The Volade Ecosystem — Web Tool

Hash Generator

Hash a text, a file or an HMAC message with MD5, SHA-1, SHA-256, SHA-384, SHA-512 and CRC32 in one click: hexadecimal or Base64 output, known-hash verification, measured throughput, local history and an algorithm cheat sheet. Free, no sign-up and 100% local: your content never leaves your browser.

6 hash algorithms0 byte sent to the server25 MB per file
The tool

Your online hash generator

Paste your text, tick the algorithms and the digests appear immediately, in hexadecimal or Base64, with the time and throughput measured.

Hash Generator

Online Security, Network & Cryptography
Sign in
Shortcuts: Ctrl + Enter generate
Ready.
0 bytes
Hashing starts as soon as you click « Generate », or with Ctrl + Enter. Each ticked algorithm produces its own row.
The SHA algorithms rely on your browser's Web Crypto API; MD5 and CRC32 are computed locally in JavaScript. CRC32 is always displayed in hexadecimal, because its output is only four bytes.
Click an example to load it into the input box and start hashing.
AlgorithmLengthValue
Hashing runs in your browser · Ctrl + Enter to hash · no network request · 100% local, nothing leaves your device.
0,0 0Comment All tools
Free or Premium?

The hash generator is free and unlimited: no account, nothing to install, no network request. Premium unlocks the whole Volade ecosystem.

FreeMD5, SHA-1, SHA-256, SHA-384, SHA-512 and CRC32 in hexadecimal or Base64
FreeFiles up to 25 MB, HMAC-SHA-1/256/512 and equality check
FreeLocal history, measured throughput and an algorithm cheat sheet
PremiumEncrypted cloud sync of your comparisons across your devices
PremiumAPI access and scripts shared across the ecosystem tools
Unlock Premium
Features

Hash, verify and compare without leaving your browser

Six algorithms, three input types and a local history — everything you need to check the integrity of a piece of content.

Six algorithms in a single run

Tick MD5, SHA-1, SHA-256, SHA-384, SHA-512 and CRC32: the digests appear together in a table, with their exact length and the chosen format — lowercase hexadecimal, uppercase or Base64. Time and throughput are measured for every run, and « Copy results » puts the name-value pairs on the clipboard.

Generate a digest

File, text or HMAC message

The Files tab hashes a document of up to 25 MB in a single pass, in memory, with no upload: archives, executables, screenshots, backups. The HMAC tab combines a secret key with the message using HMAC-SHA-1, HMAC-SHA-256 or HMAC-SHA-512 to authenticate an exchange between two parties. As for the text, it is hashed on every Ctrl + Enter.

Hash a file

Verification, history and cheat sheet

Paste a published digest: the tool compares it with the one computed from your text and tells you whether the match is exact, with no fuzzy comparison. Every calculation joins the local history with its time and throughput, summarised by four indicators and a chart. The filterable cheat sheet recalls sizes, formulas and security pointers.

Verify a digest
How it works

Hash any content in three steps

No installation, no sign-up: the tool is always ready, on mobile as on desktop.

Paste the content

A text entered in the Text tab, a file picked in the Files tab, or a key and message pair in the HMAC tab. Nothing is sent: your input stays on your device, even offline.

Choose the algorithms

Tick SHA-256 for serious use, MD5 for a quick check, CRC32 for a checksum: the boxes can be combined freely. The output format switches between hexadecimal and Base64 in one click.

Copy, verify, archive

Copy the digests to keep them next to the file, paste a published value into the verification field to confirm the match, then open the Statistics tab: every calculation records its time and throughput there.

Quick reference

The algorithms at a glance

What most people check before hashing a piece of content — with full definitions in the « Cheat sheet » tab.

AlgorithmOutputTypical use
MD5128 bits → 32 hex charsindexes, caches, non-sensitive checks
SHA-1160 bits → 40 hex charslegacy certificates, Git history
SHA-256256 bits → 64 hex charsfile integrity, signatures
SHA-384384 bits → 96 hex charslonger SHA-2 variants
SHA-512512 bits → 128 hex charslarge volumes on 64-bit processors
CRC3232 bits → 8 hex charstransmission errors, ZIP archives
HMAC-SHA-256256 bits with a secret keytokens, APIs, authenticated messages
Hexadecimal2 characters per bytereadable, comparable display
Base644 characters per 3 bytescompact transport, HTTP headers
Published digestcopy kept next to the fileintegrity proof you can re-check later

What is a hash function?

A hash function turns any content — a sentence, a piece of software, a multi-gigabyte backup — into a fixed-length string called a digest or hash. Three properties define it: the output is always the same size whatever the input, the same content always produces the same digest, and going from the digest back to the input must be impractical. It is this third point that separates a cryptographic hash from a checksum like CRC32.

In practice, two uses cover most of the ground. Verifying integrity : the publisher posts the digest of their file, you recompute it, and a match proves the download was not tampered with. Comparing contents : instead of keeping the documents themselves, you keep their digests — identical digests mean identical contents, without revealing anything about their nature.

Which algorithm should you choose today?

