Stateless Tools

When this hash tool is genuinely useful

Check release integrity

Compare SHA values for downloaded files or build outputs to confirm whether two artifacts are actually identical.

Validate signing inputs

Test how whitespace, line breaks, or field ordering change a digest before you wire the same input into a backend signature flow.

Review values locally

Short comparison strings stay in the browser, which is safer than pasting them into random online converters during debugging.

Questions that come up often

Is hashing the same as encryption?

No. Hashing is a one-way digest used for comparison or integrity checks, while encryption is designed for later decryption.

Should I use SHA-256 or SHA-512?

SHA-256 is usually the practical default for integrity checks. Use SHA-512 when your policy, ecosystem, or output-length requirements call for it.

Does the page upload my input?

The digest is computed with the browser Web Crypto API. You should still account for extensions, device security, and your own operating environment.

Using hashes

SHA-1 is out for security use

Collisions in SHA-1 can be constructed deliberately, so it is unsuitable for signatures or authentication. It remains fine for checking transfer corruption. Use SHA-256 or stronger where security matters.

Do not store passwords with SHA

SHA is designed to be fast, which helps bulk guessing. Password storage needs a deliberately slow function such as bcrypt, scrypt or Argon2. An unsalted SHA table, once leaked, is largely recoverable with rainbow tables.

Equal hashes mean equal files, not the reverse

Matching hashes effectively mean identical content, but a single differing byte changes the hash entirely. How much changed cannot be read from a hash — that needs a diff tool.