Hash Generator

Calculate MD5, SHA-1, SHA-256, SHA-512, SHA-3, SHAKE, NTLM, Whirlpool and a dozen other hashes of text or of a file, all at once. Everything runs in your browser: files are read locally in chunks and never uploaded. Add an HMAC key, switch to Base64, or paste a published checksum to verify a download.

Algorithms
WordPress password hash (phpass): generate or verify

What this hash generator does

A cryptographic hash function turns any input, whether a word, a password or a 4 GB disk image, into a short, fixed-length fingerprint called a digest. Change a single bit of the input and the digest changes completely, which is why hashes are used to check downloads, detect tampering, index data and build digital signatures. This tool computes 20 different hash algorithms side by side, so you can match whatever format a website, database or command-line tool gives you.

Everything happens on your device. Text is hashed as you type, and files are read in 4 MB chunks with the browser’s File API, so even very large files never leave your computer and never have to fit in memory at once. SHA-1, SHA-256, SHA-384 and SHA-512 text hashes use the browser’s built-in Web Crypto API; every other algorithm, and all file hashing, uses streaming JavaScript implementations that were checked against published test vectors and reference implementations.

How to use it

  1. Choose Text or File. For text you can also paste raw bytes as hex or Base64.
  2. Tick the algorithms you want, or use the Common, SHA-2, SHA-3 and All shortcuts. All selected digests appear together.
  3. Optionally enter an HMAC key to compute a keyed HMAC instead of a plain hash, choose hex or Base64 output, or set a custom SHAKE output length.
  4. To verify a download, paste the checksum published by the vendor into Compare / verify a checksum. The tool tells you which result matches, if any.
  5. Use Copy link to share a preset. Links like /hash-generator?algo=sha256 or ?algo=md5,sha1 open with those algorithms selected.

Hash algorithm comparison

Not all hash functions are equal. “Broken” below means researchers can create collisions (two different inputs with the same digest) faster than brute force; it does not mean the hash can be reversed.

AlgorithmOutputPublishedStatusTypical use today
MD2128 bits1989 (RFC 1319, 1992)Broken, obsoleteVery old certificates and test suites
MD4128 bits1990BrokenInside NTLM; legacy file-sharing IDs
MD5128 bits1992 (RFC 1321)Broken for collisionsNon-security checksums, cache keys, deduplication
MD6-256256 bits2008Not standardizedResearch; did not advance in the SHA-3 competition
NTLM128 bits1993 (Windows NT)Weak: fast and unsaltedWindows and Active Directory password storage
SHA-1160 bits1995Broken (first public collision 2017)Legacy systems, older Git repositories
SHA-224224 bits2004SecureTruncated SHA-256 for constrained formats
SHA-256256 bits2001SecureFile checksums, TLS certificates, code signing, Bitcoin
SHA-384384 bits2001SecureTLS cipher suites, high-assurance systems
SHA-512512 bits2001SecureIntegrity checks; fast on 64-bit CPUs
SHA-512/224, SHA-512/256224, 256 bits2012 (FIPS 180-4)SecureSHA-512 speed with shorter output; not length-extendable
SHA3-224 to SHA3-512224–512 bits2015 (FIPS 202)SecureModern designs wanting a non-SHA-2 construction
SHAKE128, SHAKE256Any length2015 (FIPS 202)SecureExtendable output: key derivation, post-quantum schemes
Whirlpool512 bits2000 (final 2003)No practical attacks knownISO standard; disk-encryption and legacy tools
WordPress phpass34-character string2005Legacy (MD5-based)Passwords in WordPress before version 6.8

Which hash should I use?

Do not store passwords with plain hashes

MD5, SHA-1, SHA-256, NTLM and every other fast hash are the wrong tool for storing passwords. Graphics cards can test billions of guesses per second against a fast hash, and without a unique salt, identical passwords produce identical hashes that can be looked up in precomputed tables. Password storage needs a deliberately slow, salted algorithm such as Argon2id, bcrypt, scrypt or PBKDF2 with a high iteration count. You can create and check bcrypt hashes with the bcrypt generator. The NTLM and WordPress options here exist to test and migrate existing systems, not to design new ones.

