SHA-256 Hash Generator
Generate the SHA-256 hash of any text or file, verify a download against its published checksum, or compute an HMAC-SHA256 signature. Everything is hashed in your browser.
How to Use
- Choose Text or File, then type, paste, or drop a file. The hash updates as you go.
- To check a download, paste the published SHA-256 into Expected hash — it says Match or No match. A whole sha256sum line works too.
- To sign or check a webhook, put the shared secret in HMAC key.
- Pick hex, uppercase HEX or Base64 output, then press Copy hash.
- Edit the text by one character and watch the bit grid: about half of the 256 bits flip.
—Worked Example
Hash the text “abc”.
Bytes: 61 62 63 (3 bytes, 24 bits).
Padding: add 80, then 52 zero bytes, then the length 24 as 8 bytes, high byte first (00 00 00 00 00 00 00 18). Total: 64 bytes — one 512-bit block.
Expand the block into 64 words and run 64 rounds on eight 32-bit words, starting from fixed values taken from the square roots of the first eight primes (6A09E667, BB67AE85 …).
Result: ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad.
Now “abd”: a52d159f262b2c6ddb724a61840befc36eb30c88877a4030b65cbe86298449c9. 122 of the 256 bits are different — close to half, with no trace of how similar the inputs were. The empty input has a hash too: e3b0c442…7852b855, which you will see wherever an empty file was hashed.
Show Work
Formulas
Where SHA-256 Came From
SHA-256 belongs to the SHA-2 family, designed by the US National Security Agency and published by NIST in 2001 (FIPS 180-2, finalised in 2002). It followed SHA-1, whose 160-bit output was starting to look too short, and MD5, which was already showing cracks.
Those worries proved right: MD5 collisions became practical in 2004, and in 2017 Google and CWI Amsterdam produced two different PDF files with the same SHA-1 (“SHAttered”). SHA-256 has no such attack, and it became the default for HTTPS certificates, software signing, package managers and, from 2009, Bitcoin.
About This Tool
This tool computes the SHA-256 of text (as UTF-8) or of any file up to 100 MB using your browser’s built-in cryptography, and can verify the result against a published checksum — in hex, uppercase hex, Base64, or pasted straight from a sha256sum line. With a key it computes HMAC-SHA256 instead.
Files are read and hashed on your device and never uploaded. The bit grid shows all 256 bits and lights up the ones that flip when you change the input, and Show Work gives the padding and block count for exactly what you entered.
Related tools: MD5 Hash Generator, Hash Generator, and File Hasher.
Frequently Asked Questions
What is SHA-256?
SHA-256 is a hash function from the SHA-2 family. It turns any input into a 256-bit fingerprint, written as 64 hex characters. The same input always gives the same hash, and the smallest change gives a completely different one: “abc” is ba7816bf…20015ad and “abd” is a52d159f…298449c9.
Is SHA-256 secure?
Yes. No practical way is known to find two inputs with the same SHA-256 or to work back from a hash to its input. It protects HTTPS certificates, software signing and Bitcoin. Its predecessors are a different story: MD5 has been broken since 2004 and SHA-1 since 2017.
Can a SHA-256 hash be reversed?
No. It is a one-way function, not encryption, and there is no key to undo it. The only way to find an input is to guess and check, which is hopeless for anything long or random — but fast for short, common inputs, which is why hashes of passwords need salt and a slow algorithm.
Should I hash passwords with SHA-256?
No. SHA-256 is designed to be fast — a graphics card can try billions of guesses a second. Passwords need a deliberately slow, salted algorithm such as Argon2, bcrypt or scrypt. Use SHA-256 for checksums, signatures and identifiers.
What is HMAC-SHA256?
A keyed hash: SHA-256 run twice with a secret key mixed in (RFC 2104). Only someone with the key can produce the right value, so services use it to sign messages. GitHub, for example, sends X-Hub-Signature-256: sha256= followed by the HMAC-SHA256 of the request body. With key “secret”, “hello” signs to 88aab3ede8d3adf94d26ab90d3bafd4a2083070c3bcce9c014ee04a443847c0b.
How do I use the SHA-256 Hash Generator?
Simply pick your options and read the result, which refreshes the instant you change something. There is nothing to submit and nothing to wait for.
Do I need to install or sign up for anything?
Not at all — it runs in the browser with nothing to install and no account. After it loads once, it even works without an internet connection.
Is my information private?
Yes. Everything happens in your browser. Nothing you type is sent to a server or saved anywhere.
Common Use Cases
Verifying a download
Software sites publish SHA256SUMS files. Drop the download and paste its line into Expected hash — a match proves not one byte changed.
Webhook signatures
Put your webhook secret in HMAC key and paste the request body to recompute the signature GitHub or Stripe sent, and see if they agree.
Bitcoin
Block and transaction IDs are SHA-256 applied twice. Miners search for an input whose double SHA-256 starts with enough zeros.
Content addresses
Docker images and Git (in its SHA-256 mode) name each piece of content by its hash, so identical content is stored once and any tampering changes the name.
Comparing large files
Hash two 2 GB files instead of comparing them byte by byte across a network: equal hashes mean equal files.
Last updated: