Hash and HMAC generator

Compute SHA-256, SHA-384, SHA-512, SHA-1 or MD5 of text or a file, or an HMAC with your own key, as hex or Base64. A self-test runs the published NIST and RFC vectors in your browser, and the page explains why digests that look wrong usually are not. Your text, file and key never leave the page.

Algorithms

    Self-test: run the published test vectors in this browser

    Runs every NIST, RFC 4231, RFC 2202 and RFC 1321 vector listed further down this page through the same code as the tool above, and compares the result with the published value.

      Runs in your browser with the Web Crypto API (MD5 uses code on this page, because Web Crypto has no MD5). Nothing is uploaded or stored. The share link includes your text for plain hashing only; it never includes HMAC keys or file contents.

      How to use

      1. Choose Text or File. For text, the characters are first turned into bytes (UTF-8 by default) because hash functions work on bytes, not characters. A file is hashed exactly as stored.
      2. Choose Hash for a plain digest, or HMAC to add a secret key. State how the key is written (plain text, hex, or Base64) so the right bytes are used.
      3. Tick one or more algorithms. SHA-256 is the sensible default; SHA-1 and MD5 are offered for checking old checksums and are marked as such.
      4. Pick the output: lowercase or uppercase hex, Base64 (with padding) or Base64URL (without). They are the same bytes written differently.
      5. To check a published checksum, paste it into Compare with a known value. The comparison ignores case and spaces and is done on the hex form.

      Worked examples

      These are the values the tool is tested against. The hash values come from the example values published by NIST and from the RFC 1321 test suite; the HMAC values come from RFC 4231 and RFC 2202. The Self-test button above runs every row below through the code on this page. Digests are shown as lowercase hex.

      Hash test vectors

      CaseInputExpected digestSource
      SHA-1 "abc""abc"a9993e364706816aba3e25717850c26c9cd0d89dNIST example values (csrc.nist.gov SHA_All.pdf)
      SHA-1, 448-bit message"abcdbcdecdefdefgefghfghighijhijkijkljklmklmnlmnomnopnopq"84983e441c3bd26ebaae4aa1f95129e5e54670f1NIST example values (csrc.nist.gov SHA_All.pdf)
      SHA-256 "abc""abc"ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015adNIST example values (csrc.nist.gov SHA_All.pdf)
      SHA-256, 448-bit message"abcdbcdecdefdefgefghfghighijhijkijkljklmklmnlmnomnopnopq"248d6a61d20638b8e5c026930c3e6039a33ce45964ff2167f6ecedd419db06c1NIST example values (csrc.nist.gov SHA_All.pdf)
      SHA-384 "abc""abc"cb00753f45a35e8bb5a03d699ac65007272c32ab0eded1631a8b605a43ff5bed8086072ba1e7cc2358baeca134c825a7NIST example values (csrc.nist.gov SHA_All.pdf)
      SHA-384, 896-bit message"abcdefghbcdefghicdefghijdefghijkefghijk...09330c33f71147e83d192fc782cd1b4753111b173b3b05d22fa08086e3b0f712fcc7c71a557e2db966c3e9fa91746039NIST example values (csrc.nist.gov SHA_All.pdf)
      SHA-512 "abc""abc"ddaf35a193617abacc417349ae20413112e6fa4e89a97ea20a9eeee64b55d39a2192992a274fc1a836ba3c23a3feebbd454d4423643ce80e2a9ac94fa54ca49fNIST example values (csrc.nist.gov SHA_All.pdf)
      SHA-512, 896-bit message"abcdefghbcdefghicdefghijdefghijkefghijk...8e959b75dae313da8cf4f72814fc143f8f7779c6eb9f7fa17299aeadb6889018501d289e4900f7e4331b99dec4b5433ac7d329eeb6dd26545e96e55b874be909NIST example values (csrc.nist.gov SHA_All.pdf)
      MD5 """"d41d8cd98f00b204e9800998ecf8427eRFC 1321 section A.5
      MD5 "a""a"0cc175b9c0f1b6a831c399e269772661RFC 1321 section A.5
      MD5 "abc""abc"900150983cd24fb0d6963f7d28e17f72RFC 1321 section A.5
      MD5 "message digest""message digest"f96b697d7cb7938d525a2f31aaf161d0RFC 1321 section A.5
      MD5 "abcdefghij...""abcdefghijklmnopqrstuvwxyz"c3fcd3d76192e4007dfb496cca67e13bRFC 1321 section A.5
      MD5 "ABCDEFGHIJ...""ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789"d174ab98d277d9f5a5611c2c9f419d9fRFC 1321 section A.5
      MD5 "1234567890...""123456789012345678901234567890123456789...57edf4a22be3c955ac49da2e2107b67aRFC 1321 section A.5

      Long messages are cut off in the table; the tests use the full text. The NIST sets list the messages "abc", the 448-bit message "abcdbcdecdefdefgefghfghighijhijkijkljklmklmnlmnomnopnopq" (SHA-1 and SHA-256) and the 896-bit message that begins "abcdefghbcdefghicdefghijdefghijk..." (SHA-384 and SHA-512).

