🔒 Runs in your browser — nothing is uploaded✓ Free, no signup
Hash Generator — MD5, SHA-256, SHA-512 & HMAC
Hash text or files with MD5, SHA-1, SHA-256, SHA-384 and SHA-512 at once, sign with HMAC, and verify a checksum by pasting it in.
Hashes
When should you use the Hash Generator?
- Verifying a downloaded file against the vendor's published checksum
- Computing an HMAC-SHA256 signature to debug a webhook
- Generating a content hash for caching or deduplication
How to use the Hash Generator
- 1
Choose text or file
Type text in the Text tab, or switch to File and pick a file. All five hashes are computed as you type.
- 2
Add a secret key for HMAC (optional)
Tick HMAC and enter the key to get HMAC-SHA1, SHA-256, SHA-384 and SHA-512 signatures.
- 3
Pick the output format
Hashes are shown as lowercase hex by default. Switch to uppercase hex or Base64 if your system expects that.
- 4
Verify or copy
Paste a known checksum into 'Compare' to see which algorithm matches, or copy any hash with one click.
Examples
Hashes of the text “hello”
Input
hello
Output
MD5: 5d41402abc4b2a76b9719d911017c592
SHA-1: aaf4c61ddcc5e8a2dabede0f3b482cd9aea9434d
SHA-256: 2cf24dba5fb0a30e26e83b2ac5b9e29e
1b161e5c1fa7425e73043362938b9824Common errors and how to fix them
My hash doesn't match the one from my code- Your code probably hashes a trailing newline (e.g. echo adds one — use echo -n), different line endings, or non-UTF-8 bytes.
Checksum doesn't match the download- Make sure you are comparing the same algorithm (SHA-256 vs SHA-512). If it still differs, the download is incomplete or modified — download it again.
Webhook HMAC signature is different- Hash the raw request body exactly as received, before JSON parsing or re-serialising. Some providers also prefix the signature, e.g. sha256=…
Explore More Developer Tools
Format, Validate, and Generate Data Instantly
TrueFormatter provides essential utilities for modern web development, including JSON formatting, YAML conversion, and more.
JSON Auto-Fixer & Formatter
Repair, validate, and beautify broken JSON (missing quotes, trailing commas).
JSON Validator & Linter
Check JSON syntax and see the exact line and column of every error.
JSON Beautifier
Pretty-print and indent JSON for easy reading and debugging.
JSON Compare & Diff Tool
Find the difference between two JSON objects visually and quickly.
JSONPath Tester
Evaluate JSONPath expressions with filters and recursive queries.
JSON Schema Generator
Generate a JSON Schema from any sample JSON document.
JSON to CSV Converter
Flatten nested JSON arrays into CSV for spreadsheets.
YAML ⇆ JSON Converter
Convert YAML to JSON or JSON to YAML instantly.
JWT Decoder
Decode and inspect JSON Web Tokens (JWT) Header and Payload.
JWT Generator
Create and sign HS256/HS384/HS512 JSON Web Tokens for testing.
Hash Generator (MD5, SHA)
Generate MD5, SHA-1, SHA-256, SHA-384 and SHA-512 hashes.
Base64 Encoder ⇆ Decoder
Encode text to Base64 and decode Base64 to text for API debugging.
URL Encoder & Decoder
Cleanly encode special characters in URLs and decode query strings.
SQL Formatter & Beautifier
Format SQL queries for MySQL, PostgreSQL, SQL Server, SQLite and more.
CSS Minifier & Compressor
Optimize CSS by removing whitespace and comments to accelerate page load time.
JS Minifier & Compressor
Compress JavaScript to improve website speed and performance.
Regex Tester & Debugger
Test JavaScript regular expressions with live match highlighting and groups.
Cron Expression Generator
Build cron schedules, read them in plain English and preview next runs.
UUID / GUID Generator
Generate unique V4 UUIDs for database keys or testing.
Epoch converter online
Convert UNIX timestamps to human-readable dates and back instantly.
Crop Image Online
Crop images exactly as selected with fixed aspect ratios. No upload, no resize, no quality loss.
Compress Image Online
Compress JPG, PNG & WebP images directly in your browser. No upload, no tracking, instant download.
Hash Generator FAQ
A hash function turns any input into a fixed-length fingerprint. The same input always produces the same hash, and a tiny change in the input produces a completely different one.
Use SHA-256 for checksums, signatures and anything security-related. MD5 and SHA-1 are broken for security purposes and should only be used for non-security checks or compatibility with legacy systems.
You can see its hash, but do not store passwords as plain MD5 or SHA hashes. Use a slow, salted password hash such as bcrypt, scrypt or Argon2.
No. Hashes are one-way. Short or common inputs can be found with lookup tables, which is why passwords need salting and slow hashing.
Switch to File mode, choose the file, then paste the checksum published by the vendor into 'Compare with a known hash'. A green tick shows which algorithm matches.
HMAC combines a hash with a secret key. It is used to sign webhooks and API requests (e.g. GitHub and Stripe webhooks use HMAC-SHA256) so the receiver can check the message was not tampered with.
