Skip to content
G3getByteRush

Hash Generator

MD5, SHA-1, SHA-256, SHA-384, SHA-512, and HMAC for text or files.

MD5
—
SHA-1
—
SHA-256
—
SHA-384
—
SHA-512
—

100% client-side — your data is processed in this browser tab and never uploaded anywhere.

Advertisement
Advertisement

How to use this tool

  1. Choose Text or File as your input.
  2. Type text, or select a file — MD5, SHA-1, SHA-256, SHA-384, and SHA-512 all compute automatically.
  3. Check "HMAC" and enter a secret key if you need a keyed hash instead of a plain one.
  4. Copy any result with its copy button.

Common mistakes to avoid

  • When verifying a download, compare against the exact algorithm the publisher provided — a matching SHA-256 doesn't confirm a SHA-512 checksum, and vice versa.

Why hash files in the browser instead of uploading them?

Hashing is often used to verify a file hasn't been tampered with — which only means something if the file never touched a third party in between. This tool uses the Web Crypto API'scrypto.subtle.digest, so the file is read and hashed entirely on your device.

Frequently asked questions

Should I use MD5 or SHA-1 for anything security-related?
No — both are cryptographically broken and unsuitable for passwords, signatures, or anything where an attacker being able to find a collision matters. They're offered here for their remaining legitimate uses: matching a checksum a vendor already published in one of these formats, cache-busting keys, or legacy system compatibility. For anything new, use SHA-256 or higher.
What is HMAC and when would I need it?
HMAC combines a hash with a secret key, so the result depends on both the message and the key — useful for verifying a message came from someone who knows the key (e.g. validating a webhook payload against a signing secret), which a plain hash can't do.
Can I hash a file, not just text?
Yes — switch to the File tab and choose a file. It's hashed directly from its bytes, useful for verifying a download matches a published checksum.
Is the file uploaded to check the hash?
No — the file never leaves your device. SHA-1/256/384/512 use the browser's own crypto.subtle.digest; MD5 runs through a local implementation, since it isn't in that API.
Why do all the hashes update as I type?
Every algorithm is computed together so you don't have to re-run the tool if you need a different one.

How GetByteRush compares

Most free tools for this online work the same way: you upload your file to their server, wait, then download the result — which means your file (and often your email, for a "free" account) sits on someone else's infrastructure. Here's the actual difference:

FeatureGetByteRushTypical online hash generators
File ever leaves your deviceNo — 100% client-sideOften yes — uploaded to compute the hash
Algorithms offeredMD5, SHA-1, SHA-256, SHA-384, SHA-512, plus HMACOften a narrower set, and rarely HMAC
File size limitNone imposed by us (device-memory bound)Often capped on free tiers

("Typical online tools" reflects publicly documented behavior of common free file-processing sites as of 2026 — always check a specific competitor's own privacy policy and pricing page, since these details change.)