A hash function takes any amount of data, whether that is a single word or a whole disk
image, and turns it into a short value of a fixed length, which is called a hash or a
digest. The same input always produces the same hash, but there is no way to work
backward from a hash to the input, and changing even one bit of the input changes the
hash completely. That combination is what makes a hash useful as a fingerprint. If two
files have the same SHA-256 hash, you can be confident that they are the same file
without comparing them byte by byte.
The SHA-256 of abc
ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad
The same text with a line break at the end
edeaaff3f1774ad2888673770c6d64097e391bc362d7d6fb34982ddf0efd18cb
Why a hash might not match
Because a hash covers every byte, two pieces of text that look identical on screen can
still hash differently. The most common reason is a line break at the end. Running
echo hello | sha256sum hashes six bytes, because echo adds a
line break after the word, while printf hello | sha256sum hashes only five.
Windows and Unix also write line breaks differently, as the two bytes CRLF on Windows and
the single byte LF almost everywhere else, and a byte order mark or a non-breaking space
can sneak in when text is copied from one program to another.
This page hashes text as UTF-8, and the status line under the box points out anything
like that it finds in your text. A text box in a browser can only hold LF line breaks, so
when your text has line breaks you can choose which kind they are hashed as, using the
buttons that appear underneath. If you paste the hash you were expecting and it does not
match, the page also tries the most common variations of your text, and if one of them
matches, it will tell you which one.
If you need the hash of a file exactly as it is on disk, drop the file onto the page
rather than pasting in its contents. That way the page reads the file's own bytes, and
nothing about line breaks or text encodings can get in the way.
Which hash to use
SHA-256 is the usual choice today, and it is what most download pages and package managers
publish. SHA-384 and SHA-512 belong to the same family and produce longer hashes. Each
of the hashes on this page has a different length, so when you paste a hash to check, the
page can tell from its length alone which one it is meant to be.
MD5 and SHA-1 are older, and they are broken, which means that people can now deliberately
create two different files with the same hash. They are still fine for catching a download
that was damaged by accident, and plenty of older download pages publish them, but they
should not be relied on to prove that nobody has tampered with a file. CRC-32 is not a
cryptographic hash at all. It is a checksum that zip files, gzip and PNG images use to
catch accidental damage, and it is easy to forge on purpose.
Where the hashes come from
Your browser has its own cryptography built in, written and maintained by the people who
make the browser, and this page uses it for SHA-1, SHA-256, SHA-384, SHA-512 and every
HMAC. The browser does not offer MD5 or CRC-32, so those two are calculated by code in
this page, which you can read in View Source like the rest of it. Neither of them is ever
used with your key.
HMAC
An HMAC is a hash that also depends on a secret key, so only someone who knows the key can
produce the right value. Webhook providers such as GitHub and Stripe use one to sign the
requests they send you. They compute an HMAC of the request body with a key that only you
and they know, and you check the request by computing the same HMAC yourself. If you type
a key into the HMAC key box, the SHA hashes on this page become HMACs with that key, and
the key stays in this tab like everything else. MD5 and CRC-32 have no HMAC here, and
their rows will say so.
Providers do not all write their keys the same way. GitHub and Stripe use the key exactly
as the text you are shown, which is how this page reads it unless you tell it otherwise.
Some providers give the key as hex or as base64 instead, and you can choose either of
those with the buttons that appear next to the key.
Hex and base64
A hash is a sequence of bytes, and the two usual ways to write it down are hex, which
uses two characters for each byte, and base64, which is about a third shorter. They are
the same bytes written in two different ways. Most checksum files use hex, while the
Subresource Integrity values in HTML, which look like sha384-oqVu..., use
base64. You can choose which one this page shows with the buttons above the list of
hashes, and you can paste either one into the box for checking.
Some other things worth knowing
You can paste a whole line from a checksum file, such as the output of
sha256sum or the BSD form that macOS prints, and the page will read the
hash out of it. If you paste a whole SHA256SUMS file, every line in it is
checked, and the status line will tell you which one matched.
The SHA-256 of nothing at all is e3b0c442...b855. If you are given that
hash for a file, whatever produced it was given an empty input, and this page will
point that out if you paste it in.
Your browser's cryptography needs the whole of a file in memory at once, so this page
can hash files of up to 2 GB. A larger file would risk running out of memory and taking
the tab down with it, and the page will tell you its size instead.
This page does not compute SHA-3, because your browser's cryptography does not offer it.
If you paste a hash that says it is SHA3-256, the page will tell you that rather than
comparing it with SHA-256, which is the same length.
Try abc in the tool