What it does
This tool calculates the SHA-1 hash of any text. SHA-1 is a cryptographic hash function designed in 1995 by the NSA, published by NIST. It turns input of any length into a fixed 160-bit value, shown as 40 hexadecimal characters. The same input always gives the same hash, and changing a single character changes the hash completely.
How to use
- Type or paste text into the input box, drop a text file on it, or press Sample.
- The SHA-1 hash appears as you type.
- Choose Hex or Base64 output, and turn on Uppercase hex if the system you’re comparing with uses capital letters.
- Turn on Hash each line separately to hash a list, such as many passwords or IDs, in one go. Each line gets its own hash on the matching output line.
The text is hashed as UTF-8, exactly as typed, including spaces and line breaks. To hash a file’s contents or use other algorithms, see the general hash generator.
Example
Input: The quick brown fox jumps over the lazy dog
SHA-1: 2fd4e1c67a2d28fced849ee1bb76e7391b93eb12
Add a period at the end and the hash changes completely. This “avalanche effect” is what makes hashes useful for spotting any change in data.
Where SHA-1 is used
You still meet SHA-1 in Git commit and object IDs, older APIs and webhooks that sign with HMAC-SHA1, TOTP authenticator codes, and file checksums published by older projects. HMAC-SHA1 and TOTP are still considered safe because they do not rely on collision resistance.
Security
SHA-1 is deprecated for security. The SHAttered attack in 2017 produced two different PDFs with the same SHA-1, and attacks have only become cheaper since. Browsers and certificate authorities stopped accepting SHA-1 certificates in 2017. For new work, use SHA-256.
FAQ
› Is my text sent to a server?
No. The SHA-1 hash is computed in your browser, so passwords, keys and private text never leave your device.
› Can a SHA-1 hash be decrypted?
No. SHA-1 is a one-way hash, not encryption. Sites that claim to decrypt it look the value up in tables of hashes of common words, which only works for short or common inputs.
› Why doesn't my SHA-1 match another tool's?
Usually the input differs by invisible characters: a trailing newline (echo adds one, use echo -n), Windows CRLF line endings, a leading space, or a different text encoding. This tool hashes the exact UTF-8 bytes of the text box.
› How long is a SHA-1 hash?
160 bits: 40 hexadecimal characters, or 28 characters in Base64.
› Is SHA-1 secure?
SHA-1 is deprecated for security. The SHAttered attack in 2017 produced two different PDFs with the same SHA-1, and attacks have only become cheaper since. Browsers and certificate authorities stopped accepting SHA-1 certificates in 2017.