Generate MD5 and SHA hashes of any text, or sign it with an HMAC key. Useful for checksums, webhook and API signatures, and testing.
MD5
SHA-1
SHA-256
SHA-384
SHA-512
HMAC (signed hash)
Enter a secret key to sign the text above, for example to check a webhook or API signature.
Computed in your browser: SHA and HMAC with the Web Crypto API, MD5 with the audited @noble/hashes library. Nothing is sent anywhere. MD5 and SHA-1 are broken for security; for passwords, use bcrypt or Argon2 on your server.
What a hash is
A hash turns any text into a fixed-length fingerprint. The same input always gives the same hash, and a tiny change gives a completely different one. Example: SHA-256 of abc is ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad, and its MD5 is 900150983cd24fb0d6963f7d28e17f72.
Which algorithm?
SHA-256: the standard choice for checksums and signatures. SHA-384 and SHA-512 are longer versions from the same family.
MD5 and SHA-1: legacy only. Both are broken for security, but you'll still see them as download checksums and in older systems.
HMAC-SHA-256 / HMAC-SHA-512: when the hash must prove it came from someone who knows a secret key, for example a webhook signature.
HMAC example
With the key Jefe and the text what do ya want for nothing?, HMAC-SHA-256 gives 5bdcc146bf60754e6a042426089575c75a003f089d2739839dec58b964ec3843. That's the published test value from RFC 4231, so you can use it to check that your own code signs messages the same way. Text and keys are read as UTF-8, and the result is shown in hex and Base64.
Frequently asked questions
Can a hash be reversed?
No. Hashes are one-way, but short or common inputs can be guessed by trying many options, which is why passwords need slow, salted hashing such as bcrypt or Argon2.
Is MD5 still safe to use?
Not for security. Researchers can create two different inputs with the same MD5 hash, so it mustn't be used for signatures or passwords. It's still fine for spotting accidental changes, such as checking a download against a published MD5 checksum, and for older systems that expect it.
What is an HMAC?
A hash that also depends on a secret key (RFC 2104). Only someone with the key can produce the same value, so services use HMAC-SHA-256 to sign webhooks and API requests. To check a signature, paste the exact message body, enter the shared secret and compare the result with the one you received, in hex or Base64 as the service sends it.
Is my text or key sent anywhere?
No. SHA and HMAC use your browser's built-in Web Crypto API, and MD5 runs in the page with the open-source @noble/hashes library. Nothing is uploaded, so it's safe to use with real secrets, though it's good practice to rotate any key you paste into a website.
How do I verify a file download?
Compare the publisher's SHA-256 checksum with one computed from the file, for example with `certutil -hashfile file SHA256` on Windows or `shasum -a 256 file` on macOS/Linux. Our file checksum checker does the same in the browser.