The Magic Codex

Hash Generator

Paste text and watch its SHA-256, SHA-384, SHA-512 and MD5 digests appear as you type. Every hash is computed on your device — nothing leaves the browser.

Everything stays in your browser. Nothing is uploaded or stored.

SHA-256

…

SHA-384

…

SHA-512

…

MD5 (legacy — checksums only)

…

How to hash text

  1. Paste your text into the box above. All four digests update live as you type.
  2. Copy the digest you need. Each algorithm has its own copy button; SHA-256 is the default choice for most jobs.
  3. Compare to verify. Hashing the same file on two machines should give identical digests — if they differ, the file changed.

Which algorithm should I use?

Use SHA-256 unless you have a reason not to: it is the industry default for file checksums, Git commits, and API signatures. SHA-384/512 add margin for long-lived secrets. Use MD5 only when an older system demands it — checksums, legacy databases, Gravatar-style identifiers. Never hash passwords with any of these directly; password storage needs a slow function like bcrypt, scrypt, or Argon2.

Byte length vs. character length

The panel shows the input's UTF-8 byte length, which is what hashing actually digests. Plain English text is one byte per character, but accented letters take two and emoji take four — so "café" is 5 bytes, not 4 characters. This matters when a hash doesn't match: the usual culprit is an invisible encoding difference (a trailing newline, Windows vs. Unix line endings).

What is a hash?
A hash is a fixed-length fingerprint of some input. Change even one character and the fingerprint changes completely. Hashes are one-way: you cannot reconstruct the input from the digest.
What is the difference between SHA-256, SHA-384 and SHA-512?
They are three strengths of the SHA-2 family, producing 256, 384 and 512 bits (64, 96 and 128 hex characters). All three are considered secure; SHA-512 is stronger on paper but slower on 32-bit devices. For most checksums and identifiers, SHA-256 is the standard choice.
Is MD5 safe to use?
Not for security. MD5 collisions can be manufactured in seconds, so never use it for passwords or signatures. It is still fine for non-security jobs like checksums and legacy file verification, which is why this tool includes it.
Why does the same text always give the same hash?
Hash functions are deterministic: identical input always produces identical output. That is what makes them useful for verifying downloads — if your file's hash matches the published one, the file is intact.
Is my text sent anywhere?
No. Hashing happens in your browser with Web Crypto (SHA) and a built-in MD5 routine. Nothing is uploaded, stored, or tracked.

More from the codex