How to verify a file checksum

Download the file, then compute its hash either here (choose File) or with a built-in command, and compare it with the value on the vendor’s site. If even one character differs, the file is corrupted or not the one the publisher released.

SystemCommand
Windows (Command Prompt)certutil -hashfile installer.exe SHA256 (also MD5, SHA1, SHA384, SHA512)
Windows (PowerShell)Get-FileHash installer.exe -Algorithm SHA256
macOSshasum -a 256 file.dmg or md5 file.dmg
Linuxsha256sum file.iso, sha512sum file.iso, md5sum file.iso
Any system with OpenSSLopenssl dgst -sha3-256 file.bin

Paste the whole output line into the compare box if you like; the tool pulls out the hash and ignores the file name. Hex is not case-sensitive, so uppercase output from Windows matches lowercase output from Linux.

Why does my text hash differ from another tool?

A hash is computed over bytes, not letters, so the exact bytes matter. The most common causes of a mismatch are a trailing newline (echo "abc" | sha256sum hashes abc\n; use printf or echo -n), Windows line endings (CRLF instead of LF), invisible spaces, and character encoding. This tool hashes text as UTF-8, the standard on the web, except NTLM, which by definition hashes the UTF-16LE form of the password. If you have raw bytes rather than text, switch the input to hex or Base64.

HMAC, SHAKE and the special algorithms

HMAC (RFC 2104) mixes a secret key into the hash so that only someone with the key can produce or check the value; it is how APIs sign webhooks and requests. It is available here for MD4, MD5, Whirlpool and every SHA-1, SHA-2 and SHA-3 hash. It is not offered for obsolete MD2, is not used with SHAKE (the keyed equivalent is KMAC) or MD6 (which has its own key input), and does not apply to the NTLM and WordPress password formats. SHAKE128 and SHAKE256 are extendable-output functions: the same input can produce 8 bits or 4,096 bits, and shorter outputs are prefixes of longer ones. NTLM is MD4 applied to the UTF-16LE encoding of a password, the format Windows uses for local and domain accounts. WordPress hashes use the phpass portable format, $P$ followed by a cost character, an 8-character salt and the result of 8,192 rounds of salted MD5. Because the salt is random, the same password gives a different hash every time, so use the verify panel rather than the compare box to check one. Since WordPress 6.8, new passwords are stored with bcrypt instead, but older $P$ hashes still work.

Privacy

No text, key or file is sent anywhere. You can disconnect from the internet after the page loads and every feature keeps working. That matters for hashing confidential documents, license keys or HMAC secrets, which you should never paste into a tool that sends data to a server.

Frequently asked questions

Is it safe to hash files and passwords here?

Yes. All hashing happens in your browser. Files are read locally in chunks and nothing you type or upload is sent to a server.

Which hash algorithms are supported?

MD2, MD4, MD5, MD6-256, NTLM, SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, SHA-512/224, SHA-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512, SHAKE128, SHAKE256, Whirlpool and the WordPress phpass password hash.

Can a hash be decrypted or reversed?

No. A hash is a one-way function, not encryption. Short or common inputs such as weak passwords can sometimes be found by guessing and comparing hashes, which is why passwords need a slow, salted algorithm like bcrypt or Argon2.

How do I verify a downloaded file with a checksum?

Choose File, select the download and the algorithm the publisher used (usually SHA-256), then paste the published checksum into the compare box. A match confirms the file is intact.

Is MD5 still safe to use?

MD5 is fine for non-security jobs such as spotting accidental corruption or deduplicating files, but it is broken for collisions, so do not use it for signatures, certificates or anything an attacker could target.

What is the difference between a hash and an HMAC?

A hash depends only on the input. An HMAC also depends on a secret key, so it proves the message came from someone who knows the key. Enter a key in the HMAC field to compute one.

Why does the WordPress hash change every time?

WordPress phpass hashes include a random 8-character salt, so the same password produces a different hash each time. Use the verify panel to check a password against an existing hash.