SHA Hash Generator

One input, all four SHA digests — computed with your browser's native WebCrypto, verified against FIPS 180 test vectors.

SHA-1
160-bit
SHA-256
256-bit
SHA-384
384-bit
SHA-512
512-bit

Privacy: hashing runs entirely in your browser with the native Web Crypto API — input and digests never leave this page.

How to use

  1. Type or paste the text to hash.
  2. Read all four digests (SHA-1, SHA-256, SHA-384, SHA-512) as they update.
  3. Prefer SHA-256 or SHA-512 for anything new; treat SHA-1 as legacy-only.

Frequently asked questions

Which SHA variant should I pick?

SHA-256 is the sensible default today: 256-bit output, universally supported. SHA-512 is not "twice as safe" but has longer output and is actually faster on 64-bit machines for large inputs. SHA-384 is SHA-512 truncated for shorter keys. SHA-1 is legacy only — collisions exist, so use it solely for compatibility with old systems.

Why does this page need a secure context?

The digests are computed with the Web Crypto API (crypto.subtle), and browsers only expose it over HTTPS or on localhost. Opened over plain HTTP on a normal domain, the tool shows a notice instead of pretending to work. This site is served over HTTPS, so you are covered.

Can SHA hashes be reversed?

No — they are one-way. What attackers do is guess: hash candidate inputs (usually word lists) and compare. That is why password hashing uses dedicated slow schemes (bcrypt/argon2), not raw SHA of a password.

Does my input leave the browser?

No. crypto.subtle.digest runs locally; the text and all four digests stay in this tab.

Why do all four digests update together?

Each is an independent function of the same input bytes, so the tool computes all of them at once — convenient when a downstream system needs a specific variant.

Comments