Skip to content
Case Converter Online
en

MD5 Hash Generator

Create the MD5 hash of any text or file, along with SHA-1, SHA-256 and SHA-512. Paste a known checksum to check that a download is intact.

Hash a

Text is hashed as UTF-8, exactly as typed. A trailing space or new line changes the hash.

Hashes

  • MD5
     
  • SHA-1
     
  • SHA-256
     
  • SHA-512
     

Paste a checksum to check a download or a copy of a file.

MD5 is fine for checksums and spotting changed files. It is not safe for passwords or signatures, because collisions can be made on purpose. Use SHA-256 or better for security.

What an MD5 hash is

MD5 is a hash function. It takes any input, from one letter to a large file, and produces a fixed-size fingerprint of 128 bits, usually written as 32 hex characters. The same input always gives the same hash. A tiny change, even one character, gives a completely different hash.

Ron Rivest published MD5 in 1992. It is still common for checksums on download pages, for spotting duplicate files, for cache keys and for quick change detection. It is no longer considered secure, which this page covers below.

How to use the MD5 generator

Hash text. Under Hash a, keep Text selected and type or paste into the box. The hashes update as you type. Text is hashed as UTF-8, exactly as entered, including spaces and line breaks.

Hash a file. Press File and choose a file of up to 500 MB. The file is read on your device. The file name and its size in bytes are shown when the hashes are ready.

Read the results. The Hashes panel shows four results:

  • MD5, highlighted, 32 hex characters
  • SHA-1, 40 characters
  • SHA-256, 64 characters
  • SHA-512, 128 characters

Each has its own Copy button. Press Uppercase if you need capital letters.

Compare with a known hash. Paste a checksum from a download page into this field. The tool checks it against all four results and tells you which one matches. If nothing matches, it uses the length of your hash to tell you which algorithm it looks like.

How MD5 works

MD5 pads the input to a multiple of 512 bits and processes it in blocks. Each block passes through 64 rounds of bit mixing that combine additions, rotations and logical operations. The final state of four 32-bit words is the hash. Because so much mixing happens, the output looks random and changes completely when any input bit changes. This is called the avalanche effect.

Examples

Input MD5
(empty) d41d8cd98f00b204e9800998ecf8427e
abc 900150983cd24fb0d6963f7d28e17f72
hello 5d41402abc4b2a76b9719d911017c592
Hello 8b1a9953c4611296a827abf8c47804d7
Hello, World! 65a8e27d8879283831b664bd8b7f0ad4
The quick brown fox jumps over the lazy dog 9e107d9d372bb6826bd81d3542a419d6
The quick brown fox jumps over the lazy dog. e4d909c290d0fb1ca068ffaddf22cbd0

The last two rows differ by one full stop, yet the hashes share nothing.

The same input, abc, with the other algorithms:

Algorithm Hash of abc
SHA-1 a9993e364706816aba3e25717850c26c9cd0d89d
SHA-256 ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad

Security: what MD5 is and is not good for

Fine: checking that a file arrived without corruption, finding duplicate files, building cache keys, and non-security IDs.

Not fine: passwords, digital signatures, certificates, or proving that a file has not been changed by someone trying to fool you. Practical collision attacks against MD5 have been public since 2004. Attackers can craft two different files with the same MD5.

Passwords need a slow hash. Even SHA-256 is too fast for passwords. Use bcrypt, scrypt or Argon2, which are designed to slow down guessing. A plain MD5 password hash such as 5f4dcc3b5aa765d61d8327deb882cf99 (the word “password”) is recognised at once by any lookup site.

Other ways to get an MD5 hash

Linux. md5sum file.zip prints the hash and file name. echo -n hello | md5sum hashes text. Leave out -n and the new line is hashed too.

macOS. md5 file.zip, or md5 -s hello for text.

Windows. certutil -hashfile file.zip MD5 in Command Prompt, or Get-FileHash file.zip -Algorithm MD5 in PowerShell.

Python. hashlib.md5(b'hello').hexdigest() returns 5d41402abc4b2a76b9719d911017c592.

Node.js. require('crypto').createHash('md5').update('hello').digest('hex') gives the same value.

Need a password rather than a hash? Use the strong password generator. For unique IDs, the UUID generator is a better fit than hashing random data. To encode binary data as text, see Base64 encode and decode.

MD5 Generator: questions and answers

Can an MD5 hash be decrypted?

No. A hash is a one-way fingerprint, not encryption, so there is nothing to decrypt. Sites that claim to reverse MD5 only look the hash up in huge lists of hashes of common words and leaked passwords. That is exactly why MD5 must not be used to store passwords.

Is MD5 safe to use?

For checking that a file was copied or downloaded without damage, yes. For anything an attacker might target, no. Researchers can create two different files with the same MD5, and plain MD5 password hashes are cracked very quickly. Use SHA-256 for integrity checks that matter, and a slow password hash such as bcrypt, scrypt or Argon2 for passwords.

Why is my MD5 different from another tool's?

Hashes change completely with the smallest change in input. The usual causes are a trailing space or new line, different capital letters, or text saved in another encoding. The MD5 of hello is 5d41402abc4b2a76b9719d911017c592, but hello with one space after it is f814893777bcc2295fff05f00e508da6.

How do I verify a downloaded file?

Choose File under Hash a, pick the downloaded file, and paste the checksum from the publisher into Compare with a known hash. The tool tells you whether it matches the MD5, SHA-1, SHA-256 or SHA-512 of your file.

Are my files uploaded?

No. Text and files are hashed inside your browser. MD5 is computed with a JavaScript library and the SHA hashes with the Web Crypto API built into your browser.

More code and data tools

See all tools