What is a hash?
A cryptographic hash function turns any amount of data into a short, fixed-length fingerprint. The same input always gives the same hash, changing a single bit gives a completely different one, and there is no way to work backwards from the hash to the input. That makes hashes useful for checking file integrity, detecting changes, deduplicating data and building signatures.
For example, these are the hashes of the five-byte string hello (no trailing newline):
| Algorithm | Length | Hash of hello | Status |
|---|---|---|---|
| MD5 | 128 bits (32 hex) | 5d41402abc4b2a76b9719d911017c592 | Broken — collisions are practical. Fine only for non-security checksums. |
| SHA-1 | 160 bits (40 hex) | aaf4c61ddcc5e8a2dabede0f3b482cd9aea9434d | Broken — a real collision was published in 2017. Avoid for security. |
| SHA-256 | 256 bits (64 hex) | 2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824 | Current standard. Recommended. |
| SHA-384 | 384 bits (96 hex) | — | Recommended. |
| SHA-512 | 512 bits (128 hex) | — | Recommended. |
How to verify a download checksum
- Copy the SHA-256 (or other) checksum published on the official download page.
- Choose the downloaded file with “Or a file”. It is read locally and never uploaded.
- Paste the checksum into “Verify”. A matching algorithm is marked with ✓ match; otherwise you will see a warning.
From the command line:
| System | Command |
|---|---|
| Linux | sha256sum file.iso |
| macOS | shasum -a 256 file.iso |
| Windows (PowerShell) | Get-FileHash file.iso -Algorithm SHA256 |
| Windows (cmd) | certutil -hashfile file.iso SHA256 |
Hashing in code
| Language | SHA-256 of a string |
|---|---|
| JavaScript (browser) | await crypto.subtle.digest('SHA-256', new TextEncoder().encode(s)) |
| Node.js | require('crypto').createHash('sha256').update(s).digest('hex') |
| Python | hashlib.sha256(s.encode()).hexdigest() |
| PHP | hash('sha256', $s) |
| Go | fmt.Sprintf("%x", sha256.Sum256([]byte(s))) |
The browser's Web Crypto API (crypto.subtle) does not support MD5; this tool computes MD5 with its own JavaScript implementation.
Frequently asked questions
Can I use SHA-256 to store passwords?
Not on its own. SHA-256 is designed to be fast, which makes brute-force guessing cheap. Store passwords with a dedicated password hashing function such as Argon2, scrypt or bcrypt, which are deliberately slow and salted.
Why does my hash differ from another tool?
The input bytes are different — most often because of a trailing newline. echo hello | sha256sum hashes hello\n and gives 5891b5b5…, while echo -n hello or printf hello gives 2cf24dba…. Line endings (CRLF vs LF) and character encoding also change the result.
Can a hash be decrypted back to the original text?
No. A hash is a one-way function, not encryption, so there is no key that reverses it. Short or common inputs (like simple passwords) can still be found by guessing candidates and comparing their hashes, which is why unsalted fast hashes are unsafe for secrets.
Is my file uploaded?
No. Text and files are hashed inside your browser; nothing is sent to a server. Files up to 500 MB are supported.