DevToolPal
EN

SHA-1 Hash Generator

Calculate the SHA-1 hash of any text, line by line if needed. Hex or Base64 output, computed in your browser.

Runs locally, never uploaded

Options

Output

Text

0 chars · 0 B

SHA-1 hash

0 chars · 0 B

What it does

This tool calculates the SHA-1 hash of any text. SHA-1 is a cryptographic hash function designed in 1995 by the NSA, published by NIST. It turns input of any length into a fixed 160-bit value, shown as 40 hexadecimal characters. The same input always gives the same hash, and changing a single character changes the hash completely.

How to use

  1. Type or paste text into the input box, drop a text file on it, or press Sample.
  2. The SHA-1 hash appears as you type.
  3. Choose Hex or Base64 output, and turn on Uppercase hex if the system you’re comparing with uses capital letters.
  4. Turn on Hash each line separately to hash a list, such as many passwords or IDs, in one go. Each line gets its own hash on the matching output line.

The text is hashed as UTF-8, exactly as typed, including spaces and line breaks. To hash a file’s contents or use other algorithms, see the general hash generator.

Example

Input:  The quick brown fox jumps over the lazy dog
SHA-1: 2fd4e1c67a2d28fced849ee1bb76e7391b93eb12

Add a period at the end and the hash changes completely. This “avalanche effect” is what makes hashes useful for spotting any change in data.

Where SHA-1 is used

You still meet SHA-1 in Git commit and object IDs, older APIs and webhooks that sign with HMAC-SHA1, TOTP authenticator codes, and file checksums published by older projects. HMAC-SHA1 and TOTP are still considered safe because they do not rely on collision resistance.

Security

SHA-1 is deprecated for security. The SHAttered attack in 2017 produced two different PDFs with the same SHA-1, and attacks have only become cheaper since. Browsers and certificate authorities stopped accepting SHA-1 certificates in 2017. For new work, use SHA-256.

FAQ

› Is my text sent to a server?

No. The SHA-1 hash is computed in your browser, so passwords, keys and private text never leave your device.

› Can a SHA-1 hash be decrypted?

No. SHA-1 is a one-way hash, not encryption. Sites that claim to decrypt it look the value up in tables of hashes of common words, which only works for short or common inputs.

› Why doesn't my SHA-1 match another tool's?

Usually the input differs by invisible characters: a trailing newline (echo adds one, use echo -n), Windows CRLF line endings, a leading space, or a different text encoding. This tool hashes the exact UTF-8 bytes of the text box.

› How long is a SHA-1 hash?

160 bits: 40 hexadecimal characters, or 28 characters in Base64.

› Is SHA-1 secure?

SHA-1 is deprecated for security. The SHAttered attack in 2017 produced two different PDFs with the same SHA-1, and attacks have only become cheaper since. Browsers and certificate authorities stopped accepting SHA-1 certificates in 2017.