Hash and HMAC generator
Compute SHA-256, SHA-384, SHA-512, SHA-1 or MD5 of text or a file, or an HMAC with your own key, as hex or Base64. A self-test runs the published NIST and RFC vectors in your browser, and the page explains why digests that look wrong usually are not. Your text, file and key never leave the page.
The file is read by your browser and never uploaded.
The key stays in this page. It is not stored and not put in share links. Do not type a production secret.
Self-test: run the published test vectors in this browser
Runs every NIST, RFC 4231, RFC 2202 and RFC 1321 vector listed further down this page through the same code as the tool above, and compares the result with the published value.
Runs in your browser with the Web Crypto API (MD5 uses code on this page, because Web Crypto has no MD5). Nothing is uploaded or stored. The share link includes your text for plain hashing only; it never includes HMAC keys or file contents.
How to use
- Choose Text or File. For text, the characters are first turned into bytes (UTF-8 by default) because hash functions work on bytes, not characters. A file is hashed exactly as stored.
- Choose Hash for a plain digest, or HMAC to add a secret key. State how the key is written (plain text, hex, or Base64) so the right bytes are used.
- Tick one or more algorithms. SHA-256 is the sensible default; SHA-1 and MD5 are offered for checking old checksums and are marked as such.
- Pick the output: lowercase or uppercase hex, Base64 (with padding) or Base64URL (without). They are the same bytes written differently.
- To check a published checksum, paste it into Compare with a known value. The comparison ignores case and spaces and is done on the hex form.
Worked examples
These are the values the tool is tested against. The hash values come from the example values published by NIST and from the RFC 1321 test suite; the HMAC values come from RFC 4231 and RFC 2202. The Self-test button above runs every row below through the code on this page. Digests are shown as lowercase hex.
Hash test vectors
| Case | Input | Expected digest | Source |
|---|---|---|---|
| SHA-1 "abc" | "abc" | a9993e364706816aba3e25717850c26c9cd0d89d | NIST example values (csrc.nist.gov SHA_All.pdf) |
| SHA-1, 448-bit message | "abcdbcdecdefdefgefghfghighijhijkijkljklmklmnlmnomnopnopq" | 84983e441c3bd26ebaae4aa1f95129e5e54670f1 | NIST example values (csrc.nist.gov SHA_All.pdf) |
| SHA-256 "abc" | "abc" | ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad | NIST example values (csrc.nist.gov SHA_All.pdf) |
| SHA-256, 448-bit message | "abcdbcdecdefdefgefghfghighijhijkijkljklmklmnlmnomnopnopq" | 248d6a61d20638b8e5c026930c3e6039a33ce45964ff2167f6ecedd419db06c1 | NIST example values (csrc.nist.gov SHA_All.pdf) |
| SHA-384 "abc" | "abc" | cb00753f45a35e8bb5a03d699ac65007272c32ab0eded1631a8b605a43ff5bed8086072ba1e7cc2358baeca134c825a7 | NIST example values (csrc.nist.gov SHA_All.pdf) |
| SHA-384, 896-bit message | "abcdefghbcdefghicdefghijdefghijkefghijk... | 09330c33f71147e83d192fc782cd1b4753111b173b3b05d22fa08086e3b0f712fcc7c71a557e2db966c3e9fa91746039 | NIST example values (csrc.nist.gov SHA_All.pdf) |
| SHA-512 "abc" | "abc" | ddaf35a193617abacc417349ae20413112e6fa4e89a97ea20a9eeee64b55d39a2192992a274fc1a836ba3c23a3feebbd454d4423643ce80e2a9ac94fa54ca49f | NIST example values (csrc.nist.gov SHA_All.pdf) |
| SHA-512, 896-bit message | "abcdefghbcdefghicdefghijdefghijkefghijk... | 8e959b75dae313da8cf4f72814fc143f8f7779c6eb9f7fa17299aeadb6889018501d289e4900f7e4331b99dec4b5433ac7d329eeb6dd26545e96e55b874be909 | NIST example values (csrc.nist.gov SHA_All.pdf) |
| MD5 "" | "" | d41d8cd98f00b204e9800998ecf8427e | RFC 1321 section A.5 |
| MD5 "a" | "a" | 0cc175b9c0f1b6a831c399e269772661 | RFC 1321 section A.5 |
| MD5 "abc" | "abc" | 900150983cd24fb0d6963f7d28e17f72 | RFC 1321 section A.5 |
| MD5 "message digest" | "message digest" | f96b697d7cb7938d525a2f31aaf161d0 | RFC 1321 section A.5 |
| MD5 "abcdefghij..." | "abcdefghijklmnopqrstuvwxyz" | c3fcd3d76192e4007dfb496cca67e13b | RFC 1321 section A.5 |
| MD5 "ABCDEFGHIJ..." | "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789" | d174ab98d277d9f5a5611c2c9f419d9f | RFC 1321 section A.5 |
| MD5 "1234567890..." | "123456789012345678901234567890123456789... | 57edf4a22be3c955ac49da2e2107b67a | RFC 1321 section A.5 |
Long messages are cut off in the table; the tests use the full text. The NIST sets list the messages "abc", the 448-bit message "abcdbcdecdefdefgefghfghighijhijkijkljklmklmnlmnomnopnopq" (SHA-1 and SHA-256) and the 896-bit message that begins "abcdefghbcdefghicdefghijdefghijk..." (SHA-384 and SHA-512).
