Hash and UUID generator
To verify that a file is intact, generate an ID in an integration, or see which version a UUID you hold is. The calculation uses the browser's own cryptography functions; text, files and generated IDs are not sent to any server.
Text is hashed as UTF-8 bytes. Line endings and trailing whitespace change the result. Input: 0 bytes
Paste the digest the publisher gives; sha256sum output (digest + file name) and a sha256= prefix are stripped. Hex and base64 are accepted.
Text, files and generated IDs never leave your device; the calculation runs in the browser and nothing is stored.
Type some text or choose a file to see the digest.
Things to keep in mind
- A digest shows integrity, not secrecy or identity. Get it through a path separate from the file (the publisher's page); if the file and digest come from the same place an attacker can change both.
- Do not store passwords with SHA-256: fast digests can be brute-forced. For passwords use slow, salted functions such as Argon2, scrypt or bcrypt.
- UUID v7 and ULID contain the creation time; if you want to hide when IDs handed out were created, use v4.
- A UUID or ULID is not access control: being hard to guess does not mean you can leave every record open to whoever knows the address.
The tool produces digests and IDs; it is not a security product or a tool for legal evidence. For very large files use command-line tools (sha256sum, Get-FileHash). The uniqueness of generated IDs is probabilistic; a uniqueness constraint in a single database is still needed.
Looking for a design for ID generation, data integrity and replay-safe flows in your integrations? Let's plan it together.
Request a call01
How to use it
A
For a digest, type text or choose a file, pick the algorithm and paste the digest the publisher gives into the comparison field, if you have one.
B
For IDs, choose the type (UUID v4, UUID v7, ULID), the count and the format and press Generate; copy the list with one click.
C
To see the version, variant and (if present) timestamp of a UUID or ULID you hold, paste it in the validate tab.
02
What is a digest (hash) and what is it for?
A hash function turns data of any length into a fixed-length fingerprint: change one bit of the input and the digest changes completely. That is a cheap way to confirm that a file you downloaded matches the publisher's, that a backup is intact or that two pieces of data are equal.
The tool computes SHA-256, SHA-384 and SHA-512 with the browser's WebCrypto and shows the result as hex and base64. The calculation has been checked against FIPS 180-4 test vectors (e.g. SHA-256 of “abc”: ba7816bf…15ad).
03
Why SHA-1 comes with a warning and MD5 is missing
Collision attacks have been demonstrated for SHA-1 and MD5: two different inputs with the same digest can be produced. That is why they must not be used for signatures, certificates or security-relevant integrity checks. SHA-1 is kept in the tool only for compatibility with legacy systems and is flagged with a warning.
MD5 is not available in the browser's WebCrypto; without adding a new dependency there is no trustworthy implementation, so it is left out on purpose. If the digest you hold is 16 bytes, the tool recognises it as MD5 and warns you.
04
UUID v4, UUID v7 and ULID: which one when?
UUID v4 is fully random; it is the most common choice and does not leak the creation time. Used as a primary key in large tables, records land scattered in the index, which can raise insert cost.
UUID v7 (RFC 9562) and ULID start with a 48-bit millisecond timestamp; they sort by time and are written to the index sequentially. IDs generated in the same millisecond are kept in order by a counter in the tool. The price is that the creation time can be read from the ID.
FAQ
- Is my file uploaded to a server?
- No. The file is read in the browser and the digest is computed on your device; no network request is made. Because the file is loaded into memory in one piece the limit is 50 MB; for larger files use sha256sum (Linux, macOS) or Get-FileHash (PowerShell).
- Why is there no MD5?
- The browser's WebCrypto does not offer MD5 and MD5 is not collision-safe, so we left it out instead of adding a dependency. If your publisher gives only an MD5, know that it does not protect against tampering, only catches accidental corruption, and ask for SHA-256 if you can.
- Can I store passwords with SHA-256?
- No. SHA-256 is fast; a stolen digest table can be cracked at billions of guesses per second. Passwords call for slow, salted functions such as Argon2id, scrypt or bcrypt. This tool is for integrity and equality checks, not for password storage.
- Should I choose UUID v4 or v7?
- v4 if the ID is visible from outside and you do not want to leak the creation time. v7 is usually better where records are written in time order, such as database primary keys or event streams. Both use the same 36-character form, so the column type does not change.
- Are UUIDs really unique?
- Not with certainty, but probabilistically. v4 has 122 random bits; even if you generate billions of IDs the chance of a collision is negligible. A uniqueness constraint in a single table still catches a rare collision at write time.
- What do I do if the digest does not match?
- Check the algorithm and the input first: a trailing newline in text, a different version of the file or an incomplete download are the most common causes. The algorithm is guessed from the length: 64 hex characters mean SHA-256, 128 SHA-512, 40 SHA-1. If it still does not match, download the file again and get the digest through a separate channel.
Let's build your integrations on solid IDs and verifiable data
We design ID generation, data integrity and replay-safe flows between CRM, ERP and logistics systems. Let's talk through your current setup in a free discovery call.