Skip to content
M2TOOLKIT

Security · free tool

Hash Generator (SHA-256, MD5)

Calculate SHA-256, SHA-512, SHA-1 and MD5 hashes of text — or HMAC signatures with a key.

Use it as often as you like — it's free, with no sign-up and no limits.

  • Security
  • Free
  • No sign-up
  • Runs in your browser
  • Updated

For files, use the File Checksum tool. Hashes are calculated with the Web Crypto API (MD5 with a built-in implementation).

Everything you type is processed in your browser. Nothing you enter is sent to our servers or stored by us.

How to use the Hash Generator

  1. Type or paste the text.
  2. Turn on HMAC and enter a key if you need a signature.
  3. Copy the hash you need.

What does this tool do?

A hash function turns any input into a fixed-length fingerprint. The same input always gives the same hash, and a tiny change gives a completely different one. HMAC combines a hash with a secret key to prove a message came from someone who knows the key, which is how many webhooks are signed.

Text is encoded as UTF-8 before hashing, matching what most programming languages do.

Why use it?

  • Verify webhook signatures.
  • Generate checksums and cache keys.
  • Compare values without revealing them.

Use cases

  • Check a webhook signature: compute HMAC-SHA256 of the body with your signing secret and compare it with the header.
  • Create cache keys, ETags or de-duplication keys from text.
  • Confirm two pieces of text are byte-for-byte identical without comparing them by eye.

Example

The SHA-256 of “hello” is 2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824.

Common mistakes

  • Hashing text with an invisible difference — a trailing space or newline — and getting a different hash. Hashes change completely with any change: “hello” and “Hello” have nothing in common.
  • Storing passwords as plain SHA-256 or MD5. Use a slow, salted algorithm such as bcrypt, scrypt or Argon2.

Accuracy and limits

  • MD5 and SHA-1 are broken for security purposes. Use SHA-256 or better for anything security-related, and a dedicated algorithm (like bcrypt or Argon2) for storing passwords.

Privacy

Everything you type is processed in your browser. Nothing you enter is sent to our servers or stored by us. There's no account to create and nothing to install.

Frequently asked questions

Is it safe to do this in a browser?

Yes, because nothing leaves your device. Everything is generated or checked with your browser's built-in cryptography (the Web Crypto API) — no network requests are made with what you type.

Can a hash be reversed?

Not directly. But short or common inputs can be found by guessing, so hashing alone doesn't protect weak passwords.

What is the MD5 of “hello”?

5d41402abc4b2a76b9719d911017c592. The SHA-256 is 2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824. Text is hashed as UTF-8, so results match Python's hashlib, Node's crypto and the command line (echo -n hello | sha256sum).

How do I hash a file?

Use the File Checksum tool. It reads the file on your device and shows its SHA-256 and other checksums, so you can compare them with a published value.

Last reviewed by the M2Toolkit team.

Other tools people use alongside the hash generator.