Skip to main contentSkip to calculator
108 calculatorsLive resultsStep-by-step solutions

Rechnerpilot tool

Hash Generator

Calculate SHA-256, SHA-384 or SHA-512 locally and output the digest as hex or Base64.

Developer Tools
SHA-256 · Hex
—

Empty input

Explanation

How Hash Generator works

The hash generator calculates cryptographic checksums for arbitrary texts directly in the browser. The entered text is encoded as UTF-8 and processed by the selected SHA algorithm.

SHA-256 is the most common algorithm and produces a 256-bit hash (64 hex characters). SHA-384 produces 96 hex characters, SHA-512 produces 128 hex characters. These algorithms belong to the SHA-2 family, standardised by NIST in FIPS 180-4.

Hex and standard Base64 represent the same digest bytes. Base64 is more compact but may contain +, / and padding and is not automatically URL-safe.

Common mistakes

  • Confusing hashing with encryption: A hash is not a reversible plaintext representation. Encryption serves a different purpose and is reversible with the right key.
  • Using MD5 or SHA-1 for security purposes: Both algorithms have known collision attacks and are considered insecure according to BSI TR-02102-1.
  • Using SHA hashes for password storage: Simple SHA hashes can be computed too fast. Use bcrypt, scrypt or Argon2 with a salt and work factor.
  • Interpreting hash equality as identity: Equal hashes mean equal input with extremely high probability, but not with absolute certainty (theoretical possibility of collision).

Limits of this tool

  • No salting function — unsuitable for password storage.
  • Text input only, no files (use dedicated tools for file hashes).
  • No HMAC mode (keyed hashing) — only simple hash calculation.
  • No verification against known hash values integrated.
  • Whitespace, line breaks and Unicode normalization are not unified but hashed as part of the UTF-8 input.

Sources

  • BSI TR-02102-1: Cryptographic mechanisms — recommendations and key lengths. German Federal Office for Information Security.
  • NIST FIPS 180-4: Secure Hash Standard (SHS). Defines SHA-256, SHA-384, SHA-512.
  • RFC 1321: MD5 Message-Digest Algorithm (historical, not recommended for security).
  • Web Crypto API: W3C standard for cryptographic operations in the browser (crypto.subtle.digest).

Practice

Practical examples

SHA-256 for text

Calculate the SHA-256 hash for a short test text in hex format.

SHA-512 as Base64

Use Base64 if a target system does not expect hex output.

Empty input

Even the empty input has a defined hash value.

FAQ

Frequently asked questions

Is the text sent to a server?

No. The hash is calculated locally in the browser with the Web Crypto API. The entered text does not leave the device.

Which algorithms are available?

SHA-256, SHA-384 and SHA-512. MD5 and SHA-1 are not offered because they are considered broken for security purposes (BSI TR-02102-1).

Should I hash passwords here?

No. Simple SHA hashes are not suitable for password storage. Use specialised password-hashing methods such as bcrypt, scrypt or Argon2, which use a salt and work factor.

What is the difference between hashing and encryption?

Hashing is a deterministic one-way mapping — the hash is not a reversible plaintext representation. Encryption is reversible with the right key.

Why does the hash change completely on a minimal input change?

This is the avalanche effect of cryptographic hash functions. A single changed bit in the input changes on average half of all bits in the hash.

What is SHA-256 used for in practice?

SHA-256 is used for integrity checks of downloads, digital signatures, certificates (TLS/SSL), blockchain technology and HMAC-based authentication.

Can the original text be recovered from a SHA hash?

Not regularly. For short or predictable inputs, candidates can be tried and hash values compared. That is why password storage needs a suitable password hash function with a salt and cost factor.

What is the difference between hex and Base64 output?

Hex uses 0-9 and a-f and represents each digest byte with two characters. Standard Base64 is more compact but can contain +, / and padding and is not automatically URL-safe.

Why does the generator not offer MD5 or SHA-1?

MD5 (RFC 1321) and SHA-1 are considered cryptographically broken. Practical collision attacks exist. BSI and NIST recommend at least SHA-256 for security-relevant applications.

Is SHA-512 more secure than SHA-256?

SHA-512 produces a longer digest than SHA-256. Which function is appropriate depends on the protocol and its standard; the digest length alone is not a blanket security clearance.

Tips

Good to know

  • Choose the algorithm to match the given protocol or reference value.
  • The hash changes completely if even a single character is different.
  • Hex is longer but more readable — Base64 is more compact.

Related calculators

More tools