Online Hash Calculator

MD5 / SHA-1 / SHA-256 / SHA-384 / SHA-512

What Is a Hash?

A hash (also called a fingerprint or message digest) is a one-way, irreversible mathematical function that maps input of any length to a fixed-length hexadecimal string. The same input always produces the same output, but the original text cannot be recovered from the output. This tool supports five algorithms — MD5 (128-bit/32 chars), SHA-1 (160-bit/40 chars), SHA-256 (256-bit/64 chars), SHA-384 (384-bit/96 chars), and SHA-512 (512-bit/128 chars) — computed entirely in your browser, so your data is never uploaded to a server. For reversible encryption, use the symmetric encryption tool.

Algorithm Comparison & Use Cases

AlgorithmOutput LengthSecurityRecommended Uses
MD532 chars (128-bit)Insecure (collisions broken)Non-security: download checks, deduplication
SHA-140 chars (160-bit)Deprecated (SHAttered attack)Git version IDs, legacy compatibility
SHA-25664 chars (256-bit)SecurePassword storage, digital signatures, blockchain, SSL certificates
SHA-38496 chars (384-bit)SecureHigh-security, government/military compliance
SHA-512128 chars (512-bit)Very secureHighest-security needs, long-document fingerprints

Click "Hash All" to generate the hash for every algorithm at once and easily compare their outputs.

Frequently Asked Questions

Can a hash be decrypted or reversed?

No. A hash is a digest function that maps input of arbitrary length to a fixed-size output; information is lost in the process, so it is impossible to recover the original text from the hash. So-called "MD5 decryption" on the web is actually rainbow-table lookup — attackers pre-compute hashes of many common strings and store them in a database, then simply look up the match. It is not real decryption. For reversible encryption, use a symmetric encryption tool instead.

Why is MD5 no longer considered secure?

In 2004, Professor Wang Xiaoyun's team published an MD5 collision attack that could construct two files, different in content but identical in MD5, within hours. This means an attacker can forge a file while keeping its hash unchanged. For cryptographic scenarios, you should use at least SHA-256.

What is the difference between SHA-1 and SHA-256?

SHA-1 produces a 160-bit digest, while SHA-256 produces 256 bits. In 2017 Google published the first real-world SHA-1 collision (the SHAttered attack), proving SHA-1 is no longer secure either. The recommended family today is SHA-2, i.e. SHA-256, SHA-384 and SHA-512.

How do I use a hash to verify file integrity?

After downloading a file, compute its MD5 or SHA-256 hash and compare it with the value published by the official source. If they match, the file is intact; if not, it may have been tampered with or corrupted in transit. This tool processes text input; for large-file verification, use command-line tools such as md5sum or shasum.