100% local — your data never leaves your browser

Hash Generator — Check a Fingerprint Matches

Hash text with SHA-256, SHA-1 or SHA-512. The same text always gives the same digest, so you can compare yours against the one you were handed.

Instant Private Zero cookies
Algorithm

Text input

Hash output

What this tool does

Text in, its digest out, in the algorithm you pick.

hello
2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824

SHA-256 by default, SHA-1 and SHA-512 on the same menu. The digest is computed by the browser’s own Web Crypto implementation — no hashing code of ours, and nothing sent anywhere.

Generator, calculator, converter: one operation

The same thing goes by a SHA-256 generator, a calculator, a converter, a hash tool. It is one operation: text in, a digest of fixed length out. SHA-256, SHA256, SHA-2 256 and sha 256 all name that one algorithm as well — the spelling moves, the result does not.

The digest comes out as lowercase hexadecimal, sixty-four characters for SHA-256 and forty for SHA-1. Tools that show a shorter base64 string encode the thirty-two raw bytes behind that hex; passing the hex text itself to a base64 encoder gives something longer and different.

Why the command line may disagree

hello    → 2cf24dba5fb0a30e…
hello\n  → 5891b5b522d5df08…

echo hello | sha256sum hashes the second one: echo adds a line break. Neither digest is wrong; they are digests of different bytes, and a hash has no way to tell you that the difference was invisible. If you are comparing against a checksum, check the newline first.

The other difference is the unit: this box holds text, and what gets hashed is its UTF-8 bytes. A file is bytes already — its encoding, its line endings, its final newline are part of it — so for a file, hash the file: sha256sum on Unix, certutil -hashfile on Windows, Get-FileHash in PowerShell.

What a hash is not

  • Not encryption. There is no way back. The digest is the same length whatever you paste, which is enough to prove there is no room for the original inside it.
  • Not a password store. No salt, no iterations, and fast on purpose. Use bcrypt, scrypt or Argon2 for that, server-side.
  • Not an identity for untrusted input, with SHA-1. Two different files can be made to share a SHA-1 digest; nobody knows how to do that for SHA-256 today.

Where it runs

In your browser, through crypto.subtle.digest — the same implementation your browser uses for TLS, not a reimplementation in this page. The text never leaves the tab, which is the point: a string worth hashing is often a string worth not sending to a stranger.

Private by design

Everything runs locally in your browser with JavaScript. Your data is never uploaded, which makes the tool safe for sensitive content, and it keeps working offline.

Frequently asked questions

Why does my hash differ from `sha256sum`?
Almost always a trailing newline. `echo hello` sends four characters and a line break, so `sha256sum` hashes `hello\n` and gets `5891b5b5…`, while pasting `hello` here gives `2cf24dba…`. Both are correct — they are hashes of different bytes. The second usual cause is that a file is bytes and this box is text: for a real file, `sha256sum` on Unix or `certutil -hashfile` on Windows reads it byte for byte.
Can I use this to store passwords?
No. A raw hash has no salt and no iteration count, and it is fast — which is exactly what someone testing billions of guesses wants. Passwords belong in bcrypt, scrypt or Argon2, on your server, with the cost parameters those libraries exist to manage. A hash answers “is this the same text?”, not “is this the right password?”.
Is SHA-1 still usable?
For a checksum among friendly inputs, yes — Git still identifies its objects that way. Not where someone could craft two files with the same hash: collisions in SHA-1 have been public since 2017, so signatures, deduplication of untrusted uploads and anything that decides trust want SHA-256 or SHA-512. That is why SHA-256 is the default here.

Related converters