Online Hash Calculator
MD5 / SHA-1 / SHA-256 / SHA-384 / SHA-512
What Is a Hash?
A hash (also called a fingerprint or message digest) is a one-way, irreversible mathematical function that maps input of any length to a fixed-length hexadecimal string. The same input always produces the same output, but the original text cannot be recovered from the output. This tool supports five algorithms — MD5 (128-bit/32 chars), SHA-1 (160-bit/40 chars), SHA-256 (256-bit/64 chars), SHA-384 (384-bit/96 chars), and SHA-512 (512-bit/128 chars) — computed entirely in your browser, so your data is never uploaded to a server. For reversible encryption, use the symmetric encryption tool.
Algorithm Comparison & Use Cases
| Algorithm | Output Length | Security | Recommended Uses |
|---|---|---|---|
| MD5 | 32 chars (128-bit) | Insecure (collisions broken) | Non-security: download checks, deduplication |
| SHA-1 | 40 chars (160-bit) | Deprecated (SHAttered attack) | Git version IDs, legacy compatibility |
| SHA-256 | 64 chars (256-bit) | Secure | Password storage, digital signatures, blockchain, SSL certificates |
| SHA-384 | 96 chars (384-bit) | Secure | High-security, government/military compliance |
| SHA-512 | 128 chars (512-bit) | Very secure | Highest-security needs, long-document fingerprints |
Click "Hash All" to generate the hash for every algorithm at once and easily compare their outputs.
Frequently Asked Questions
No. A hash is a digest function that maps input of arbitrary length to a fixed-size output; information is lost in the process, so it is impossible to recover the original text from the hash. So-called "MD5 decryption" on the web is actually rainbow-table lookup — attackers pre-compute hashes of many common strings and store them in a database, then simply look up the match. It is not real decryption. For reversible encryption, use a symmetric encryption tool instead.
In 2004, Professor Wang Xiaoyun's team published an MD5 collision attack that could construct two files, different in content but identical in MD5, within hours. This means an attacker can forge a file while keeping its hash unchanged. For cryptographic scenarios, you should use at least SHA-256.
SHA-1 produces a 160-bit digest, while SHA-256 produces 256 bits. In 2017 Google published the first real-world SHA-1 collision (the SHAttered attack), proving SHA-1 is no longer secure either. The recommended family today is SHA-2, i.e. SHA-256, SHA-384 and SHA-512.
After downloading a file, compute its MD5 or SHA-256 hash and compare it with the value published by the official source. If they match, the file is intact; if not, it may have been tampered with or corrupted in transit. This tool processes text input; for large-file verification, use command-line tools such as md5sum or shasum.