VSThiran

How to generate a SHA-256 checksum online

Quick answer

Paste the text in and a SHA-256 (or SHA-1, SHA-384, SHA-512) hash is generated instantly, entirely in your browser using the Web Crypto API - nothing is uploaded. MD5 is not offered, since it is cryptographically broken and SHA-256 is the appropriate modern replacement for the same job.

Free, no sign-up, and your file is read on your own device rather than uploaded.

A checksum lets you confirm that two pieces of data are identical without comparing them byte-by-byte - change even one character and the hash comes out completely different. This is commonly used to verify a downloaded file was not corrupted, or that two copies of a document match.

MD5 is still what many people search for out of habit, but it has been considered cryptographically broken for security purposes for years - collisions (two different inputs producing the same hash) are practical to generate. SHA-256, part of the same SHA-2 family used throughout modern TLS and software signing, is the appropriate replacement for the same job.

Step by step

  1. Paste or type the text

    The exact content you want a checksum for.

    Hash Generator
  2. Read off the hash

    SHA-256 is shown by default, alongside SHA-1, SHA-384 and SHA-512.

    Hash Generator
  3. Compare against a known-good hash

    If the two match exactly, the content is identical.

Tips

  • A single different character anywhere in the input produces a completely different hash - there is no such thing as a "close" match.
  • For comparing files rather than pasted text, hash each file's exact contents the same way and compare the results.

Common problems

Looking for an MD5 option specifically.

MD5 is not offered because it is no longer considered secure for anything sensitive - SHA-256 does the same integrity-checking job with none of MD5's known weaknesses.

Need a hash for password storage.

Neither MD5 nor SHA-256 (nor any plain hash function) is appropriate for storing passwords - that job needs a purpose-built algorithm like bcrypt, scrypt or Argon2, which are deliberately slow to resist brute-force attacks.

Frequently asked questions

Why is there no MD5 option?
Browsers do not provide MD5 through their built-in cryptographic API, and it is cryptographically broken for security purposes regardless - SHA-256 is the right choice for the same job.
Is this safe to use for sensitive text?
Yes - hashing happens entirely in your browser via the Web Crypto API. Nothing you type is sent anywhere.
Which hash should I use to check a downloaded file?
SHA-256 is the most common choice publishers provide today. Match whichever algorithm the publisher lists alongside their download.

Related related tools

Related articles

Ready to do it?

Free, no sign-up, and nothing is uploaded to a server.