Skip to content

Hash Generator

Generate MD5, SHA and password hashes like bcrypt and Argon2 - or verify a password against a hash.

FreeRuns in your browserNothing is sent
All hashing happens in your browser (WebAssembly). Nothing you type leaves this page.

Which hash algorithm should you use?

UseRecommendedAvoid
Storing user passwordsArgon2id, bcryptMD5, SHA-1, SHA-256 without a slow KDF
Verifying downloadsSHA-256, SHA-512MD5, SHA-1
Digital signatures, certificatesSHA-256 or strongerSHA-1
Quick non-security checksumsCRC32, MD5, BLAKE2b-

Why password hashes are different

Fast hashes are great for files and terrible for passwords.

A modern GPU computes billions of SHA-256 hashes per second, so a leaked table of SHA-256 passwords falls quickly. bcrypt and Argon2id are slow on purpose and add a random salt to every password.

For new projects, OWASP recommends Argon2id with at least 19 MiB of memory and 2 iterations - the default above. In PHP that is simply password_hash($pw, PASSWORD_ARGON2ID).

Need the hash of a file?

Use the File Hash Checker to compute SHA-256 or MD5 of a download and compare it with the publisher's checksum. To create strong passwords in the first place, use the Password Generator.

Frequently asked questions

Is it safe to hash a real password here?

Yes. Every hash - including bcrypt and Argon2 - is calculated in your browser with WebAssembly. Nothing you type is sent to ScanWith or anywhere else.

Which hash should I use to store passwords?

Use Argon2id or bcrypt. They are deliberately slow and salted, which makes cracking leaked databases expensive. Never store passwords with MD5, SHA-1 or plain SHA-256 - they are built to be fast, which helps attackers.

Why does bcrypt give a different result every time?

bcrypt and Argon2 add a random salt to each hash, so the same password produces a different string each time. To check a password, use the Verify tab - it reads the salt from the stored hash.

Is MD5 still safe?

Not for security. MD5 and SHA-1 have known collision attacks. They are still fine for non-security checksums, such as detecting accidental file corruption, but use SHA-256 or better to verify downloads.

Can a hash be reversed?

No - hashing is one-way. But weak passwords can be found by guessing: attackers hash billions of common passwords and compare. That is why salted, slow hashes and long random passwords matter.