What a hash function does
A cryptographic hash function turns any input, from one letter to a multi-gigabyte file, into a fixed-length fingerprint. SHA-256 always produces 256 bits, shown as 64 hexadecimal characters. The same input always gives the same hash, but changing even one character changes the output completely, and it is not feasible to work backwards from the hash to the original data. These properties make hashes useful for verifying downloads, detecting changes, identifying files and building other security tools.
Checking a download
Software projects often publish the SHA-256 value for their installers. After downloading, pick the file here and compare the result with the published one. If they match exactly, the file is the same as the one the publisher hashed. If they differ, the download is corrupted or has been altered. The comparison is only meaningful if you obtained the published hash from a trustworthy source, separate from the download itself.
Which algorithm to choose
- SHA-256: the current general-purpose choice. It is widely supported and considered secure.
- SHA-384 and SHA-512: longer members of the same SHA-2 family, sometimes required by specifications.
- SHA-1: considered broken for security purposes because researchers have produced collisions. It remains in older systems and Git object names, but do not use it to protect anything.
MD5 is deliberately not offered because it is broken and the browser's secure hashing interface does not support it.
Do not hash passwords this way
A plain SHA-256 hash is fast, which is exactly wrong for storing passwords: attackers can test billions of guesses per second. Password storage needs a slow, salted algorithm such as bcrypt, scrypt or Argon2. Use this tool for integrity checks and fingerprints, not for password databases.
How it works here
Hashing uses the Web Crypto API built into your browser, so there is no library to download and the data never leaves your device. Text is converted to UTF-8 before hashing, which matches how most command-line tools such as sha256sum treat text, provided you take care with trailing newlines. Typing "hello world" without a newline gives b94d27b9…, while echo adds a newline and changes the result. The page needs a secure (https) context for the browser to allow hashing.