nicetool.dev logo

Hash Generator

Hashes are computed locally with Web Crypto. Files never leave your device.

Input text
Hashes
MD5
-
SHA-1
-
SHA-256
-
SHA-384
-
SHA-512
-

What is a hash function?

A cryptographic hash function turns any input into a fixed-length fingerprint. The same input always produces the same hash, while even a one-character change produces a completely different result. Hashes are used to verify downloads, store passwords and sign API requests (HMAC).

Features

  • • MD5, SHA-1, SHA-256, SHA-384 and SHA-512 at the same time
  • • HMAC signatures with your own secret key
  • • Hash text or files up to 200 MB
  • • Hex or Base64 output and instant checksum verification

Your data stays local

Everything is calculated in your browser using the Web Crypto API. Your text, files and secret keys are never uploaded.

Note: MD5 and SHA-1 are not safe for passwords or signatures.

How to use the Hash Generator

  1. 1

    Choose Text to hash a string, or File to hash any file from your computer (up to 200 MB).

  2. 2

    Type or paste the text, or drop the file. MD5, SHA-1, SHA-256, SHA-384 and SHA-512 are calculated at the same time.

  3. 3

    Optionally enter a secret key to compute HMAC signatures instead of plain hashes, and switch the output between hex and Base64 or uppercase.

  4. 4

    To verify a download or a signature, paste the expected value into the compare box. The tool tells you which algorithm matches.

Practical examples

Verifying downloads

Linux ISOs, installers and release archives publish a SHA-256 checksum. Hash the downloaded file and compare: a single changed byte gives a completely different value.

Webhook signatures

GitHub, Stripe and Shopify sign webhook bodies with HMAC-SHA256. Hash the raw payload with your secret to check that your server computes the same signature.

Cache keys and ETags

Hash the content of a file or API response to build a short, stable key that changes only when the content changes.

Comparing files

Two files with the same SHA-256 are, for all practical purposes, identical. Comparing hashes is faster than comparing large files byte by byte.

Frequently asked questions

Can a hash be reversed?+

No. A hash function is one-way: you cannot compute the input from the output. Short or common inputs can still be guessed by trying many candidates, which is why passwords need special slow algorithms.

Is MD5 or SHA-1 still safe?+

Not for security. Practical collisions exist for both, so attackers can create two different inputs with the same hash. They are still fine as fast checksums against accidental corruption. Use SHA-256 or better for anything security related.

Should I hash passwords with SHA-256?+

No. General hashes are designed to be fast, so attackers can test billions of guesses per second. Store passwords with bcrypt, scrypt or Argon2, which are slow on purpose and add a salt.

What is the difference between a hash and an HMAC?+

A hash depends only on the input. An HMAC also mixes in a secret key, so only someone with the key can produce or verify it. That makes it suitable for signing messages and webhooks.

From the blog