Hash Generator
Compute a cryptographic hash of the text you paste, using the Web Crypto implementation already in your browser. All four algorithms can be compared side by side, which is the quickest way to see that the length of the digest says nothing about the quality of the hash.
How hash generator works
- Paste the textEncoded as UTF-8 first, so non-ASCII input hashes the same as it does anywhere else.
- Choose the algorithmOr pick all four to see the digests together.
- Copy the digestLower or upper case, and the byte count of the input is shown beside it.
What you get
Hash text with SHA-256, SHA-384, SHA-512 or SHA-1. Everything happens inside this page: the file is read by your browser, transformed in memory and handed straight back to you as a download. There is no upload queue, no waiting for a server, and nothing left behind when you close the tab.
Supported formats
This tool works on text you paste or type, so there is no file format to worry about. Nothing you type is sent anywhere.
Limitations, stated up front
- No keyed hash, no salting, no key stretching, and no file hashing. This is a plain one-way digest of text.
- SHA-1 is offered for compatibility with older systems, not because it should be used.
Frequently asked questions
Is SHA-1 safe to use?
No, not for anything that has to resist an attacker. Practical collisions against SHA-1 have been demonstrated, and chosen-prefix collisions are cheap enough to buy. Version control still uses it to identify objects, and that is fine — nothing there depends on collision resistance. For signatures, certificates, download integrity or anything adversarial, use SHA-256 or better.
Can I use this to hash a password?
No. A plain hash is fast on purpose, and a fast hash is exactly what a password cracker wants. Passwords need a slow, salted function such as Argon2, scrypt or bcrypt, which is a different tool. As a checksum for a downloaded file or a cache key, this is the right tool.
Why is the output different on another machine?
It should not be. SHA-256 of the same UTF-8 text is the same everywhere, on every platform. If two machines disagree, the inputs differ — a trailing newline, a different line ending, a non-breaking space, or a different text encoding are the usual causes. Furtu encodes UTF-8 and reports the byte count, which makes that easy to check.
What happens if the page is not served over HTTPS?
Web Crypto is only available in a secure context, so Furtu says so plainly instead of producing nothing. It needs HTTPS, or HTTP on localhost.
Is the text I hash uploaded?
No. The digest is computed with the Web Crypto API in your browser. This is why Furtu will hash a licence key or a password hash comparison, but you should still not paste a real password anywhere.