Hash Generator Widget
Add a hash generator to your security or developer pages. Readers type text and see its MD5, SHA-1, SHA-256, SHA-384 and SHA-512 digests side by side, in hex or Base64.
Live preview
Exactly what your visitors will seeUnder the widget on your page: Powered by A2Z Tools
Embed code
<iframe src="https://a2z.tools/embed/w/hash-generator" title="Hash Generator by A2Z Tools" width="100%" height="830" style="border:0;width:100%" loading="lazy" allow="clipboard-write"></iframe>
A plain iframe. Works everywhere, including site builders that strip scripts. Adjust height if your content needs more room.
<div data-a2z-widget="hash-generator" data-height="830"></div> <script async src="https://a2z.tools/embed.js"></script>
Adds a small script (what it does) that sizes the widget to fit its content, loads it lazily and keeps it isolated from your page's CSS.
Works with
How it works
Text is converted to UTF-8 bytes and hashed in the browser. The SHA family comes from Web Crypto (crypto.subtle.digest), the browser's native implementation. Web Crypto deliberately leaves out MD5, so the widget includes a straightforward implementation of RFC 1321, checked against the RFC's own test vectors. MD5 and SHA-1 are marked as unsuitable for security: practical collision attacks exist for both, so they are only good for matching a published checksum. Web Crypto only exists on https pages; on plain http the SHA rows say so rather than failing silently.
Method
- Input: UTF-8 bytes of the text (no trailing newline added)
- MD5: RFC 1321; SHA-1/SHA-256/SHA-384/SHA-512: FIPS 180-4 via crypto.subtle.digest
- Output: lowercase or uppercase hex, or Base64 of the digest bytes
- Digest sizes: MD5 128, SHA-1 160, SHA-256 256, SHA-384 384, SHA-512 512 bits
Limitations
- Hashes typed text only, not files, so it cannot check the checksum of a downloaded installer directly.
- No HMAC, salted or keyed hashing, and no SHA-3, BLAKE2/3 or CRC32.
- Line endings are hashed exactly as pasted: text copied from Windows with CRLF gives a different digest from the same text with LF.
- The SHA rows need a secure (https) page because Web Crypto is unavailable elsewhere; MD5 works on any page.
Where publishers use it
- Download pages that publish checksums for installers or ISO images
- Security courses showing how a one-character change alters the whole digest
- API docs that sign requests with SHA-256 (e.g. content hashes)
- Explaining why MD5 is still seen in the wild but should not protect anything
Questions
Can I hash passwords with this?
No hash here is suitable for storing passwords. Use a slow, salted algorithm such as bcrypt, scrypt or Argon2 on your server.
Why does my command-line hash differ?
echo adds a newline, so echo hello | sha256sum hashes "hello\n". Use printf 'hello' or echo -n to match the widget.
Is MD5 safe?
Not for security - collisions can be created deliberately. It is still fine for detecting accidental corruption.
Is my text uploaded?
No. All hashing runs in the browser.
Sources
- FIPS 180-4: Secure Hash Standard (SHS) - NIST . SHA-1, SHA-256, SHA-384, SHA-512; August 2015
- RFC 1321: The MD5 Message-Digest Algorithm - IETF . Algorithm and appendix A.5 test suite (checked in the tests)
- RFC 6151: Updated Security Considerations for MD5 - IETF . MD5 is not collision-resistant
- NIST Retires SHA-1 Cryptographic Algorithm - NIST . SHA-1 to be phased out by 31 December 2030; 15 Dec 2022
Cite or recommend this tool
If you reference this tool in an article, course or documentation, these formats are ready to copy. They are optional - nothing is added to your site unless you paste it.
A2Z Tools Hash Generator https://a2z.tools/hash-generator
<a href="https://a2z.tools/hash-generator">A2Z Tools Hash Generator</a>
[A2Z Tools Hash Generator](https://a2z.tools/hash-generator)
Hash Generator by A2Z Tools - https://a2z.tools/hash-generator
Related widgets
-
Encode text to Base64 or decode it, with proper UTF-8 and an optional URL-safe alphabet.
-
Generate 1 to 100 random v4 or time-ordered v7 UUIDs in several formats.
-
Read a JSON Web Token's header and claims, with exp, nbf and iat shown as dates.
-
Pretty-print, minify or validate JSON, with the line and column of the first syntax error.
-
Convert a JSON array of objects to CSV and CSV back to JSON, with RFC 4180 quoting.
-
Percent-encode or decode text and URLs, and find the exact position of a malformed escape.