safepaste hash

Hash calculator

Type or paste some text, or drop in a file, to see its MD5, SHA-1, SHA-256 and other hashes. You can paste the hash you were expecting underneath to check it. Everything is calculated in this tab and nothing is sent anywhere.

Text

You can also drop a file anywhere on this page to hash it. The file is read inside this tab and is never uploaded.

What happens to what you paste

Nothing happens to it beyond what you asked for. It is hashed inside this browser tab, and it is gone as soon as you close the tab. That includes any file you drop onto the page and any HMAC key you type in. SafePaste has no account, no database and no analytics, so there is nothing for any of it to be stored in.

How your browser enforces this

The page includes a Content Security Policy of connect-src 'none'. That makes fetch, XMLHttpRequest, WebSocket, EventSource and sendBeacon fail in the browser itself, whatever the code on this page tries to do. Images and fonts are restricted to data that is already inside the file, and form-action 'none' prevents all form submission.

You do not have to take our word for it. Open your browser's developer tools, watch the Network tab while you use the page, and confirm that it stays empty after the page itself has loaded.

What happens to a file

When you drop a file onto the page or choose one, your browser lets this page read that one file's contents. The page reads it into memory inside this tab and calculates its hashes there. The file is never uploaded, and the page only learns its name and its size, not where it is kept on your computer.

What the host can see

This page is served by Cloudflare Pages. Like any web server, it sees the request for the page itself, which includes your IP address, the name and version of your browser, and the time of the request. That happens before any of this page's code runs, and it is the same for every website you visit. What it does not see is anything you paste or any file you hash, because none of it is ever part of a request.

Cookies, storage and tracking

Links to other sites

The footer links to Flytrap Industries and to a Stripe donation page. Neither is contacted unless you click it. They carry no query string and no referrer, so following one tells the destination nothing about what you were doing here. If you do donate, Stripe handles that payment under its own privacy policy and SafePaste never sees your card details.

Working offline

Save this page to disk and open it again. It is a single self-contained file, so it works with no network at all, including on a machine that has never been connected to one.

This policy describes the page you are reading. It is part of the same file, so the copy you save to disk carries it too.

How hashes work

A hash function takes any amount of data, whether that is a single word or a whole disk image, and turns it into a short value of a fixed length, which is called a hash or a digest. The same input always produces the same hash, but there is no way to work backward from a hash to the input, and changing even one bit of the input changes the hash completely. That combination is what makes a hash useful as a fingerprint. If two files have the same SHA-256 hash, you can be confident that they are the same file without comparing them byte by byte.

Why a hash might not match

Because a hash covers every byte, two pieces of text that look identical on screen can still hash differently. The most common reason is a line break at the end. Running echo hello | sha256sum hashes six bytes, because echo adds a line break after the word, while printf hello | sha256sum hashes only five. Windows and Unix also write line breaks differently, as the two bytes CRLF on Windows and the single byte LF almost everywhere else, and a byte order mark or a non-breaking space can sneak in when text is copied from one program to another.

This page hashes text as UTF-8, and the status line under the box points out anything like that it finds in your text. A text box in a browser can only hold LF line breaks, so when your text has line breaks you can choose which kind they are hashed as, using the buttons that appear underneath. If you paste the hash you were expecting and it does not match, the page also tries the most common variations of your text, and if one of them matches, it will tell you which one.

If you need the hash of a file exactly as it is on disk, drop the file onto the page rather than pasting in its contents. That way the page reads the file's own bytes, and nothing about line breaks or text encodings can get in the way.

Which hash to use

SHA-256 is the usual choice today, and it is what most download pages and package managers publish. SHA-384 and SHA-512 belong to the same family and produce longer hashes. Each of the hashes on this page has a different length, so when you paste a hash to check, the page can tell from its length alone which one it is meant to be.

MD5 and SHA-1 are older, and they are broken, which means that people can now deliberately create two different files with the same hash. They are still fine for catching a download that was damaged by accident, and plenty of older download pages publish them, but they should not be relied on to prove that nobody has tampered with a file. CRC-32 is not a cryptographic hash at all. It is a checksum that zip files, gzip and PNG images use to catch accidental damage, and it is easy to forge on purpose.

Where the hashes come from

Your browser has its own cryptography built in, written and maintained by the people who make the browser, and this page uses it for SHA-1, SHA-256, SHA-384, SHA-512 and every HMAC. The browser does not offer MD5 or CRC-32, so those two are calculated by code in this page, which you can read in View Source like the rest of it. Neither of them is ever used with your key.

HMAC

An HMAC is a hash that also depends on a secret key, so only someone who knows the key can produce the right value. Webhook providers such as GitHub and Stripe use one to sign the requests they send you. They compute an HMAC of the request body with a key that only you and they know, and you check the request by computing the same HMAC yourself. If you type a key into the HMAC key box, the SHA hashes on this page become HMACs with that key, and the key stays in this tab like everything else. MD5 and CRC-32 have no HMAC here, and their rows will say so.

Providers do not all write their keys the same way. GitHub and Stripe use the key exactly as the text you are shown, which is how this page reads it unless you tell it otherwise. Some providers give the key as hex or as base64 instead, and you can choose either of those with the buttons that appear next to the key.

Hex and base64

A hash is a sequence of bytes, and the two usual ways to write it down are hex, which uses two characters for each byte, and base64, which is about a third shorter. They are the same bytes written in two different ways. Most checksum files use hex, while the Subresource Integrity values in HTML, which look like sha384-oqVu..., use base64. You can choose which one this page shows with the buttons above the list of hashes, and you can paste either one into the box for checking.

Some other things worth knowing