How to use it
- Type or paste the text, or switch to File and drop one on the dropzone.
- All five digests appear at once. The a1b2 / A1B2 switch changes the hex case.
- Put a secret in HMAC key and every digest becomes its HMAC — the arrangement a postback signature uses.
- Paste an expected value into Compare with. The algorithm follows from the length, and the matching row turns green or red.
What is computed where
SHA-1, SHA-256, SHA-384 and SHA-512 go through WebCrypto, the browser native implementation, so a large file is hashed at close to native speed. MD5 is not in WebCrypto — no browser offers it, because it has been broken for collisions since 2004 — so it is implemented in the page and processed in chunks, yielding to the event loop between them. That is why a 500 MB file does not freeze the tab, and why a progress percentage appears for MD5 alone.
WebCrypto needs a secure context. On HTTP, or in some privacy-hardened setups, the SHA rows show as unavailable while MD5 still works, and the status line says so instead of leaving you guessing.
HMAC, and why a plain hash is not a signature
Concatenating a secret with a payload and hashing the result is a signature scheme with a known weakness: the length-extension attack lets someone append data to the payload and produce a valid-looking digest without knowing the secret. HMAC exists to close that, by hashing the message twice with two derived keys. If a tracker or an affiliate network documents a signature as HMAC-SHA256, put the secret in the key field here and compare against what they sent.
The key is held in the page and is not written to local storage. Reload and it is gone.
Which algorithm to use
- MD5 — only for checksums against a file someone published. Never for passwords, never for signatures.
- SHA-1 — same category. A practical collision was demonstrated in 2017.
- SHA-256 — the default for signatures, integrity checks and anything new.
- SHA-384 and SHA-512 — the same family with a longer digest; SHA-512 is often faster on 64-bit hardware.
Verifying a download
Switch to File, drop the file in, paste the published checksum into the comparison field and read the verdict. The file is read through the File API and processed in memory; nothing is uploaded, which is the only sane way to check a hash on something you did not want to send anywhere in the first place.
Questions
Is my file uploaded?
No. It is read locally through the browser File API and hashed in the page. Nothing is transmitted, so the tool works on a file you would never put on someone else server.
Why is SHA-256 unavailable on this page?
The SHA family comes from WebCrypto, which browsers only expose in a secure context. Open the page over HTTPS and the rows fill in. MD5 is implemented in the page itself and works either way.
How do I check a postback signature?
Paste the exact payload the network signs, put the shared secret in HMAC key, and compare the HMAC-SHA256 row against the signature you received. Getting the payload byte-exact is usually the hard part.
Can a hash be reversed?
Not by computation. It can be looked up: MD5 and SHA-1 of common passwords and short strings sit in public rainbow tables, which is a reason not to hash a password with either.
What does the comparison field accept?
Hex, in any case, with optional whitespace and an optional prefix such as sha256:. The algorithm is inferred from the length — 32, 40, 64, 96 or 128 characters.