What is SHA-256?
SHA-256 is the most widely used member of the SHA-2 family of hash functions, designed by the U.S. National Security Agency and published by NIST in 2001 (today in FIPS 180-4). It splits the input into 512-bit blocks, mixes each one through 64 rounds of 32-bit additions, rotations and logical functions, and outputs a 256-bit digest, written as 64 hex characters or 44 Base64 characters. No practical attack is known against the full algorithm: finding two inputs with the same SHA-256 hash, or an input matching a given hash, remains far beyond reach.
| Input | SHA-256 |
|---|---|
| (empty string) | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 |
abc | ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad |
The quick brown fox jumps over the lazy dog | d7a8fbb307d7809469ca9abcb0082e4f8d5651e46d3cdb762d02d0bf37c9e592 |
How to use the SHA-256 generator
- Type or paste text in the Text tab; the hash updates instantly. Switch the input to hex or Base64 if you are hashing raw bytes.
- For a file, use the File tab. The file is streamed in 4 MB chunks on your device, so large disk images work without filling memory.
- Choose lowercase hex (Linux, macOS), uppercase hex (Windows) or Base64 (web and API formats).
- Enter an HMAC key to get an HMAC-SHA256 instead of a plain hash.
- Paste a published checksum into the compare box to verify a download. For several algorithms at once, open the full hash generator.
Where SHA-256 is used
Bitcoin and blockchains
Bitcoin’s proof of work is built on SHA-256: miners repeatedly hash a block header twice with SHA-256 (“double SHA-256”) until the result falls below a target value, and block and transaction IDs are double-SHA-256 hashes. Bitcoin addresses use SHA-256 followed by RIPEMD-160. The same property that makes mining hard, that the only way to find a hash with certain properties is to try inputs one by one, is what makes SHA-256 useful everywhere else.
TLS certificates and HTTPS
Almost every HTTPS certificate is signed with a SHA-256-based signature such as sha256WithRSAEncryption or ECDSA with SHA-256; browsers stopped trusting SHA-1 certificates in 2017. Inside the connection, TLS 1.3 cipher suites such as TLS_AES_128_GCM_SHA256 use SHA-256 for key derivation (HKDF) and handshake integrity.
Code signing and software supply chains
Windows Authenticode, Apple code signing, Android APK signatures, Linux package repositories and Docker image digests (sha256:…) all rely on SHA-256 to prove that the code you run is the code the publisher signed. Git also supports a SHA-256 object format as an alternative to its original SHA-1 hashes.
Web and API security
Subresource Integrity attributes (integrity="sha256-…") contain a Base64 SHA-256 of a script or stylesheet, which you can produce here by choosing Base64 output. Webhooks from payment and developer platforms are commonly signed with HMAC-SHA256, and JSON Web Tokens signed with HS256 use the same construction.
Verify a file’s SHA-256 checksum
| System | Command |
|---|---|
| Windows Command Prompt | certutil -hashfile setup.exe SHA256 |
| Windows PowerShell | Get-FileHash setup.exe (SHA-256 is the default) |
| macOS | shasum -a 256 image.dmg |
| Linux | sha256sum image.iso, or sha256sum -c SHA256SUMS to check a list |
Compare every character, or paste both values here and let the compare box do it. Hex is case-insensitive, so Windows’ uppercase output matches Linux’s lowercase output.
SHA-256, HMAC and length extension
SHA-256 is a Merkle–Damgård hash, which means that anyone who knows SHA-256(secret + message) and the secret’s length can compute the hash of the message with extra data appended, without knowing the secret. This “length-extension attack” has broken real API signature schemes. The fix is to use HMAC-SHA256, which this page computes when you enter a key, or a hash that is not vulnerable, such as SHA-512/256 or SHA3-256, both available in the hash generator.
SHA-256 compared with other hashes
| Hash | Output | Status | When to pick it over SHA-256 |
|---|---|---|---|
| MD5 | 128 bits | Broken | Only to match an existing MD5 checksum |
| SHA-1 | 160 bits | Broken | Only for legacy compatibility |
| SHA-512 | 512 bits | Secure | Often faster on 64-bit CPUs; longer output |
| SHA-512/256 | 256 bits | Secure | Same length as SHA-256 but resistant to length extension |
| SHA3-256 | 256 bits | Secure | When you want a design unrelated to SHA-2 |
For almost every new checksum or integrity job, SHA-256 is still the right default because every operating system, language and library supports it.
SHA-256 is not a password hash
SHA-256 is designed to be fast, so an attacker with a graphics card can try billions of password guesses per second against it. Passwords should be stored with a slow, salted algorithm such as Argon2id, bcrypt or scrypt. Try the bcrypt generator if you need one.
Frequently asked questions
How long is a SHA-256 hash?
A SHA-256 hash is 256 bits: 64 hexadecimal characters or 44 Base64 characters including padding.
Is SHA-256 secure?
Yes. No practical collision or preimage attack is known against SHA-256, and it is approved by NIST. For secrets combined with messages, use HMAC-SHA256 to avoid length-extension attacks.
Can SHA-256 be decrypted?
No. SHA-256 is a one-way hash, not encryption. The only way to find an input is to guess it, which is feasible only for short or common inputs such as weak passwords.
How do I get a Base64 SHA-256 for Subresource Integrity?
Paste the file content or choose the file, set the output format to Base64 and prefix the result with sha256- in the integrity attribute.
Is my file uploaded when I hash it?
No. The file is read and hashed in your browser in 4 MB chunks. Nothing is sent to a server.
What is the difference between SHA-256 and SHA-2?
SHA-2 is a family of hash functions: SHA-224, SHA-256, SHA-384, SHA-512, SHA-512/224 and SHA-512/256. SHA-256 is the most widely used member of that family.