// SHA-1/256/384/512 via the native
Web Crypto API
· MD5 adapted from
blueimp-md5
(public domain, after Joseph Myers)
// which hash should I use?
A hash is a fixed-length fingerprint of some input. The same input always produces the same digest; changing a single byte changes the output completely.
- SHA-256 / SHA-512: use these for anything that matters. Integrity verification, signatures, and as a building block for password hashing. Native to the browser via the Web Crypto API.
- MD5 / SHA-1: cryptographically broken. Attackers can manufacture collisions, so never use them against a malicious actor. Still fine for non-adversarial checksums: catching accidental file corruption, deduplication, or matching a vendor-published MD5 on a download.
Privacy: the SHA digests are computed with
crypto.subtle.digest(), the browser's built-in crypto. MD5 runs in a
small embedded JavaScript routine. Your text and files never leave the page.
Related: need to encode binary safely as text instead? The Base64 Encoder & Decoder handles that.
// a free, browser-only tool by Tiempo Software, built in Omaha, Nebraska. Runs entirely in your browser; nothing you enter is uploaded. see all tools.