What it does
This tool calculates the SHA-256 hash of any text. SHA-256 is a cryptographic hash function designed in 2001 by the NSA, published by NIST as part of SHA-2. It turns input of any length into a fixed 256-bit value, shown as 64 hexadecimal characters. The same input always gives the same hash, and changing a single character changes the hash completely.
How to use
- Type or paste text into the input box, drop a text file on it, or press Sample.
- The SHA-256 hash appears as you type.
- Choose Hex or Base64 output, and turn on Uppercase hex if the system you’re comparing with uses capital letters.
- Turn on Hash each line separately to hash a list, such as many passwords or IDs, in one go. Each line gets its own hash on the matching output line.
The text is hashed as UTF-8, exactly as typed, including spaces and line breaks. To hash a file’s contents or use other algorithms, see the general hash generator.
Example
Input: The quick brown fox jumps over the lazy dog
SHA-256: d7a8fbb307d7809469ca9abcb0082e4f8d5651e46d3cdb762d02d0bf37c9e592
Add a period at the end and the hash changes completely. This “avalanche effect” is what makes hashes useful for spotting any change in data.
Where SHA-256 is used
SHA-256 is used for TLS certificates, code signing, software download checksums, Subresource Integrity (SRI) hashes, Bitcoin, Docker image digests, JWTs signed with HS256 or RS256, and API request signing such as AWS Signature V4.
Security
SHA-256 is secure. No practical collision or preimage attack is known, and it is the default hash for most modern security protocols. For passwords, still use a slow password hash such as bcrypt, scrypt or Argon2: SHA-256 is fast, which makes guessing cheap.
FAQ
› Is my text sent to a server?
No. The SHA-256 hash is computed in your browser, so passwords, keys and private text never leave your device.
› Can a SHA-256 hash be decrypted?
No. SHA-256 is a one-way hash, not encryption. Sites that claim to decrypt it look the value up in tables of hashes of common words, which only works for short or common inputs.
› Why doesn't my SHA-256 match another tool's?
Usually the input differs by invisible characters: a trailing newline (echo adds one, use echo -n), Windows CRLF line endings, a leading space, or a different text encoding. This tool hashes the exact UTF-8 bytes of the text box.
› How long is a SHA-256 hash?
256 bits: 64 hexadecimal characters, or 44 characters in Base64.
› Is SHA-256 secure?
SHA-256 is secure. No practical collision or preimage attack is known, and it is the default hash for most modern security protocols.