No. MD5 is cryptographically broken and far too fast. Use bcrypt, scrypt, or Argon2 for passwords — these are slow by design to resist brute force attacks.
Generate MD5, SHA-1, SHA-256, SHA-384, and SHA-512 hashes from text or any file — live as you type, entirely in your browser. Compare two hashes to verify integrity in one click.
Hash text directly (live as you type), hash a file, or compare two hashes.
Type or paste text, or drag and drop any file — any format, any size.
All five algorithms compute simultaneously — no need to pick one upfront.
Copy any individual hash, or use the Compare tab to verify integrity.
Click to upload or drag and drop any file
Any format, any size — processed entirely in your browser
Paste two hashes to compare them — useful for verifying a downloaded file's checksum against the one published by the developer.
| Algorithm | Output Length | Speed | Security Status | Use This For | Don't Use For |
|---|---|---|---|---|---|
| MD5 | 128 bits (32 hex) | Very fast | Broken | Legacy checksums, non-security deduplication | Passwords, signatures, certificates |
| SHA-1 | 160 bits (40 hex) | Fast | Broken | Git commit IDs (legacy), non-security checksums | TLS certificates, code signing, passwords |
| SHA-256 | 256 bits (64 hex) | Fast | Secure | File integrity, HMAC, digital signatures, TLS | Directly hashing passwords (use bcrypt/Argon2) |
| SHA-384 | 384 bits (96 hex) | Fast | Secure | Higher security margin than SHA-256, TLS 1.3 | Directly hashing passwords |
| SHA-512 | 512 bits (128 hex) | Fast (faster than SHA-256 on 64-bit CPUs) | Secure | Maximum hash length, file integrity, HMAC-SHA-512 | Directly hashing passwords |
SHA-256 is too fast — an attacker with a GPU can test billions of passwords per second. Password hashing needs a deliberately slow function: bcrypt, scrypt, or Argon2. These are built on top of hash functions but add work factors that make brute force impractical.
HMAC (Hash-based Message Authentication Code) combines a hash function with a secret key — HMAC-SHA256 is the signature algorithm inside most JWTs and API request signing schemes. It proves both integrity (the data wasn't changed) and authenticity (the sender knows the key).
No. MD5 is cryptographically broken and far too fast. Use bcrypt, scrypt, or Argon2 for passwords — these are slow by design to resist brute force attacks.
SHA-256 is used for file integrity verification, HMAC authentication, digital signatures, TLS certificate fingerprints, and as the foundation of most blockchain protocols.
No. Hashing uses the FileReader API and the browser's Web Crypto API entirely locally. No data is uploaded to any server.
SHA-512 uses 64-bit words, making it faster than SHA-256 (32-bit words) on modern 64-bit CPUs, even though it produces a longer output.