      HMAC test vectors

      CaseKeyDataExpected MAC
      RFC 4231 test case 1, HMAC-SHA-2560x0b repeated 20 times"Hi There"b0344c61d8db38535ca8afceaf0bf12b881dc200c9833da726e9376c2e32cff7
      RFC 4231 test case 1, HMAC-SHA-3840x0b repeated 20 times"Hi There"afd03944d84895626b0825f4ab46907f15f9dadbe4101ec682aa034c7cebc59cfaea9ea9076ede7f4af152e8b2fa9cb6
      RFC 4231 test case 1, HMAC-SHA-5120x0b repeated 20 times"Hi There"87aa7cdea5ef619d4ff0b4241a1d6cb02379f4e2ce4ec2787ad0b30545e17cdedaa833b7d6b8a702038b274eaea3f4e4be9d914eeb61f1702e696c203a126854
      RFC 4231 test case 2, HMAC-SHA-256"Jefe""what do ya want for nothing?"5bdcc146bf60754e6a042426089575c75a003f089d2739839dec58b964ec3843
      RFC 4231 test case 2, HMAC-SHA-384"Jefe""what do ya want for nothing?"af45d2e376484031617f78d2b58a6b1b9c7ef464f5a01b47e42ec3736322445e8e2240ca5e69e2c78b3239ecfab21649
      RFC 4231 test case 2, HMAC-SHA-512"Jefe""what do ya want for nothing?"164b7a7bfcf819e2e395fbe73b56e0a387bd64222e831fd610270cd7ea2505549758bf75c05a994a6d034f65f8f0e6fdcaeab1a34d4a6b4b636e070a38bce737
      RFC 4231 test case 3, HMAC-SHA-2560xaa repeated 20 times0xdd repeated 50 times773ea91e36800e46854db8ebd09181a72959098b3ef8c122d9635514ced565fe
      RFC 4231 test case 3, HMAC-SHA-3840xaa repeated 20 times0xdd repeated 50 times88062608d3e6ad8a0aa2ace014c8a86f0aa635d947ac9febe83ef4e55966144b2a5ab39dc13814b94e3ab6e101a34f27
      RFC 4231 test case 3, HMAC-SHA-5120xaa repeated 20 times0xdd repeated 50 timesfa73b0089d56a284efb0f0756c890be9b1b5dbdd8ee81a3655f83e33b2279d39bf3e848279a722c806b485a47e67c807b946a337bee8942674278859e13292fb
      RFC 4231 test case 4, HMAC-SHA-2560x01 to 0x19 (25 bytes)0xcd repeated 50 times82558a389a443c0ea4cc819899f2083a85f0faa3e578f8077a2e3ff46729665b
      RFC 4231 test case 4, HMAC-SHA-3840x01 to 0x19 (25 bytes)0xcd repeated 50 times3e8a69b7783c25851933ab6290af6ca77a9981480850009cc5577c6e1f573b4e6801dd23c4a7d679ccf8a386c674cffb
      RFC 4231 test case 4, HMAC-SHA-5120x01 to 0x19 (25 bytes)0xcd repeated 50 timesb0ba465637458c6990e5a8c5f61d4af7e576d97ff94b872de76f8050361ee3dba91ca5c11aa25eb4d679275cc5788063a5f19741120c4f2de2adebeb10a298dd
      RFC 4231 test case 6, HMAC-SHA-2560xaa repeated 131 times"Test Using Larger Than Block-Size Key - Hash Key First"60e431591ee0b67f0d8a26aacbf5b77f8e0bc6213728c5140546040f0ee37f54
      RFC 4231 test case 6, HMAC-SHA-3840xaa repeated 131 times"Test Using Larger Than Block-Size Key - Hash Key First"4ece084485813e9088d2c63a041bc5b44f9ef1012a2b588f3cd11f05033ac4c60c2ef6ab4030fe8296248df163f44952
      RFC 4231 test case 6, HMAC-SHA-5120xaa repeated 131 times"Test Using Larger Than Block-Size Key - Hash Key First"80b24263c7c1a3ebb71493c1dd7be8b49b46d1f41b4aeec1121b013783f8f3526b56d037e05f2598bd0fd2215d6a1e5295e64f73f63f0aec8b915a985d786598
      RFC 4231 test case 7, HMAC-SHA-2560xaa repeated 131 times"This is a test using a larger than bloc...9b09ffa71b942fcb27635fbcd5b0e944bfdc63644f0713938a7f51535c3a35e2
      RFC 4231 test case 7, HMAC-SHA-3840xaa repeated 131 times"This is a test using a larger than bloc...6617178e941f020d351e2f254e8fd32c602420feb0b8fb9adccebb82461e99c5a678cc31e799176d3860e6110c46523e
      RFC 4231 test case 7, HMAC-SHA-5120xaa repeated 131 times"This is a test using a larger than bloc...e37b6a775dc87dbaa4dfa9f96e5e3ffddebd71f8867289865df5a32d20cdc944b6022cac3c4982b10d5eeb55c3e4de15134676fb6de0446065c97440fa8c6a58
      RFC 4231 test case 5, HMAC-SHA-256 (truncated to 128 bits)0x0c repeated 20 times"Test With Truncation"a3b6167473100ee06e0c796c2955552b (first 16 bytes only)
      RFC 2202 test case 1, HMAC-SHA-10x0b repeated 20 times"Hi There"b617318655057264e28bc0b6fb378c8ef146be00
      RFC 2202 test case 2, HMAC-SHA-1"Jefe""what do ya want for nothing?"effcdf6ae5eb2fa2d27416d5f184df9c259a7c79
      RFC 2202 test case 3, HMAC-SHA-10xaa repeated 20 times0xdd repeated 50 times125d7342b9ac11cd91a39af48aa17b4f63f175d3
      RFC 2202 test case 1, HMAC-MD50x0b repeated 16 times"Hi There"9294727a3638bb1c13f48ef8158bfc9d
      RFC 2202 test case 2, HMAC-MD5"Jefe""what do ya want for nothing?"750c783e6ab0b503eaa86e310a5db738

