MD5 Hash Generator

Generate the MD5 hash of any text or file, check it against a published checksum, or compute an HMAC-MD5. Everything is hashed in your browser.

Generator Text & Encoding Updated Oct 2, 2026
How to Use
  1. Choose Text or File, then type, paste, or drop a file. The hash updates as you go.
  2. To check a download, paste the published MD5 into Expected hash — it says Match or No match.
  3. For an HMAC (a keyed hash used to sign messages), type the secret into HMAC key.
  4. Pick hex, uppercase HEX or Base64 output, then press Copy hash.
  5. Edit the text by one character and watch the bit grid: about half of the 128 bits flip.
Input
hashed as UTF-8
optional
optional — to verify
Presets
MD5 hash
—
Input
—bytes
Blocks
—× 64 B
Digest
128bits · 32 hex
Bits changed
—

Worked Example

Hash the text “abc”.

Bytes: 61 62 63 (3 bytes, 24 bits).
Padding: add 80, then 52 zero bytes, then the length 24 as 8 bytes, low byte first (18 00 00 00 00 00 00 00). Total: 64 bytes — exactly one 512-bit block.
Process the block in 4 rounds of 16 steps, starting from the fixed values 67452301, EFCDAB89, 98BADCFE, 10325476.
Result: 900150983cd24fb0d6963f7d28e17f72.

Now hash “abd”, one letter different: 4911e516e5aa21d327512e0c8b197616. 63 of the 128 bits are different — about half, which is what a good hash does. Nothing in the second hash hints that the inputs were almost the same.

Show Work

Type something above to see how it is hashed.

Formulas

Digest
128 bits = 32 hex
16 bytes, whatever the input size
Padded length
64 × (⌊(n + 8) / 64⌋ + 1)
n input bytes; always at least 9 bytes added
Work per block
4 rounds × 16 steps
On four 32-bit words A, B, C, D
Collision effort
ideal 264 — actual: seconds
Why MD5 is broken for security
HMAC
H((K⊕opad) ‖ H((K⊕ipad) ‖ m))
RFC 2104; ipad = 36…, opad = 5C…
Avalanche
≈ 64 of 128 bits flip
For any one-character change

The Rise and Fall of MD5

Ron Rivest designed MD5 in 1991 to replace MD4, and it was published as RFC 1321 in 1992. For a decade it was the default checksum of the internet: download pages, password files, digital signatures and software updates all used it.

Weaknesses appeared in 1996, and in 2004 Xiaoyun Wang and her colleagues showed how to make two different inputs with the same MD5 quickly. In 2008 researchers used such a collision to create a rogue certificate authority trusted by browsers, and in 2012 the Flame malware used one to pass as a Microsoft-signed update. MD5 is now considered broken for security, but it remains in wide use as a fast checksum for catching accidental damage.

About This Tool

This tool computes the MD5 of text (as UTF-8) or of any file up to 100 MB, and can verify the result against a published checksum — in hex, uppercase hex, Base64, or pasted straight from an md5sum line. With a key it computes HMAC-MD5 instead.

Files are read and hashed in your browser and never uploaded. The bit grid shows all 128 bits of the hash and lights up the ones that flip when you change the input, and Show Work gives the padding and block count for exactly what you entered.

Related tools: SHA-256 Hash Generator, Hash Generator, and File Hasher.

Frequently Asked Questions

What is an MD5 hash?

MD5 turns any input — a word or a 4 GB file — into a fixed 128-bit fingerprint, written as 32 hex characters. The same input always gives the same hash, and changing even one character gives a completely different one: “abc” is 900150983cd24fb0d6963f7d28e17f72 and “abd” is 4911e516e5aa21d327512e0c8b197616.

Is MD5 secure?

Not for security. Since 2004 it has been possible to make two different files with the same MD5, and that was used to forge a certificate authority in 2008 and to sign the Flame malware in 2012. MD5 is still fine for spotting accidental corruption or duplicates; for signatures, certificates or anything an attacker could tamper with, use SHA-256.

Can an MD5 hash be decrypted?

No — a hash is one-way, not encryption. But common inputs can be looked up: 5f4dcc3b5aa765d61d8327deb882cf99 is well known to be the MD5 of “password”. That is why passwords must never be stored as plain MD5; use a slow password hash such as bcrypt or Argon2.

Why is my MD5 different from another tool’s?

Almost always an invisible difference in the input. echo hello | md5sum hashes “hello” plus a line break and gives b1946ac92492d2347c6235b4d2611184, not the 5d41402a… of “hello” alone. Windows line endings (\r\n), a trailing space or a different text encoding change the hash too.

How do I verify a downloaded file with MD5?

Choose File, drop the download, and paste the MD5 from the publisher’s site into Expected hash. A match means the file arrived exactly as published. On the command line the same check is md5sum file (Linux), md5 file (macOS) or certutil -hashfile file MD5 (Windows).

How do I use the MD5 Hash Generator?

Simply pick your options and read the result, which refreshes the instant you change something. There is nothing to submit and nothing to wait for.

Does it cost anything or need an account?

No. The tool is completely free, there is no account to create, and it keeps working offline after the page first loads.

Is anything I type uploaded?

No. The tool works entirely on your device, so the values you enter never leave your browser.

Common Use Cases

Checking a download

A Linux ISO page lists its MD5. Drop the file and paste the value; one changed byte anywhere in 4 GB gives a different hash.

Finding duplicate files

Two photos with the same MD5 are byte-for-byte identical, so hashing a folder finds duplicates without comparing every pair.

Cache keys and ETags

Web servers and build tools use an MD5 of a file’s contents as its version tag — the hash changes exactly when the contents change.

Older APIs

Some older services identify things by the MD5 of a normalised value, such as Gravatar’s original lookup by the MD5 of a lower-cased email address.

HMAC-MD5 in legacy protocols

Protocols like CRAM-MD5 authentication sign a challenge with HMAC-MD5; with key “secret”, “hello” signs to bade63863c61ed0b3165806ecd6acefc.

Last updated: