How to use
- 1Type text or drop a file.
- 2All hashes are calculated at once; choose hex or Base64 output.
- 3For HMAC-SHA256, enter your secret key.
- 4Paste an expected hash in the compare field to verify a match.
Which hash algorithm to use
A hash turns any input into a fixed-length fingerprint; change one bit of input and the hash changes completely. SHA-256 is the default choice today for checksums, signatures and integrity checks. SHA-384 and SHA-512 offer larger outputs. MD5 (2004) and SHA-1 (2017, the SHAttered attack) have practical collision attacks: fine for detecting accidental corruption or cache keys, but never for security.
Verifying a download checksum
Software publishers list SHA-256 checksums next to downloads. Drop the downloaded file here, paste the published hash into the compare field, and the tool tells you whether they match. A mismatch means the file is corrupted or has been tampered with — don’t run it. Files are hashed locally, so even large or private files never leave your device.
HMAC and password hashing
HMAC-SHA256 combines a secret key with the message, proving both integrity and that the sender knows the key — it is how webhook signatures (payment providers, GitHub, Slack) and many API authentication schemes work. Plain hashes are not suitable for storing passwords, because GPUs compute billions of SHA-256 hashes per second; use a slow, salted algorithm such as Argon2id, bcrypt or scrypt instead.
Frequently asked questions
Can a hash be decrypted?
No. Hashing is one-way. Short or common inputs can be guessed with lookup tables, which is why hashes of passwords are easy to crack without salting and slow algorithms.
Why do I get a different hash than another tool?
Usually invisible differences in the input: a trailing newline or space, different line endings (CRLF vs LF) or a different text encoding.
How do I verify a webhook signature?
Paste the raw request body as text, enter the webhook secret as the HMAC key, and compare the HMAC-SHA256 result (hex or Base64, matching the provider) with the signature header.
Is my file uploaded?
No. Hashing uses your browser’s Web Crypto API and a local MD5 implementation; nothing is transmitted.
Not happy with the results?
Talk to Webin Agency about fast, SEO-friendly websites, e-commerce and Google Ads management.