HMAC test vectors
| Case | Key | Data | Expected MAC |
|---|---|---|---|
| RFC 4231 test case 1, HMAC-SHA-256 | 0x0b repeated 20 times | "Hi There" | b0344c61d8db38535ca8afceaf0bf12b881dc200c9833da726e9376c2e32cff7 |
| RFC 4231 test case 1, HMAC-SHA-384 | 0x0b repeated 20 times | "Hi There" | afd03944d84895626b0825f4ab46907f15f9dadbe4101ec682aa034c7cebc59cfaea9ea9076ede7f4af152e8b2fa9cb6 |
| RFC 4231 test case 1, HMAC-SHA-512 | 0x0b repeated 20 times | "Hi There" | 87aa7cdea5ef619d4ff0b4241a1d6cb02379f4e2ce4ec2787ad0b30545e17cdedaa833b7d6b8a702038b274eaea3f4e4be9d914eeb61f1702e696c203a126854 |
| RFC 4231 test case 2, HMAC-SHA-256 | "Jefe" | "what do ya want for nothing?" | 5bdcc146bf60754e6a042426089575c75a003f089d2739839dec58b964ec3843 |
| RFC 4231 test case 2, HMAC-SHA-384 | "Jefe" | "what do ya want for nothing?" | af45d2e376484031617f78d2b58a6b1b9c7ef464f5a01b47e42ec3736322445e8e2240ca5e69e2c78b3239ecfab21649 |
| RFC 4231 test case 2, HMAC-SHA-512 | "Jefe" | "what do ya want for nothing?" | 164b7a7bfcf819e2e395fbe73b56e0a387bd64222e831fd610270cd7ea2505549758bf75c05a994a6d034f65f8f0e6fdcaeab1a34d4a6b4b636e070a38bce737 |
| RFC 4231 test case 3, HMAC-SHA-256 | 0xaa repeated 20 times | 0xdd repeated 50 times | 773ea91e36800e46854db8ebd09181a72959098b3ef8c122d9635514ced565fe |
| RFC 4231 test case 3, HMAC-SHA-384 | 0xaa repeated 20 times | 0xdd repeated 50 times | 88062608d3e6ad8a0aa2ace014c8a86f0aa635d947ac9febe83ef4e55966144b2a5ab39dc13814b94e3ab6e101a34f27 |
| RFC 4231 test case 3, HMAC-SHA-512 | 0xaa repeated 20 times | 0xdd repeated 50 times | fa73b0089d56a284efb0f0756c890be9b1b5dbdd8ee81a3655f83e33b2279d39bf3e848279a722c806b485a47e67c807b946a337bee8942674278859e13292fb |
| RFC 4231 test case 4, HMAC-SHA-256 | 0x01 to 0x19 (25 bytes) | 0xcd repeated 50 times | 82558a389a443c0ea4cc819899f2083a85f0faa3e578f8077a2e3ff46729665b |
| RFC 4231 test case 4, HMAC-SHA-384 | 0x01 to 0x19 (25 bytes) | 0xcd repeated 50 times | 3e8a69b7783c25851933ab6290af6ca77a9981480850009cc5577c6e1f573b4e6801dd23c4a7d679ccf8a386c674cffb |
| RFC 4231 test case 4, HMAC-SHA-512 | 0x01 to 0x19 (25 bytes) | 0xcd repeated 50 times | b0ba465637458c6990e5a8c5f61d4af7e576d97ff94b872de76f8050361ee3dba91ca5c11aa25eb4d679275cc5788063a5f19741120c4f2de2adebeb10a298dd |
| RFC 4231 test case 6, HMAC-SHA-256 | 0xaa repeated 131 times | "Test Using Larger Than Block-Size Key - Hash Key First" | 60e431591ee0b67f0d8a26aacbf5b77f8e0bc6213728c5140546040f0ee37f54 |
| RFC 4231 test case 6, HMAC-SHA-384 | 0xaa repeated 131 times | "Test Using Larger Than Block-Size Key - Hash Key First" | 4ece084485813e9088d2c63a041bc5b44f9ef1012a2b588f3cd11f05033ac4c60c2ef6ab4030fe8296248df163f44952 |
