Skip to main content

Hash Generator

Generate MD5, SHA-1, SHA-256, and SHA-512 hashes from any text input.

Digest method, algorithm choice, and verification

A cryptographic hash maps input bytes to a fixed-length digest. The same bytes produce the same digest, while a one-byte change should produce a very different result. Hashes are not encryption and cannot be decrypted. This page uses browser cryptographic APIs for supported SHA algorithms and clearly separates legacy compatibility options from security recommendations.

Methodology

  1. Text is converted to UTF-8 bytes before hashing, so encoding is part of the result.
  2. Supported SHA digests are computed with the browser Web Crypto implementation.
  3. Output is rendered as hexadecimal bytes in a stable order.
  4. To compare files or systems, both sides must use the same bytes, character encoding, algorithm, and line endings.

Worked review example

Hashing “hello” is different from hashing “hello” followed by a newline. Copying text between Windows and Unix tools can therefore change a digest when line endings differ. For a release checksum, hash the original file bytes rather than text copied from an editor. For passwords, use a dedicated salted password-hashing function instead of a fast general-purpose digest.

Test coverage and expected behavior

Checks include known short vectors, empty input, Unicode text, line-ending changes, and repeated runs. We verify deterministic output for the same byte sequence and a changed digest after editing one character. We do not claim collision resistance for algorithms that standards treat as obsolete.

Decision checklist before using the output

Write down the verification goal before choosing an algorithm. For a public file checksum, use the algorithm published by the distributor and compare every hexadecimal character through a trusted channel. For deduplication, understand that equal digests are a practical signal, not proof that content is benign. For digital signatures, message authentication, and password storage, a bare hash is the wrong construction; use a protocol or library designed for that purpose. Make the byte representation reproducible by agreeing on UTF-8, line endings, normalization, and whether a final newline is present. Test one known vector and one changed input before trusting an integration. If a downloaded file’s checksum differs, do not keep retrying until a value happens to match; obtain the file and expected digest again from the authoritative source and investigate transport or version differences.

Important limitations

  • MD5 and SHA-1 are unsuitable for collision-sensitive security uses.
  • A plain SHA digest is unsuitable for password storage.
  • A matching hash checks byte equality, not whether content is trustworthy.
  • Browser memory limits can affect very large inputs.

Sources and specifications

These references define the relevant format or browser behavior. They do not endorse WordCaseFix.

Last reviewed: August 6, 2026