SHA-256 is the default answer: standardised by the NSA, then adopted everywhere, implemented in every language, and with no known collision. SHA-512 fits large volumes when the processor is 64-bit, often faster than its cousin on that kind of architecture. SHA-384 brings nothing special beyond a longer variant. For keyed message signing, the HMAC-SHA-256 is the reference: it combines the secret key and the hash, so only the key holder can produce the same value.

The MD5 and the SHA-1 remain useful for non-sensitive checks — an index, a cache, duplicate detection — where speed matters more than resistance. The CRC32, for its part, is not a cryptographic hash: it detects accidental corruption, but a deliberate alteration can be crafted in seconds.

Why are MD5 and SHA-1 considered broken?

Because researchers have produced, for each of them, two different documents sharing the same digest. For MD5, the demonstration dates back to 2004; for SHA-1, a real collision was produced in 2017 under the name SHAttered. A single collision is enough to break a signature: if the attacker chooses the document and the publisher only hashes it, they can obtain a signature over entirely different content. That is why TLS certificates, software updates and package signatures have dropped these algorithms.

What hashing does not do

Hashing is not encrypting: a digest is irreversible by design, but it does not protect the content by making it unreadable. Hashing encrypts nothing, replaces neither TLS nor an encryption key, and does not protect a password on its own — that is a job for bcrypt, scrypt or Argon2, designed to be slow. Finally, hashing twice strengthens nothing: chaining algorithms only adds a fragile layer where a single unbroken function would suffice.

Recommended for

System administrators and CIOs who verify distribution checksums, developers who seal artifacts or authenticate webhooks, auditors and compliance staff who check backup integrity, journalists and analysts who compare documents without distributing them, cryptography students working with the notions of digest, collision and salt — and anyone who wants to hash some content quickly and without a trace, complemented by the password generator, theBase64 encoder decoder, the JWT decoder, the regex tester and the character counter.

FAQ

Frequently asked questions about the hash generator

Everything you want to know before comparing digests, signing a message or checking a file.

What is the difference between hashing and encryption?

Encryption turns content into a secret form so that only the key holder can read it: it is reversible. Hashing produces an irreversible digest, designed so that you can never get back to the content. You encrypt to protect confidentiality; you hash to prove integrity or to compare without storing.

Which hash algorithm should you choose today?

SHA-256 for any serious use: file integrity, signatures, tokens, content comparison. SHA-512 for large volumes on a 64-bit processor. HMAC-SHA-256 as soon as a secret key is involved. Keep MD5 and CRC32 for non-sensitive checks where speed wins, never to authenticate or sign.

Why are MD5 and SHA-1 discouraged?

Because collisions have been demonstrated publicly: two different documents can produce exactly the same digest. An attacker who chooses the content can therefore fool a check based on the hash alone. That is why certificates, package signatures and official updates replaced them with functions from the SHA-2 family.

What does a 64-character hexadecimal output mean?

Each hexadecimal character encodes four bits, so two characters make one byte: 64 characters is 32 bytes, i.e. 256 bits. That is exactly the size of a SHA-256 digest. Likewise, 32 characters mean an MD5, 40 characters a SHA-1, 96 characters a SHA-384 and 128 characters a SHA-512.

Is CRC32 a cryptographic hash?

No: it is a 32-bit checksum designed to detect accidental transmission or storage errors. Its output fits in eight characters, it is easy to produce deliberately, and it resists nothing adversarial. Use it to check that an archive is not corrupted, never to prove that a file is authentic.

What is the difference between HMAC and a plain hash?

A plain hash can be recomputed by anyone: it proves that the content is unchanged, not where it came from. HMAC folds a secret key into the calculation: only the holder of that key can produce the same digest, which authenticates the sender together with the integrity. That is the construction used for API tokens and webhooks.

How do I check that a file is intact?

Recompute its digest with the same algorithm the publisher announced, then compare the two values over their whole length, after normalising the case. A single-character difference signals tampering. With this tool, load the file in the Files tab, copy the displayed value and compare it with the published one.

Does the tool send my text or file to a server?

No: MD5 and CRC32 are computed in JavaScript, the SHA and HMAC algorithms use your browser's Web Crypto API, and everything runs locally, with no network request and no account, even offline. Your content, your keys and your history stay in your device's local storage and can be erased in one click.

100% local hash generator: your content never leaves your computer

Unlike online services that upload your files to hash them server-side, nothing is transmitted here: MD5 and CRC32 are computed in JavaScript, SHA and HMAC by your browser's Web Crypto API, and the result is displayed before anything can leave the page. That is what lets you hash a contract, an application log or a sensitive backup — even offline or on a public network. The text, the digests and the history stay in your device's local storage.

The license Volade Premium adds optional, encrypted cloud sync independent of the tool — everything else stays free and unlimited, with no sign-up.

One premium license, all your web tools

Hash generator, Base64 encoder decoder, JWT decoder, regex tester, JSON formatter, generators and dozens of free tools — and the whole Volade ecosystem with a single license.

One licence, the whole premium ecosystem Browser · CMS · Desktop · Mobile · Scripts · API · Tools · Database
One licence, the whole ecosystem Go premium Log in