| RFC 4231 test case 6, HMAC-SHA-512 | 0xaa repeated 131 times | "Test Using Larger Than Block-Size Key - Hash Key First" | 80b24263c7c1a3ebb71493c1dd7be8b49b46d1f41b4aeec1121b013783f8f3526b56d037e05f2598bd0fd2215d6a1e5295e64f73f63f0aec8b915a985d786598 |
| RFC 4231 test case 7, HMAC-SHA-256 | 0xaa repeated 131 times | "This is a test using a larger than bloc... | 9b09ffa71b942fcb27635fbcd5b0e944bfdc63644f0713938a7f51535c3a35e2 |
| RFC 4231 test case 7, HMAC-SHA-384 | 0xaa repeated 131 times | "This is a test using a larger than bloc... | 6617178e941f020d351e2f254e8fd32c602420feb0b8fb9adccebb82461e99c5a678cc31e799176d3860e6110c46523e |
| RFC 4231 test case 7, HMAC-SHA-512 | 0xaa repeated 131 times | "This is a test using a larger than bloc... | e37b6a775dc87dbaa4dfa9f96e5e3ffddebd71f8867289865df5a32d20cdc944b6022cac3c4982b10d5eeb55c3e4de15134676fb6de0446065c97440fa8c6a58 |
| RFC 4231 test case 5, HMAC-SHA-256 (truncated to 128 bits) | 0x0c repeated 20 times | "Test With Truncation" | a3b6167473100ee06e0c796c2955552b (first 16 bytes only) |
| RFC 2202 test case 1, HMAC-SHA-1 | 0x0b repeated 20 times | "Hi There" | b617318655057264e28bc0b6fb378c8ef146be00 |
| RFC 2202 test case 2, HMAC-SHA-1 | "Jefe" | "what do ya want for nothing?" | effcdf6ae5eb2fa2d27416d5f184df9c259a7c79 |
| RFC 2202 test case 3, HMAC-SHA-1 | 0xaa repeated 20 times | 0xdd repeated 50 times | 125d7342b9ac11cd91a39af48aa17b4f63f175d3 |
| RFC 2202 test case 1, HMAC-MD5 | 0x0b repeated 16 times | "Hi There" | 9294727a3638bb1c13f48ef8158bfc9d |
| RFC 2202 test case 2, HMAC-MD5 | "Jefe" | "what do ya want for nothing?" | 750c783e6ab0b503eaa86e310a5db738 |
RFC 4231 test case 5 publishes only the first 128 bits of the MAC, so only those are compared. RFC 4231 also defines HMAC-SHA-224, which Web Crypto does not offer and this tool leaves out.
What goes wrong
Real inputs where a hash "looks wrong". Every digest below is SHA-256 in lowercase hex, computed by the tool and cross-checked with Python's hashlib and hmac.
A trailing newline changes everything
abc gives ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad (the NIST value).
abc followed by a line feed gives edeaaff3f1774ad2888673770c6d64097e391bc362d7d6fb34982ddf0efd18cb. With a carriage return and line feed it gives 552bab6864c7a7b69a502ed1854b9245c0e1a30f008aaa0b281da62585fdb025. In a shell, echo abc | sha256sum hashes "abc" plus a line feed, not "abc"; printf abc or echo -n abc avoids it. The tool warns when your text contains a line break.
