 and SHA-512 hashes from UTF-8 text in your browser. Compare Hex and Base64 outputs or calculate all five at once.

About Hash Generator — MD5 and SHA

Generate MD5 and SHA hashes from text

Enter text, choose MD5, SHA-1, SHA-256, SHA-384 or SHA-512, then select Generate hash. Generate all five hashes calculates all five algorithms for the same input. Results are available as lowercase Hex, uppercase Hex and Base64. These are different representations of the same digest bytes; Base64 does not encode the characters of the Hex string.

For a reproducible example, enter hello without quotation marks or a final line break and choose SHA-256. The lowercase Hex result is 2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824. Adding a space or line break changes the input bytes and the result.

UTF-8 input, whitespace and limits

The tool hashes the UTF-8 bytes of the text in the input field. Empty text is valid. Spaces are not trimmed and Unicode normalization is not applied. Line endings in the field use LF. Visually identical text can have different Unicode representations and therefore different hashes. Unpaired UTF-16 surrogates become replacement characters during UTF-8 encoding.

The limit is 20,000 UTF-16 code units, not 20,000 bytes. Most common characters use one code unit; most individual emoji use two, and multi-character emoji sequences can use more. Over-limit input is rejected, not partially hashed. This is a text tool: it does not read file bytes or let you select another character encoding.

Cancel a calculation and copy results

Changing the input or algorithm, or selecting Clear, cancels the current calculation and removes previous results. A five-second timer stops an unfinished calculation. Background tabs, a sleeping device or a busy browser can delay the timeout check and its message. After an error, check the input and try again.

Each output has its own Copy button. If copying fails or cannot be confirmed, select the read-only result field and copy manually. While a previous native copy operation is still pending, another copy operation is blocked to avoid overlapping writes. The SHA algorithms require Web Crypto support; all calculations use a Web Worker.

What a hash does—and does not—prove

MD5 produces 128 bits; SHA-1 produces 160 bits. SHA-256, SHA-384 and SHA-512 are members of the SHA-2 family and produce 256, 384 and 512 bits respectively. SHA-384 uses different initial values from SHA-512, so it is not simply the first 384 bits of a SHA-512 result. Choose the algorithm and output format required by your protocol.

Use MD5 and SHA-1 only for legacy compatibility checks, not for new digital-signature or tamper-protection designs. Hashing is not encryption. Short PINs or predictable strings may be guessed by hashing candidates and comparing results. Collision attacks and attacks that seek an input for a given digest are different problems. A matching hash alone does not authenticate a sender.

Do not use these raw hashes for password storage. Password storage needs a dedicated password-hashing scheme with a salt and an appropriate cost factor. Do not enter real passwords or secrets. Hash calculations run in your browser and do not upload the input to a calculation server. Normal site traffic still occurs; this does not guarantee the safety of your device, extensions or clipboard.

Frequently asked questions

Q. Can I hash empty text or whitespace?
Yes. Empty text is valid, and leading or trailing spaces remain part of the input. A final line break also matters. Line endings in the text field use LF.
Q. Why does identical-looking text produce different hashes?
For the same algorithm, identical bytes produce the same hash. Check Unicode composition, whitespace, line endings and character encoding. This tool uses UTF-8 and does not normalize Unicode.
Q. Can I recover the original text from a hash?
There is no decryption operation that uniquely restores the original input. However, short or predictable inputs can be guessed by hashing candidates, so hashing alone does not keep a secret safe.
Q. Is SHA-384 a shortened SHA-512 result?
No. SHA-384 uses different initial values. Truncating a SHA-512 digest does not give the SHA-384 digest for the same input.
Q. Can I use the result to store passwords?
Do not store passwords as raw MD5 or SHA hashes from this tool. Use a dedicated password-hashing scheme with a salt and a suitable cost factor.
Q. What happens if the input is too long or a calculation fails?
The maximum is 20,000 UTF-16 code units. Longer input is rejected without truncation. A five-second timer stops unfinished work, although background tabs and device sleep can delay the check. Failed calculations do not show results; you can try again.
Q. What does the Base64 output encode?
It encodes the digest bytes, not the characters of the Hex output. Hex and Base64 represent the same hash.
Q. Does this tool upload my text or hash files?
It calculates text hashes locally in your browser without sending the input to a calculation server. MD5 uses JavaScript and SHA uses Web Crypto. Normal site traffic still occurs. File hashing is not supported.

Sources and specifications

Related tools

Questions or feedback? Contact NanToo

Rate this tool
—(0 ratings)