What this tool does
Text in, its digest out, in the algorithm you pick.
hello
2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824
SHA-256 by default, SHA-1 and SHA-512 on the same menu. The digest is computed by the browser’s own Web Crypto implementation — no hashing code of ours, and nothing sent anywhere.
Generator, calculator, converter: one operation
The same thing goes by a SHA-256 generator, a calculator, a converter, a hash tool. It is one operation: text in, a digest of fixed length out. SHA-256, SHA256, SHA-2 256 and sha 256 all name that one algorithm as well — the spelling moves, the result does not.
The digest comes out as lowercase hexadecimal, sixty-four characters for SHA-256 and forty for SHA-1. Tools that show a shorter base64 string encode the thirty-two raw bytes behind that hex; passing the hex text itself to a base64 encoder gives something longer and different.
Why the command line may disagree
hello → 2cf24dba5fb0a30e…
hello\n → 5891b5b522d5df08…
echo hello | sha256sum hashes the second one: echo adds a line break. Neither digest is wrong; they are digests of different bytes, and a hash has no way to tell you that the difference was invisible. If you are comparing against a checksum, check the newline first.
The other difference is the unit: this box holds text, and what gets hashed is its UTF-8 bytes. A file is bytes already — its encoding, its line endings, its final newline are part of it — so for a file, hash the file: sha256sum on Unix, certutil -hashfile on Windows, Get-FileHash in PowerShell.
What a hash is not
- Not encryption. There is no way back. The digest is the same length whatever you paste, which is enough to prove there is no room for the original inside it.
- Not a password store. No salt, no iterations, and fast on purpose. Use bcrypt, scrypt or Argon2 for that, server-side.
- Not an identity for untrusted input, with SHA-1. Two different files can be made to share a SHA-1 digest; nobody knows how to do that for SHA-256 today.
Where it runs
In your browser, through crypto.subtle.digest — the same implementation your browser uses for TLS, not a reimplementation in this page. The text never leaves the tab, which is the point: a string worth hashing is often a string worth not sending to a stranger.
Private by design
Everything runs locally in your browser with JavaScript. Your data is never uploaded, which makes the tool safe for sensitive content, and it keeps working offline.