mockstack.

Hash Generator

MD5 → SHA-512 ← Developer & Data

MD5, SHA, and CRC32 for text or a file, computed locally.

Input
HMAC Key
Click any digest to copy it.
Verify
READY RUNS LOCALLY

About the Hash Generator

Computes the common hashes for text or a file and checks a published checksum against a download, in your browser. Password Hash makes and checks bcrypt and Argon2id hashes, the slow, salted kind that password storage needs.

Every Setting

Mode
Checksums fingerprints text or a file with CRC32, MD5, and the SHA family. Password Hash turns a password into a bcrypt or Argon2id hash, or checks a password against one.
Choose File
In the rail: hashes a file’s real bytes, streamed with a progress bar so a big download does not freeze the page. Typing in the box afterward switches back to hashing the text.
Show As
Hex is the form download pages publish; Base64 is what some APIs and headers want. Same digest, two spellings.
Input
The text being hashed, live on every keystroke. Clear resets the page.
HMAC Key
Fill it and the SHA rows become keyed fingerprints, the form APIs use to sign requests. Leave it empty for plain hashes.
The Algorithm Rows
CRC32 is a quick integrity check, not security. MD5 and SHA-1 are labeled broken: fine for spotting corruption, never for security. SHA-256 is the modern default; SHA-384 and SHA-512 are its longer siblings. Click any digest to copy it.
Verify
Paste the digest a download page published and it is compared against your file or text, ignoring case and spacing, with a plain match or no-match verdict.
Algorithm
Password Hash only. bcrypt is the long-standing choice that nearly every framework reads. Argon2id is the newer recommendation, harder to attack with graphics cards because each guess needs a block of memory.
Cost
bcrypt’s work factor, from 4 to 14. Each step doubles the time a hash takes, for you and for anyone guessing. 10 is a common default and 12 a cautious one.
Memory, Passes, and Lanes
Argon2id’s settings: how much memory each hash uses, how many times it runs over it, and how many lanes run side by side. They start at 19 MiB, 2, and 1, the OWASP minimum, and are written into the hash so a checker knows them.
Hash Password
Makes the hash with a new random salt and shows how long it took. Click the hash to copy it. bcrypt reads at most 72 bytes of a password and says so if yours is longer.
Check a Hash
Paste a bcrypt hash ($2a$, $2b$, or $2y$) or an Argon2 hash and it is tested against the password above, with a plain match or no-match answer.
Cheat Sheet
The drawer summarizes each algorithm’s size and standing, and what passwords actually need instead.

Common Questions

How do I verify a download?
Choose the file, paste the published checksum into Verify, and read the verdict.
Can I store passwords as SHA-256?
No. The checksums are fast by design, which is what makes guessing cheap. Use Password Hash: bcrypt and Argon2id are slow and salted on purpose.
Why does the same password give a different hash each time?
Each hash gets a new random salt, stored inside the hash itself. That is how two users with the same password end up with different hashes, and why checking works by testing the password against the hash, not by comparing hashes.

Related: Base64 and URL Encoder, JWT Decoder.