      RFC 4231 test case 5 publishes only the first 128 bits of the MAC, so only those are compared. RFC 4231 also defines HMAC-SHA-224, which Web Crypto does not offer and this tool leaves out.

      What goes wrong

      Real inputs where a hash "looks wrong". Every digest below is SHA-256 in lowercase hex, computed by the tool and cross-checked with Python's hashlib and hmac.

      A trailing newline changes everything

      abc gives ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad (the NIST value).

      abc followed by a line feed gives edeaaff3f1774ad2888673770c6d64097e391bc362d7d6fb34982ddf0efd18cb. With a carriage return and line feed it gives 552bab6864c7a7b69a502ed1854b9245c0e1a30f008aaa0b281da62585fdb025. In a shell, echo abc | sha256sum hashes "abc" plus a line feed, not "abc"; printf abc or echo -n abc avoids it. The tool warns when your text contains a line break.

      UTF-8 versus Latin-1 for the same character

      The text é is the two bytes C3 A9 in UTF-8 and the single byte E9 in Latin-1. SHA-256 of the UTF-8 bytes is 4a99557e4033c3539de2eb65472017cad5f9557f7a0625a09f1c3f6e2ba69c4c; of the Latin-1 byte it is de2e331d891ae267a7009cb45b4e8830f170e0c937288ea2731a1941c7a53b0d. Choose the encoding the other side used. The Latin-1 option rejects characters above U+00FF (such as the euro sign) instead of altering them.

      A hex key typed as text

      HMAC-SHA-256 of what do ya want for nothing?: with the key Jefe (or its hex form 4a656665 declared as Hex) the result is 5bdcc146bf60754e6a042426089575c75a003f089d2739839dec58b964ec3843, the RFC 4231 value. With 4a656665 declared as Plain text the key is eight ASCII characters and the result is 0fca6b808cacdfe99c05ab656aa00d610cfd6c468e6ab7aca93e240319f65955.

      An empty HMAC key

      For the same message and an empty key RFC 2104 defines the result 76d9e7194e7dbc3aa00bbe8ffb9f6fcb5a932170f971f948bb2ab61607d2b9d6. A direct crypto.subtle.importKey call refuses a zero-length HMAC key with a DataError (Web Crypto, HMAC import steps; also observed in Node 20.19.2). The tool computes it by hand and shows a note that such a MAC proves nothing.

      Uppercase hex is not a different digest

      The same SHA-256 of abc in uppercase hex is BA7816BF8F01CFEA414140DE5DAE2223B00361A396177A9CB410FF61F20015AD, in Base64 ungWv48Bz+pBQUDeXa4iI7ADYaOWF3qctBD/YfIAFa0= and in Base64URL without padding ungWv48Bz-pBQUDeXa4iI7ADYaOWF3qctBD_YfIAFa0. Compare after converting to the same form; the compare box does this for hex.

      Limits & gotchas

      • No streaming; 100 MB file limit. Web Crypto's digest() takes the whole input at once, so the file is read fully into memory. Files larger than 100 MB are refused with a message. Command-line tools such as sha256sum handle huge files better.
      • MD5 is our own code. Web Crypto has no MD5 (its digest algorithms are SHA-1, SHA-256, SHA-384 and SHA-512), so MD5 is implemented from RFC 1321 on this site, passes the RFC 1321 test suite and was compared with Node's built-in MD5 for lengths 0 to 300 bytes and a 1 MB input. It is labelled not secure.
      • Not a password hasher. SHA-2 is fast by design, which is wrong for passwords. Use a purpose-built password hash (for example Argon2, scrypt or bcrypt) in your own code.
      • Not covered: SHA-3, SHA-224, SHA-512/256, BLAKE2/3, CRC32 and other checksums, HMAC-SHA-224. They are on the v1.1 list, not omitted by accident.
      • Keys are not stored. The HMAC key field is a password-type input, is never written to local storage and is never put in a share link; HMAC mode creates no share link at all. Still, do not type a production secret into any web page you cannot audit.
      • Share link. In plain hash mode the link carries your text in the part after #, which browsers do not send to servers, limited to about 3,000 characters. File contents are never included.
      • HMAC key length. RFC 2104 recommends a key at least as long as the hash output; the tool does not enforce it. RFC 2104 hashes keys longer than the block size (64 bytes for MD5, SHA-1 and SHA-256, 128 bytes for SHA-384 and SHA-512) before use; RFC 4231 test cases 6 and 7 cover that.

      FAQ

      Why does my SHA-256 not match the one on the download page?

      Almost always the bytes differ, not the algorithm. The usual causes are a trailing newline (SHA-256 of "abc" is ba7816bf...15ad, of "abc" plus a line feed is edeaaff3...18cb), Windows line endings ("abc" plus CR LF gives 552bab68...b025), text read as Latin-1 instead of UTF-8, or comparing the digest of a different file. Hash the file itself, not text copied from it, and compare the hex ignoring case: uppercase and lowercase hex are the same value.

      Is it safe to use MD5 or SHA-1?

      Not where an attacker can choose or alter the input. RFC 6151 says MD5 is no longer acceptable where collision resistance is required, such as digital signatures, while an MD5 checksum used only to detect accidental errors is still acceptable. NIST announced that SHA-1 should be phased out by 31 December 2030 in favor of SHA-2 and SHA-3. For new work use SHA-256 or stronger. Neither is suitable for storing passwords; that needs a slow, salted password hash, which this tool does not offer.

      What is the difference between a hash and an HMAC?

      A hash has no key: anyone can compute it, so it proves nothing about who produced the data. An HMAC (RFC 2104) mixes a secret key into the hash so only someone with the key can produce or check the value. Do not build your own "hash(secret + message)": HMAC exists because that construction is weak for the SHA-1 and SHA-2 families. Compare MACs with a constant-time comparison in your own code, not with ==.

      Why does HMAC with an empty key fail in some libraries?

      The Web Crypto specification says importing an HMAC key whose data has zero length must throw a DataError, so crypto.subtle.importKey cannot sign with an empty key. RFC 2104 itself allows keys of any length and pads a short key with zeros, so an empty key has a defined result. This tool computes that case by following RFC 2104 step by step and tells you the key is empty, because an HMAC with no secret authenticates nothing.

      Why is my HMAC different from the one in my code?

      Check how the key is interpreted. The text "4a656665" as a UTF-8 key is eight characters; the same digits as a hex key are the four bytes of "Jefe", and they produce different MACs (for the RFC 4231 case 2 message, 0fca6b80... versus 5bdcc146...). Also check that both sides use the same hash, the same text encoding for the message and the same output encoding (hex or Base64).

      Sources

      Every document above was opened and read on 2026-10-02. Documentation changes; if a page here disagrees with the current docs, trust the docs and tell us.