๐Ÿ› ๏ธ Developer ยท Updated October 8, 2026 ยท 7 min read

Generate MD5 and SHA-256 Hashes to Verify Files and HMAC

Any input Fixed digest ๐Ÿ”’

To generate an MD5 or SHA-256 hash, type or paste text into the GrabCast Hash Generator and six digests appear instantly: MD5, SHA-1, SHA-256, SHA-384, SHA-512 and CRC32. Switch to the Files tab to fingerprint downloads up to 2 GB each, paste a published checksum to see a green match, or turn on HMAC to reproduce a webhook signature. Files are read on your own device and never uploaded.

๐Ÿ”’ Try Hash Generator now โ€” freeOpen โ†’
Hash Generator Files tab with invoice.pdf hashed and a green Match - invoice.pdf - SHA-256 line above the digests
A verified file checksum.
๐Ÿ’ก Why checksums still matter

A checksum is a short fingerprint of data. Change one byte of a 4 GB installer and its SHA-256 value changes completely, which is why software vendors, Linux distributions and backup tools publish them. Comparing the value you compute against the published one proves the file you downloaded is the file they built, and not a truncated transfer or a tampered copy from a mirror. The same math powers webhook signatures from services like GitHub, where a shared secret turns a plain digest into an HMAC that proves who sent a request.

Six hash algorithms at once, and which one to trust

Every keystroke in the Text tab recomputes all six values, encoded as UTF-8 so accented letters and emoji match what other tools produce. You can switch the output between lowercase hex, uppercase HEX and Base64.

The tool itself shows a reminder under the results: for passwords, none of these are appropriate. Store passwords with a slow key derivation function such as bcrypt or Argon2.

Verify a download against a published checksum

Open the Files tab and drop one file or a whole batch. Each file shows its size and a Reading, then Hashing progress line, followed by all six digests. Now paste the vendor checksum into the expected field. The matching row turns green and the status line names the file and algorithm. If nothing matches, the tool reports the length of what you pasted and guesses the algorithm, for example 64 characters looks like SHA-256, so you know whether you compared the right kind of value.

The expected field is forgiving. It ignores case, strips a leading label such as the algorithm name followed by a colon or equals sign, and takes only the first word of the line, so you can paste a whole line from a SHA256SUMS file including the filename. With Base64 output selected and a hex value pasted, it asks you to switch the output back to hex.

Honest limit: the file is read into browser memory before hashing, so a 2 GB file needs that much free RAM. On an older phone, very large files may fail with a clear message rather than a wrong result.

Checksum files and CSV exports for batches

After hashing several files, choose an algorithm and download a checksum file in the same two-space format that sha256sum and md5sum write, named after the algorithm you picked. Anyone can then check the whole batch on Linux with the -c option of sha256sum. A CSV export lists every file, algorithm and value, which is handy for audit trails or a spreadsheet of archived deliverables.

These commands and the browser tool should produce identical hex strings for the same bytes. If they disagree, the files differ, often because of line ending conversion on text files.

HMAC signatures for webhooks and APIs

Tick HMAC, enter the secret key and every SHA row becomes HMAC-SHA-1, HMAC-SHA-256 and so on, with HMAC-MD5 available for legacy systems. CRC32 shows not available, because it has no keyed version. This is the fastest way to debug a webhook that keeps failing signature checks.

GitHub, for example, sends an X-Hub-Signature-256 header containing the prefix sha256= followed by the HMAC of the raw request body using your webhook secret. Paste the exact raw body into the Text tab, enter the secret, and paste the header value into the expected field; the prefix is stripped for you. A green row means your secret is right and the bug is in how your code reads the body, commonly because a framework parsed and re-serialized the JSON before hashing it.

Only use test secrets or rotate a production secret after debugging with it, as a matter of habit, even though the key never leaves your browser. Treat any secret pasted into a shared screen or recorded call as exposed.

For webhook signatures, you can then inspect the token side with the JWT Decoder, which is another common place HMAC appears.

Step-by-step

1234
1Open the Hash Generator and choose the Text tab for strings or the Files tab for downloads and documents.
Hash Generator with the Files tab selected and an empty drop area reading Drop files here or click to browse
Switch to the Files tab.
2Type, paste or drop your input; all six digests appear, and you can switch the output to hex, HEX or Base64.
invoice.pdf, 0.09 MB, hashed on the device: MD5 6e50a632, SHA-1 e0731cf2, SHA-256 0d2581f2 plus SHA-384, SHA-512 and CRC32 d27c3891
Every digest of the file is computed locally.
3Paste the published checksum or signature into the expected field and look for the green matching row, or read the length hint if nothing matches.
Published SHA-256 checksum pasted into the verify box with a green Match - invoice.pdf - SHA-256 message
Paste the published checksum to verify.
4For batches, download the checksum file or CSV; for webhooks, tick HMAC and enter the secret before comparing.
Checksum file (sha256sum format) and CSV download buttons under the digests, with the menu set to SHA-256
Download a checksum file or CSV for batches.

Common mistakes to avoid

โš ๏ธComparing a SHA-256 checksum against the MD5 row and deciding a good download is corrupted.
โš ๏ธCopying text with an invisible trailing newline or space, which produces a completely different digest from the one you expected.
โš ๏ธUsing plain MD5 or SHA-256 to store user passwords instead of a slow function like bcrypt or Argon2.
โš ๏ธSigning a re-formatted JSON body when debugging a webhook, rather than the exact raw bytes the sender hashed.

Pro tips

โœ“Get checksums from the vendor site over HTTPS, not from the same mirror that served the file, or tampering can go unnoticed.
โœ“Keep a checksums.sha256 file beside long-term archives so you can confirm years later that nothing has silently changed.
โœ“Use CRC32 or MD5 to find duplicate photos or videos quickly, and SHA-256 when the result must stand up to scrutiny.
โœ“When a webhook signature fails, check the secret first with a known sample from the provider docs, then check the body.
โœ“Switch to Base64 output when an API documents its signatures in Base64 rather than hex; the bytes are identical.

Frequently asked questions

Are my files uploaded to generate the hash?

No. Files are read and hashed by JavaScript on your device, which is why a 2 GB file can be checked without waiting for an upload.

Is MD5 safe to use?

For detecting accidental corruption or duplicates, yes. For security, no: MD5 and SHA-1 collisions can be forged, so use SHA-256 or stronger.

Why does my hash not match the one from another tool?

Almost always the input differs, such as a trailing newline, different line endings or a different text encoding. This tool hashes text as UTF-8.

Can I verify a GitHub or Shopify webhook signature?

Yes. Enable HMAC, enter the secret, paste the raw request body and compare with the header. Shopify documents its signature in Base64, so switch the output to Base64 first.

What is the largest file it can handle?

Up to 2 GB per file, limited in practice by free memory on your device. You can drop many files at once and export the results.

๐Ÿ“Œ Bottom line

The GrabCast Hash Generator computes six digests at once, verifies downloads with a green match, exports sha256sum-style files and reproduces HMAC webhook signatures, all on your own device. Use SHA-256 for anything that matters, keep MD5 and CRC32 for quick duplicate checks, and never use either for passwords.

Open Hash Generator โ†’

Related guides

Browse more: all text and developer guides ยท Hash Generator