UTF-8 versus Latin-1 for the same character
The text é is the two bytes C3 A9 in UTF-8 and the single byte E9 in Latin-1. SHA-256 of the UTF-8 bytes is 4a99557e4033c3539de2eb65472017cad5f9557f7a0625a09f1c3f6e2ba69c4c; of the Latin-1 byte it is de2e331d891ae267a7009cb45b4e8830f170e0c937288ea2731a1941c7a53b0d. Choose the encoding the other side used. The Latin-1 option rejects characters above U+00FF (such as the euro sign) instead of altering them.
A hex key typed as text
HMAC-SHA-256 of what do ya want for nothing?: with the key Jefe (or its hex form 4a656665 declared as Hex) the result is 5bdcc146bf60754e6a042426089575c75a003f089d2739839dec58b964ec3843, the RFC 4231 value. With 4a656665 declared as Plain text the key is eight ASCII characters and the result is 0fca6b808cacdfe99c05ab656aa00d610cfd6c468e6ab7aca93e240319f65955.
An empty HMAC key
For the same message and an empty key RFC 2104 defines the result 76d9e7194e7dbc3aa00bbe8ffb9f6fcb5a932170f971f948bb2ab61607d2b9d6. A direct crypto.subtle.importKey call refuses a zero-length HMAC key with a DataError (Web Crypto, HMAC import steps; also observed in Node 20.19.2). The tool computes it by hand and shows a note that such a MAC proves nothing.
Uppercase hex is not a different digest
The same SHA-256 of abc in uppercase hex is BA7816BF8F01CFEA414140DE5DAE2223B00361A396177A9CB410FF61F20015AD, in Base64 ungWv48Bz+pBQUDeXa4iI7ADYaOWF3qctBD/YfIAFa0= and in Base64URL without padding ungWv48Bz-pBQUDeXa4iI7ADYaOWF3qctBD_YfIAFa0. Compare after converting to the same form; the compare box does this for hex.
Limits & gotchas
- No streaming; 100 MB file limit. Web Crypto's
digest()takes the whole input at once, so the file is read fully into memory. Files larger than 100 MB are refused with a message. Command-line tools such assha256sumhandle huge files better. - MD5 is our own code. Web Crypto has no MD5 (its digest algorithms are SHA-1, SHA-256, SHA-384 and SHA-512), so MD5 is implemented from RFC 1321 on this site, passes the RFC 1321 test suite and was compared with Node's built-in MD5 for lengths 0 to 300 bytes and a 1 MB input. It is labelled not secure.
- Not a password hasher. SHA-2 is fast by design, which is wrong for passwords. Use a purpose-built password hash (for example Argon2, scrypt or bcrypt) in your own code.
- Not covered: SHA-3, SHA-224, SHA-512/256, BLAKE2/3, CRC32 and other checksums, HMAC-SHA-224. They are on the v1.1 list, not omitted by accident.
- Keys are not stored. The HMAC key field is a password-type input, is never written to local storage and is never put in a share link; HMAC mode creates no share link at all. Still, do not type a production secret into any web page you cannot audit.
- Share link. In plain hash mode the link carries your text in the part after
#, which browsers do not send to servers, limited to about 3,000 characters. File contents are never included. - HMAC key length. RFC 2104 recommends a key at least as long as the hash output; the tool does not enforce it. RFC 2104 hashes keys longer than the block size (64 bytes for MD5, SHA-1 and SHA-256, 128 bytes for SHA-384 and SHA-512) before use; RFC 4231 test cases 6 and 7 cover that.
FAQ
Why does my SHA-256 not match the one on the download page?
Almost always the bytes differ, not the algorithm. The usual causes are a trailing newline (SHA-256 of "abc" is ba7816bf...15ad, of "abc" plus a line feed is edeaaff3...18cb), Windows line endings ("abc" plus CR LF gives 552bab68...b025), text read as Latin-1 instead of UTF-8, or comparing the digest of a different file. Hash the file itself, not text copied from it, and compare the hex ignoring case: uppercase and lowercase hex are the same value.
Is it safe to use MD5 or SHA-1?
