Hash Generator Widget

Add a hash generator to your security or developer pages. Readers type text and see its MD5, SHA-1, SHA-256, SHA-384 and SHA-512 digests side by side, in hex or Base64.

Developer Tools Generator Runs in your browser Free · no ads

Customize your widget

Theme
Auto follows the visitor's light/dark setting.
Style
Attribution on your page
Optional and entirely your choice. The exact line is shown in the code below; it links to the tool with rel="nofollow".
More options
Starting values
Leave blank to use the widget's defaults. Visitors can still change every value.

Live preview

Exactly what your visitors will see

Embed code

<iframe src="https://a2z.tools/embed/w/hash-generator" title="Hash Generator by A2Z Tools" width="100%" height="830" style="border:0;width:100%" loading="lazy" allow="clipboard-write"></iframe>

A plain iframe. Works everywhere, including site builders that strip scripts. Adjust height if your content needs more room.

Works with

How it works

Text is converted to UTF-8 bytes and hashed in the browser. The SHA family comes from Web Crypto (crypto.subtle.digest), the browser's native implementation. Web Crypto deliberately leaves out MD5, so the widget includes a straightforward implementation of RFC 1321, checked against the RFC's own test vectors. MD5 and SHA-1 are marked as unsuitable for security: practical collision attacks exist for both, so they are only good for matching a published checksum. Web Crypto only exists on https pages; on plain http the SHA rows say so rather than failing silently.

Method

  • Input: UTF-8 bytes of the text (no trailing newline added)
  • MD5: RFC 1321; SHA-1/SHA-256/SHA-384/SHA-512: FIPS 180-4 via crypto.subtle.digest
  • Output: lowercase or uppercase hex, or Base64 of the digest bytes
  • Digest sizes: MD5 128, SHA-1 160, SHA-256 256, SHA-384 384, SHA-512 512 bits

Limitations

  • Hashes typed text only, not files, so it cannot check the checksum of a downloaded installer directly.
  • No HMAC, salted or keyed hashing, and no SHA-3, BLAKE2/3 or CRC32.
  • Line endings are hashed exactly as pasted: text copied from Windows with CRLF gives a different digest from the same text with LF.
  • The SHA rows need a secure (https) page because Web Crypto is unavailable elsewhere; MD5 works on any page.

Where publishers use it

  • Download pages that publish checksums for installers or ISO images
  • Security courses showing how a one-character change alters the whole digest
  • API docs that sign requests with SHA-256 (e.g. content hashes)
  • Explaining why MD5 is still seen in the wild but should not protect anything

Questions

Can I hash passwords with this?

No hash here is suitable for storing passwords. Use a slow, salted algorithm such as bcrypt, scrypt or Argon2 on your server.

Why does my command-line hash differ?

echo adds a newline, so echo hello | sha256sum hashes "hello\n". Use printf 'hello' or echo -n to match the widget.

Is MD5 safe?

Not for security - collisions can be created deliberately. It is still fine for detecting accidental corruption.

Is my text uploaded?

No. All hashing runs in the browser.

Sources

  1. FIPS 180-4: Secure Hash Standard (SHS) - NIST . SHA-1, SHA-256, SHA-384, SHA-512; August 2015
  2. RFC 1321: The MD5 Message-Digest Algorithm - IETF . Algorithm and appendix A.5 test suite (checked in the tests)
  3. RFC 6151: Updated Security Considerations for MD5 - IETF . MD5 is not collision-resistant
  4. NIST Retires SHA-1 Cryptographic Algorithm - NIST . SHA-1 to be phased out by 31 December 2030; 15 Dec 2022

Cite or recommend this tool

If you reference this tool in an article, course or documentation, these formats are ready to copy. They are optional - nothing is added to your site unless you paste it.

A2Z Tools Hash Generator
https://a2z.tools/hash-generator

Preview