How to use the Hash Generator
- Type or paste the text.
- Turn on HMAC and enter a key if you need a signature.
- Copy the hash you need.
What does this tool do?
A hash function turns any input into a fixed-length fingerprint. The same input always gives the same hash, and a tiny change gives a completely different one. HMAC combines a hash with a secret key to prove a message came from someone who knows the key, which is how many webhooks are signed.
Text is encoded as UTF-8 before hashing, matching what most programming languages do.
Why use it?
- Verify webhook signatures.
- Generate checksums and cache keys.
- Compare values without revealing them.
Example
The SHA-256 of “hello” is 2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824.
Accuracy and limits
- MD5 and SHA-1 are broken for security purposes. Use SHA-256 or better for anything security-related, and a dedicated algorithm (like bcrypt or Argon2) for storing passwords.
Privacy
Everything you type is processed in your browser. Nothing you enter is sent to our servers or stored by us. There's no account to create and nothing to install.
Frequently asked questions
Is it safe to do this in a browser?
Yes, because nothing leaves your device. Everything is generated or checked with your browser's built-in cryptography (the Web Crypto API) — no network requests are made with what you type.
Can a hash be reversed?
Not directly. But short or common inputs can be found by guessing, so hashing alone doesn't protect weak passwords.
Last reviewed by the M2Toolkit team.