Dev Toolbox · Windows 10 and 11
SHA-256 hash generator
Type or paste text and see its SHA-1, SHA-256, SHA-384 and SHA-512 hashes at the same time, worked out again on every keystroke. Copy the one you need in lowercase or uppercase hex. The text is hashed on your own PC, which matters when it is a key or a password.
How to make a SHA-256 hash
- 1
Open the Hash generator
In the Dev Toolbox, choose Hash generator under Make.
- 2
Enter the text
Type or paste into the Text box. All four hashes are computed from the text's UTF-8 bytes as you type.
- 3
Pick the case
Hex is lowercase to start with. Switch on Uppercase to match tools that print hashes in capitals.
- 4
Copy the hash
Press Copy on the row you need: SHA-256, or SHA-1, SHA-384 or SHA-512.
What a hash is, and what makes SHA-256 useful
A hash function turns any input into a fixed-length fingerprint. Three properties make it useful: the same input always gives the same hash; changing a single character changes the whole hash beyond recognition; and there is no way back from the hash to the text, short of guessing inputs until one matches.
Try it: hello and Hello differ by one capital letter, and their SHA-256 hashes begin 2cf24dba and 185f8db3. Nothing in the two results looks related.
That is why hashes are used to check that something has not changed (a download, a backup, a config value), to look things up without storing them (cache keys, finding duplicates), and as a building block of digital signatures, certificates and version control. SHA-256 is the usual choice for all of these today: it is supported everywhere, and no practical attack on it is known.
SHA-1, SHA-256, SHA-384, SHA-512, and the missing MD5
| Hash | Bits | Hex characters | Use it for |
|---|---|---|---|
| SHA-1 | 160 | 40 | Matching older systems only, never for security |
| SHA-256 | 256 | 64 | The everyday standard |
| SHA-384 | 384 | 96 | Where a policy asks for it, as some TLS and government profiles do |
| SHA-512 | 512 | 128 | When you want the longest hash of the family |
SHA-384 is SHA-512 started from different values and cut short. SHA-1 is broken for collisions: in 2017 researchers published two different PDF files with the same SHA-1, so it must not vouch for anything an attacker could influence. It lives on in older checksum lists and in Git's object names.
MD5 is not in this tool. Its collisions were found much earlier, in 2004, and it should not be used where security counts. If you need an MD5 to compare a file against an old checksum list, PowerShell's Get-FileHash with -Algorithm MD5 does it.
Why your hash does not match
Two tools hashing "the same text" disagree more often than you might think. A hash is of bytes, not of what you see, so every invisible difference counts:
- A trailing newline. echo hello | sha256sum on Linux hashes hello plus a line break and gives 5891b5b5…, not 2cf24dba…. Use echo -n or printf to match.
- Line endings. Windows text uses CR LF, Linux and macOS use LF. Multi-line text moved between them hashes differently.
- Spaces at the ends, picked up when copying from a web page or a PDF.
- Encoding. Octoolo hashes UTF-8. A program that turns text into UTF-16 first, as .NET code using Encoding.Unicode does, gets a different hash for the same characters.
- Case of the hex. Not a real difference: 2CF24DBA and 2cf24dba are the same hash. PowerShell's Get-FileHash prints capitals, so Uppercase makes comparing by eye easier.
And if the SHA-256 row shows e3b0c442…b855, you have hashed nothing at all: that is the hash of empty input.
Files, passwords and keys
Files. This tool hashes text. To get a file's SHA-256 from the command line, Get-FileHash file.iso in PowerShell (SHA-256 unless you ask otherwise) and certutil -hashfile file.iso SHA256 both work.
Passwords. Never store passwords as a plain SHA hash. SHA-256 is built to be fast, so a stolen list can be tested against billions of guesses a second on ordinary graphics cards. Password storage needs a slow, salted algorithm such as Argon2, bcrypt, scrypt or PBKDF2. Octoolo's own password manager protects its vault with Argon2id.
Secrets. Hashing an API key on a website means typing the key into that website. Here it never leaves your PC. This is a plain hash, not an HMAC: there is no key field, so it cannot reproduce the HMAC signatures that webhook services send.
Questions, answered
Can a SHA-256 hash be decrypted?
No. A hash is not encryption, so there is nothing to decrypt. The only way back is guessing inputs, which works for short or common text, so the hash of a weak password is not a secret.
Is SHA-256 the same as SHA-2?
SHA-2 is the family; SHA-256, SHA-384 and SHA-512 are members of it, named after their length in bits. SHA-1 is an older, separate design.
How long is a SHA-256 hash?
256 bits, written as 64 hexadecimal characters, or 44 characters in Base64. Every input, from an empty string to a whole book, gives a hash of that length.
Can two different texts have the same SHA-256?
In theory, yes, since there are endless inputs and a fixed number of hashes. In practice, no one has ever found such a pair for SHA-256.
How does a password leak check use SHA-1?
Octoolo's password leak check hashes your password with SHA-1 and sends only the first five hex characters to Have I Been Pwned. The list of matching hashes comes back, and the comparison happens on your PC.
SHA-256 hash generator, and 16 more apps.
Download for Windows7 days free, then from $3.99 a month for all 17 apps. Windows 10 and 11.