Hash Generator
Five hashes at once for text or files of any size, plus a checker that tells you if a download is genuine.
- Runs in your browser
- No upload
- No sign-up
Drop files here, or
Any file, any size · ISO, ZIP, installers, photos, PDFs
Stays on your device
Works with hex or Base64, a sha256sum line, or an SRI value like sha384-…. It finds the algorithm by the length.
Check a webhook signature
Paste what your server received to see whether it really came from the provider. Checked here, with a constant-time comparison; nothing is sent anywhere.
Expected header
About this tool
A hash is a short fingerprint of some data. Change one letter or one byte and the fingerprint changes completely, which is why download pages publish them: if the SHA-256 of the file on your computer matches the one on the website, you have exactly the file they meant you to have, with nothing damaged or swapped along the way.
This tool works out MD5, SHA-1, SHA-256, SHA-384 and SHA-512 together, live as you type, so you never have to guess which one a page wants. Drop in files instead and each one is read in 4 MB pieces by background workers, with a progress bar, so a multi-gigabyte disk image works as well as a photo. Paste the expected checksum into “Check a checksum” and it tells you in green or red whether anything matches.
Developers get the extras: hex, Base64 or Base64url output, HMAC signing with a key typed as text, hex or Base64, and a webhook checker that says whether a Stripe, GitHub, Shopify or Slack request really came from them, following each provider’s signing rules with a constant-time comparison. Everything is calculated on your device; text, files, keys and secrets are never uploaded.
How to use Hash Generator
- Choose “Text” to type or paste, or “Files” to drop or choose one or more files.
- Read the hashes as they appear. Tap an algorithm chip to hide ones you don’t need, and pick “hex”, “HEX”, “Base64” or “Base64url”.
- To sign with a key, tick “HMAC with a secret key”, type the key and say whether it is text, hex or Base64.
- Paste a published checksum into “Check a checksum”. A green box means a match; red means the data differs.
- Press the copy button on any row, “Copy all” for a card, or “Save as .txt” to keep a checksum list for your files.
- To check a webhook, pick the provider under “Check a webhook signature” and paste the secret, the signature header and the raw body. “Try an example” shows how it works.
The text “abc” gives a SHA-256 starting ba7816bf 8f01cfea and an MD5 starting 90015098 3cd24fb0. Typing “abd” instead gives completely different values for both, even though only one letter changed.
Features
- MD5, SHA-1, SHA-256, SHA-384 and SHA-512 shown together and updated on every keystroke.
- Files of any size, read in 4 MB pieces with a progress bar, time left and a Stop button.
- Several files at once, each with its own result card.
- HMAC for all five algorithms, with the key written as text, hex or Base64.
- Output as lower-case hex, upper-case hex, Base64 or Base64url (the URL-safe form used in JWTs).
- Webhook signature checks for Stripe (t= and v1=, with a timestamp tolerance), GitHub (sha256=), Shopify (Base64) and Slack (v0=), using a constant-time comparison, plus the signature you should have received when it doesn’t match.
- Checksum checker that accepts bare hex or Base64, sha256sum and macOS shasum lines, and SRI values such as sha384-….
- “Save as .txt” writes a checksum list in the same layout as the sha256sum command.
- Text is hashed as UTF-8, as nearly every other tool and language does.
Tips and good to know
- If a checksum doesn’t match, download the file again first: interrupted downloads are far more common than tampering.
- For text, a hidden space or line break at the end changes the hash, so check the very end if results differ.
- Use SHA-256 or SHA-512 whenever you choose. MD5 and SHA-1 are fine for catching accidental damage, but people can now deliberately make two different files with the same MD5 or SHA-1.
- Never store passwords as a plain hash from any tool. Real systems use slow, salted methods such as bcrypt or Argon2.
- A webhook check needs the raw body exactly as sent. A framework that parses the JSON and writes it out again changes spaces or key order, and the signature stops matching.
Frequently asked questions
Are my files or text uploaded?
No. Every hash is calculated in your browser on your own device. Files are read from your disk in pieces and never sent anywhere, and that includes any HMAC secret key you type.
Is it free? Is there a file size limit?
It is free, with no sign-up and no limit set by the tool. Files are read 4 MB at a time, so very large files work too; they just take longer.
Does it work on a phone or offline?
Yes. It works in Safari, Chrome and Firefox on iPhone, Android and computers. Once the page has loaded you can turn off the internet and keep hashing text and files.
How do I check that a download is genuine?
Choose Files, add the download, then paste the published checksum into “Check a checksum”. The algorithm is found from its length, with a green match or a red warning.
Can a hash be turned back into the original text?
No. A hash is one-way. Sites that claim to “decrypt” MD5 only look it up in huge lists of already-hashed common passwords.
What is HMAC and when do I need it?
HMAC mixes a secret key into the hash, so only someone with the key can produce the same result. APIs and webhooks use it to sign messages. For Stripe, GitHub, Shopify or Slack, use “Check a webhook signature”; for anything else, tick HMAC, enter the secret and compare.
Why does my result differ from another website?
Usually the input isn’t quite the same: a trailing space, Windows line endings or another text encoding. This tool hashes exactly what is in the box, as UTF-8.
Page last reviewed
