katlab tools/hash support on Ko-fi

Hash · Generator

Compute MD5, SHA-1, SHA-256, SHA-384 and SHA-512 of text or a file, HMAC signatures, bcrypt password hashes, and identify unknown hashes — all in your browser.

Hashes are computed locally. Nothing is uploaded to a server.
MD5—
SHA-1—
SHA-256—
SHA-384—
SHA-512—

How to generate a hash (free)

  1. Type or paste text — hashes update as you type.
  2. Or click Hash a file… to compute a checksum of any file.
  3. Click Copy next to the algorithm you need.
  4. Switch to HMAC, bcrypt or Identify for keyed hashes, password hashes or naming an unknown hash.

What is a hash?

A hash function turns any input into a fixed-length string of hex characters called a digest. The same input always produces the same digest, but you can't reverse it back to the original. Hashes are used to verify file integrity, store passwords (with salting), deduplicate data and build digital signatures.

Which algorithm should I use?

SHA-256 is the safe default for integrity and general use. MD5 and SHA-1 are faster and still widely published for download checksums, but they're cryptographically broken — don't rely on them for security. SHA-384 and SHA-512 produce longer digests for higher-assurance use.

Verifying a download

Many projects publish an MD5 or SHA-256 checksum next to their downloads. Select the downloaded file here and compare the generated digest to the published one — if they match exactly, the file arrived intact and untampered.

HMAC: hashing with a secret key

A plain hash proves that data hasn't changed, but anyone can recompute it. HMAC (hash-based message authentication code) mixes a secret key into the hash, so only someone who holds the key can produce a matching value. That is how most webhook providers sign their requests: they send an HMAC-SHA256 of the request body in a header, and your server recomputes it with the shared secret and compares.

In HMAC mode, enter the key and choose how it is encoded. Use UTF-8 for a key typed as text, hex for keys shown as hex digits, and base64 for keys delivered in base64 — a common source of mismatches when a secret is base64 but gets used as text. Pick SHA-1, SHA-256, SHA-384 or SHA-512, then type the message or choose a file. The signature is shown both as hex and base64, since providers use either. The key and message stay in your browser; the calculation uses the built-in WebCrypto API.

bcrypt vs fast hashes for passwords

MD5, SHA-1 and SHA-256 are built to be fast, which is exactly wrong for passwords: if a database leaks, an attacker with a GPU can test billions of guesses per second against a fast hash. bcrypt is a deliberately slow password hash. Every hash embeds a random salt, so identical passwords produce different hashes, and a cost factor sets how much work each check takes — each step up doubles it.

A bcrypt hash looks like $2b$10$ followed by 53 characters: the version, the cost, a 22-character salt and the 31-character hash. Cost 10–12 is a typical server setting; this tool lets you go from 4 to 15, but it runs in JavaScript, so costs above 12 can take several seconds here. One limit to know: bcrypt only uses the first 72 bytes of a password and ignores the rest, and the tool warns when your input is longer. For new systems, Argon2id is the current recommendation, but bcrypt remains widely supported and safe at a sensible cost.

Identifying an unknown hash

Paste a hash in Identify mode to see which algorithms could have produced it. Prefixed formats such as $2y$ (bcrypt), $apr1$, $6$ or $argon2id$ name their scheme and parameters. Bare hex digests only reveal their length, so a 64-character value is listed as SHA-256, SHA3-256, BLAKE2s and other possibilities rather than a single answer.

Is my data private?

Yes. Text hashes use a bundled MD5 implementation and the browser's built-in WebCrypto for the SHA family and HMAC; bcrypt uses the bundled bcrypt.js library. Files are read locally and hashed in your tab. Nothing is uploaded — you can verify in the network tab, and it works offline once loaded.