Skip to content

Hash Generator guide

Tool guide. Updated .

What cryptographic hashes and HMACs are, which algorithms the XGM Hash Generator computes, when MD5 and SHA-1 are still acceptable and when they are not.

What a hash function does

A cryptographic hash function maps input of any size to a fixed-size output, called a digest. Good hash functions are one-way (you cannot recover the input from the digest), collision-resistant (you cannot find two inputs with the same digest) and sensitive to change (flipping one bit changes about half the output bits). Those properties make hashes useful for checksums, signatures, deduplication and integrity checks.

A hash is not encryption. There is no key and nothing to decrypt; the digest simply identifies the input. Short or predictable inputs, such as common passwords, can be found by hashing guesses and comparing, which is why hashing alone does not protect secrets.

Hash versus HMACA hash takes only the message; an HMAC combines the message with a secret key, so only someone with the key can produce or check the digest.Input textEncoded as UTF-8 bytes in your browserHash: SHA-256(message)Anyone can compute it; proves the content, notwho made itHMAC: HMAC-SHA256(key, message)Needs the secret key; proves the content andknowledge of the keyHex digest64 hex characters for SHA-256, 128 for SHA-512
A hash takes only the message; an HMAC combines the message with a secret key, so only someone with the key can produce or check the digest.

How to use the Hash Generator

  1. Open the Hash Generator and type or paste text. Press Load example to see the classic test sentence.
  2. The digests for every algorithm appear as hex strings.
  3. To compute HMAC digests, tick "HMAC with a secret key" and enter the key.
  4. Copy the digest you need, or export all of them.

The input is hashed as UTF-8. The same text in another encoding, or with a trailing newline that an editor added, produces a different digest. When comparing with a digest from a command-line tool, make sure both sides hash exactly the same bytes.

Matching digests on the command line
# no trailing newline: printf, not echo
printf '%s' 'The quick brown fox jumps over the lazy dog' | sha256sum
d7a8fbb307d7809469ca9abcb0082e4f8d5651e46d3cdb762d02d0bf37c9e592  -

# HMAC-SHA256
printf '%s' 'message' | openssl dgst -sha256 -hmac 'secret-key'

Algorithms and when to use them

Algorithms computed by the generator
AlgorithmDigest sizeStatusUse it for
MD5128 bits (32 hex)Broken: collisions are practicalNon-security checksums, legacy identifiers
SHA-1160 bits (40 hex)Broken: collisions demonstratedLegacy compatibility only
SHA-256256 bits (64 hex)SecureIntegrity checks, signatures, general use
SHA-384384 bits (96 hex)SecureWhere policies require larger SHA-2 digests
SHA-512512 bits (128 hex)SecureGeneral use; often fast on 64-bit systems
SHA3-224 to SHA3-512224 to 512 bitsSecureWhere a policy names SHA-3 (FIPS 202); computed by the page, not by Web Crypto

"Broken" means an attacker can create two different inputs with the same digest. That matters whenever a hash is used to trust content, such as in certificates, code signing or document integrity. It matters much less for detecting accidental corruption of a download, where nobody is trying to craft a collision, which is why MD5 checksums are still published for some files.

Never store passwords as plain hashes

Fast hashes like SHA-256 let attackers test billions of guesses per second against a leaked database. Store passwords with a slow, salted password hashing function such as Argon2id, scrypt or bcrypt, as recommended by OWASP.

HMAC: hashes with a key

HMAC (RFC 2104) combines a hash function with a secret key. The receiver, who knows the same key, recomputes the HMAC and compares; a match proves the message was not changed and was produced by someone with the key. Webhooks, API request signing and JWTs with HS256 all rely on HMAC.

Where HMAC is used
UseHow
Webhook signaturesThe sender puts HMAC-SHA256(secret, body) in a header; the receiver recomputes it
API request signingCanonical request string signed with an access secret
JWT HS256HMAC-SHA256 over the header and payload
Cookie or token integrityServer signs a value so clients cannot change it

When verifying an HMAC in code, compare digests with a constant-time comparison function, not a normal string comparison, to avoid leaking information through timing. Use a long random key, and rotate it if it may have been exposed. The key you type into the generator stays in the page and is not sent anywhere.

Everyday uses of hashes

Where hashes show up
UseExampleAlgorithm today
File integrityChecksum next to a downloadSHA-256
Content addressingGit objects, container image layersSHA-1 in older Git repositories, SHA-256 for images
Caching and ETagsFingerprint of a response bodyAny fast hash; security not required
DeduplicationDetecting identical uploadsSHA-256
Subresource Integrityintegrity="sha384-…" on script tagsSHA-256, SHA-384 or SHA-512 (base64)
Digital signaturesTLS certificates, code signingSHA-256 or stronger inside the signature

Subresource Integrity is a good example of a security use: the page lists the expected hash of a script loaded from a CDN, and the browser refuses to run the file if its hash differs. Note that SRI values are base64-encoded digests, while the generator shows hex; the bytes are the same, only the encoding differs.

Verifying downloads with checksums

Projects often publish SHA-256 checksums next to downloads. After downloading, compute the hash of the file locally and compare it with the published value. A match shows the file was not corrupted or swapped, provided the checksum itself came from a trustworthy page, ideally over HTTPS on the project's own site such as https://downloads.example.com.

Checking a downloaded file
# Linux
sha256sum example-installer.tar.gz

# macOS
shasum -a 256 example-installer.tar.gz

# Windows PowerShell
Get-FileHash .\example-installer.zip -Algorithm SHA256

The generator works on text you paste. Hash files locally with the commands above, which avoids loading large files into a browser tab and works offline.

FAQ

Is my text uploaded?

No. Hashing runs in your browser with the Web Crypto API (MD5 in JavaScript), and the input is not sent anywhere.

Can a hash be reversed?

Not mathematically. Short or common inputs can be guessed by hashing candidates, which is why hashes of passwords or simple values are not secret.

Why does my hash differ from another tool?

The bytes differ: a trailing newline, a different text encoding, or Windows line endings. Hash exactly the same bytes on both sides.

Is SHA-256 safe for passwords?

No. It is too fast. Use Argon2id, scrypt or bcrypt with a unique salt per password.

What is the difference between SHA-256 and SHA-512?

Digest size and internal word size. Both are secure SHA-2 functions; SHA-512 produces a longer digest and can be faster on 64-bit processors.

Is MD5 still useful?

For detecting accidental corruption or as a non-security identifier, yes. For anything where someone might deliberately create a collision, no.

What is a salt?

A random value stored with each password hash so identical passwords get different hashes. It defeats precomputed tables but does not make a fast hash slow.

Does the generator support SHA-3?

Yes. Turn on “Also show SHA-3” and it adds SHA3-224, SHA3-256, SHA3-384 and SHA3-512. Web Crypto has no SHA-3, so these four are computed by the page's own FIPS 202 implementation; that is slower than the native hashes, which is why they are off by default rather than always printed.

Why are there different lengths of output for the same text?

Each algorithm has a fixed digest size: 32 hex characters for MD5, 40 for SHA-1, 64 for SHA-256, 96 for SHA-384 and 128 for SHA-512. The length says nothing about the input size.

Can I hash a file with this tool?

Yes. “Hash a file” reads the file in your browser and hashes its bytes exactly as sha256sum, shasum -a 256 or Get-FileHash would locally; nothing is uploaded. A command-line tool is still faster for very large files.

How long should an HMAC key be?

At least as long as the digest, for example 32 random bytes for HMAC-SHA256. Longer keys do not hurt; short, guessable keys do.

Sources