Hash Generator
Hash UTF-8 text with SHA-1, SHA-256 & SHA-512
Encode the text in this box as UTF-8 and calculate SHA-1, SHA-256, and SHA-512. Empty strings can be hashed. Entering a file name hashes that name as text; it does not read the file.
Both options are off by default. When enabled, line endings are normalized before trimming. Browser textareas also normalize pasted CRLF/CR to LF, so this is a text-hashing tool rather than a way to preserve original file bytes. Editing input or options immediately clears previous results.
Text is processed in this pageβs memory and is not saved to browser storage. Input text and digests are not sent to analytics. Copying writes the selected results to your system clipboard.
Hash results
Click Generate hashes to display all three results. An empty string is also valid input.
Algorithms and text boundaries
This provides hexadecimal SHA-1, SHA-256, and SHA-512 text digests, with no file upload, SHA-384, or encryption/decryption. Hashes are one-way digests. SHA-1 is unsuitable when collision resistance matters; prefer SHA-256 or SHA-512 for new integrity uses.
A plain hash does not authenticate the sender and is not suitable for password storage. Use keyed HMAC for message authentication and a dedicated password-hashing algorithm such as bcrypt for passwords. Unicode representation, surrounding whitespace, and line endings can change a digest; this tool does not normalize Unicode.
Related tools
The full guide also includes pitfalls, worked examples, snippets, FAQs, and related tools for checking results or troubleshooting.
About this tool
Calculate SHA-1, SHA-256, and SHA-512 digests of text using the browser Web Crypto API. Text is encoded as UTF-8 after the selected whitespace options. This page does not read files or encrypt text. The tool does not upload input or save input drafts; website analytics are described separately in the privacy policy.
Production Snippets
Known digests of abc (UTF-8, 3 bytes, no newline)
text
SHA-1: a9993e364706816aba3e25717850c26c9cd0d89d
SHA-256: ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad
SHA-512: ddaf35a193617abacc417349ae20413112e6fa4e89a97ea20a9eeee64b55d39a2192992a274fc1a836ba3c23a3feebbd454d4423643ce80e2a9ac94fa54ca49fCompare & Decision
Text checksum, authenticated message, or stored password?
Plain SHA digest
Compare the same known text bytes with a trusted reference digest.
Purpose-specific security scheme
Use protocol-defined HMAC or signatures for authentication, and a dedicated server-side password hash for stored passwords.
Note: A matching checksum is useful for detecting changes, but an attacker who can replace both the text and its reference digest can make them match.
Failure Clinic (Common Pitfalls)
A final newline changes the result
Cause: abc is 3 UTF-8 bytes; abc followed by LF is 4 bytes. The latter has SHA-256 edeaaff3f1774ad2888673770c6d64097e391bc362d7d6fb34982ddf0efd18cb.
Fix: Check whether the reference input includes a final newline. Do not trim it away unless the protocol says to do so.
Pasted text is not a copy of the original file bytes
Cause: The textarea normalizes line breaks to LF. Pasting can also lose an original encoding or other byte-level details before hashing begins.
Fix: Use this page for the text present in the input field. For an archive or an exact file checksum, hash the file bytes with a separate file tool.
Visually identical Unicode text can have different digests
Cause: Γ© can be the single code point U+00E9 or e followed by U+0301. In UTF-8 those are 2 and 3 bytes. This tool does not apply Unicode normalization.
Fix: Compare the actual input and encoding. Apply NFC or another normalization only when both systems explicitly require it.
Scenario Recipes
Verify the tool with abc
Goal: Check a known input before comparing an application digest.
- Turn off trimming and newline normalization. Enter exactly abc, with no space or final newline.
- Generate the digests and confirm the input is 3 UTF-8 bytes.
- Compare all three results with the known values below, using the same algorithm.
Result: The SHA-256 result starts with ba7816bf and matches the full 64-character value below.
Check whether whitespace is part of the message
Goal: See how an explicit trim rule changes the bytes being hashed.
- Enter one space, abc, then one space. With trimming off, the input is 5 UTF-8 bytes.
- Generate SHA-256: 3eaf1941003943dfaa935adecffcaaa217e290def6fb0181141ced6c9daabaad.
- Turn trimming on and generate again. The input becomes 3 bytes and the result matches the abc vector.
Result: Trimming changes the message. Enable it only when the other system applies the same rule.
Compare Unicode text by UTF-8 bytes
Goal: Check encoding rather than the number of visible characters.
- Enter exactly δ½ ε₯½ π with one space and no final newline. Keep trimming off.
- Generate the digest and check the UTF-8 byte count is 11.
- Compare SHA-256 with 11d38af3bdabe6b2cbeddca50ba2837db42ab16679896ed9cc0dfce30cfc1fa7.
Result: A matching UTF-8 input and algorithm produce the same digest in another implementation.
Suggested Workflow
Frequently Asked Questions
Which algorithms and output formats are supported?
The page produces lowercase hexadecimal SHA-1, SHA-256, and SHA-512 digests: 40, 64, and 128 hex characters respectively. SHA-1 is retained for legacy comparisons; prefer SHA-256 or SHA-512 for new integrity checks. No MD5 or SHA-384 result is generated here.
Can I hash a file by pasting its name or contents?
No. A filename is hashed as literal text, not as file contents. This page has no file reader. Browser textareas normalize line breaks to LF, and copied text does not preserve arbitrary file bytes or its original encoding. Use a file-byte hashing tool for a downloaded file or archive.
Can I calculate a hash of empty text?
Yes. Click Generate hashes with the input empty to calculate the standard digest of zero bytes. With trimming enabled, input made only of leading or trailing whitespace can also become empty.
Is a SHA digest suitable for passwords or API authentication?
A plain SHA digest has no secret key and does not authenticate a sender. Use HMAC or a digital signature according to the API protocol. For password storage, use a dedicated password hashing implementation on the server, such as Argon2id or bcrypt, with its required salt and cost settings.
Can someone recover the input from a digest?
A digest has no decryption operation. However, someone can guess likely inputs and compare their digests, so hashing a short password, email address, or other predictable value does not make it confidential.
Keep browsing