免费工具

文本哈希(SHA)

使用浏览器内置的加密功能计算任何文本的 SHA-1、SHA-256、SHA-384 或 SHA-512 十六进制摘要。

What the Text Hash (SHA) tool does

A cryptographic hash function takes any input, of any length, and produces a fixed-length "digest" — a compact fingerprint of the data. This tool computes the SHA digest of whatever text you type or paste, offering SHA-1, SHA-256, SHA-384 and SHA-512, and returns the result as a hexadecimal string. You reach for it to verify that two pieces of text are identical without comparing them character by character, to generate a stable fingerprint or identifier for some content, to produce a checksum you can compare against a published one, or to store a representation of data without keeping the plaintext around.

The output length is fixed by the algorithm, no matter how large the input. SHA-1 produces 160 bits, shown as 40 hexadecimal characters. SHA-256 produces 256 bits, or 64 hex characters. SHA-384 gives 96 hex characters and SHA-512 gives 128. A one-character input and a one-megabyte input both yield a digest of exactly that size.

How hashing works, and why it is one-way

Cryptographic hashes have three defining properties. They are deterministic: the same input always produces the same digest, which is what makes them useful for comparison and integrity checks. They exhibit the avalanche effect: changing a single bit of the input produces a completely different, unpredictable output, so hello and hellp share nothing recognisable in their digests. And they are one-way: given a digest there is no practical way to run the function backwards and recover the input. Good hashes are also collision-resistant, meaning it is infeasible to find two different inputs that produce the same digest. This tool computes the digest with the browser's built-in Web Crypto engine (crypto.subtle.digest) over the UTF-8 bytes of your text, so the results match what any standards-compliant server or language library would produce for the same input and algorithm.

Choosing an algorithm matters. SHA-1 is now considered broken for collision resistance and must not be used for digital signatures or certificates, though it remains acceptable for non-adversarial checksums, deduplication and Git-style content identifiers. For anything security-relevant, prefer SHA-256 or stronger. One critical caveat: a bare SHA hash is the wrong tool for storing passwords. Because hashing is fast, an attacker can try billions of guesses per second, so password storage needs a slow, salted key-derivation function such as bcrypt, scrypt, Argon2 or PBKDF2 instead — the same reasoning behind a strong, unique generated password in the first place.

Examples, use cases and gotchas

For instance, the SHA-256 digest of the exact string abc is ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad — a value you can reproduce anywhere and use as a reference. Everyday uses include verifying a downloaded file's checksum against the one the author published, fingerprinting a block of content to detect changes, generating cache keys or ETags, and comparing two records for equality by comparing their digests rather than their full contents.

  • Hashing is not encryption: there is no key and no "decrypt". If you need to recover the original later, hashing is the wrong choice.
  • Digests are exquisitely sensitive to input. A trailing newline, a stray space, or a different character encoding changes the result completely, so hash exactly the bytes you intend to compare.
  • Compare digests case-insensitively; hexadecimal is the same value whether written in upper or lower case.
  • A matching hash proves the content is identical, but on its own it does not prove who produced it — that requires a signature or a keyed HMAC.

Your privacy

Every digest is computed one hundred percent locally, inside your browser, using your device's own cryptographic engine. The text you hash — which might be a secret, a document, or a value you would never want to expose — never leaves your machine, is never transmitted to a server, and is never logged. Nothing is uploaded and nothing is stored once you leave the page. For a tool whose whole purpose is often to handle sensitive material without revealing it, keeping the computation on-device is not just a feature; it is the entire premise.

人们通过搜索找到此页面

此页面回答的真实搜索短语 — 链接的短语打开详细覆盖它们的页面。