Not where an attacker can choose or alter the input. RFC 6151 says MD5 is no longer acceptable where collision resistance is required, such as digital signatures, while an MD5 checksum used only to detect accidental errors is still acceptable. NIST announced that SHA-1 should be phased out by 31 December 2030 in favor of SHA-2 and SHA-3. For new work use SHA-256 or stronger. Neither is suitable for storing passwords; that needs a slow, salted password hash, which this tool does not offer.
What is the difference between a hash and an HMAC?
A hash has no key: anyone can compute it, so it proves nothing about who produced the data. An HMAC (RFC 2104) mixes a secret key into the hash so only someone with the key can produce or check the value. Do not build your own "hash(secret + message)": HMAC exists because that construction is weak for the SHA-1 and SHA-2 families. Compare MACs with a constant-time comparison in your own code, not with ==.
Why does HMAC with an empty key fail in some libraries?
The Web Crypto specification says importing an HMAC key whose data has zero length must throw a DataError, so crypto.subtle.importKey cannot sign with an empty key. RFC 2104 itself allows keys of any length and pads a short key with zeros, so an empty key has a defined result. This tool computes that case by following RFC 2104 step by step and tells you the key is empty, because an HMAC with no secret authenticates nothing.
Why is my HMAC different from the one in my code?
Check how the key is interpreted. The text "4a656665" as a UTF-8 key is eight characters; the same digits as a hex key are the four bytes of "Jefe", and they produce different MACs (for the RFC 4231 case 2 message, 0fca6b80... versus 5bdcc146...). Also check that both sides use the same hash, the same text encoding for the message and the same output encoding (hex or Base64).
Sources
- W3C: Web Cryptography API (SubtleCrypto: digest, importKey, sign, verify) Used for: digest() supports SHA-1, SHA-256, SHA-384, SHA-512; HMAC sign/verify with importKey. MD5 is not in the list.
- NIST: FIPS 180-4: Secure Hash Standard Used for: Definition of SHA-1, SHA-256, SHA-384, SHA-512.
- NIST: Cryptographic Standards and Guidelines: example values for SHA-1, SHA-256, SHA-384, SHA-512 ("abc" and the 448-bit message) Used for: Digests of "abc", of the 448-bit message "abcdbcdecdefdefgefghfghighijhijkijkljklmklmnlmnomnopnopq" (SHA-1, SHA-256) and of the 896-bit message (SHA-384, SHA-512). The empty-string digests are not from this document.
- NIST: NIST Retires SHA-1 Cryptographic Algorithm (news release) Used for: NIST (15 December 2022) recommends migrating from SHA-1 to SHA-2 or SHA-3 and says SHA-1 should be phased out by 31 December 2030.
- IETF: RFC 4231: Identifiers and Test Vectors for HMAC-SHA-224, SHA-256, SHA-384, and SHA-512 Used for: HMAC test cases 1 to 7 with keys, data and expected MACs.
- IETF: RFC 2202: Test Cases for HMAC-MD5 and HMAC-SHA-1 Used for: HMAC-SHA-1 test cases 1 to 3 and HMAC-MD5 test cases 1 and 2.
- IETF: RFC 2104: HMAC: Keyed-Hashing for Message Authentication Used for: The HMAC construction; keys of any length (longer than the block size are hashed first, shorter are zero-padded); recommended minimum key length equal to the hash output length.
- IETF: RFC 1321: The MD5 Message-Digest Algorithm Used for: Algorithm and test suite (section A.5).
- IETF: RFC 6151: Updated Security Considerations for the MD5 Message-Digest and the HMAC-MD5 Algorithms Used for: MD5 is no longer acceptable where collision resistance is required, such as digital signatures; an MD5 checksum solely to protect against errors is still acceptable.
- IETF: RFC 4648: The Base16, Base32, and Base64 Data Encodings Used for: The two Base64 alphabets (tables 1 and 2), padding (3.2), rejecting non-alphabet characters (3.3), canonical encoding and zero pad bits (3.5), no line feeds unless a referring spec says so (3.1), the "base64url" name (5), the test vectors (10), the "=" percent-encoding remark (5).
Every document above was opened and read on 2026-10-02. Documentation changes; if a page here disagrees with the current docs, trust the docs and tell us.