A hash function takes input of any length and produces a fixed-length "fingerprint" of it - the same input always produces the same output, but there is no way to reverse the output back into the input. This guide covers what each algorithm this tool supports is actually for, with a verified worked example.
On this page
What a hash is (and is not)
- Deterministic: hashing the same input twice always gives the same output.
- Fixed-length output: MD5 always outputs 128 bits (32 hex characters) regardless of whether the input is 3 bytes or 3 gigabytes; SHA-256 always outputs 256 bits (64 hex characters).
- One-way: there is no algorithm to recover the original input from the hash alone - the only general approach is guessing inputs and re-hashing them to see if they match.
- Avalanche effect: changing a single character of the input produces a completely different-looking hash, not a similar one.
Worked example: hashing the same input four ways
Input text: "Formatiq makes dev tools fast." - hashed with each algorithm this tool supports (values computed and verified independently, not just illustrative):
| Algorithm | Output length | Hash (hex) |
|---|---|---|
| MD5 | 128 bits / 32 hex chars | 74f0b219b39d4786a14012a3c35cb271 |
| SHA-1 | 160 bits / 40 hex chars | 4507be762d492b705741022e4b9e8d894ef97468 |
| SHA-256 | 256 bits / 64 hex chars | a294309c79ea10cdbc9bda5438c672fee7a14a792f7bed8f02a3e42bef774393 |
| SHA-512 | 512 bits / 128 hex chars | ec3abdd29774c4c2dc2b82ec5d11f844530e3508d11a0c27b63157294506ea867a2dcddd33afaef3e2b7d560e264b41c044274e1b72a3180bb6e634919e22ee7 |
Which algorithm to use
| Algorithm | Status | Use it for |
|---|---|---|
| MD5 | Broken for security use (collisions are practical to engineer) | Non-security checksums only - e.g. quickly checking if a downloaded file matches a known-good copy |
| SHA-1 | Broken for security use (collisions demonstrated in practice since 2017) | Legacy compatibility only (e.g. git object ids) - do not use for new security-sensitive work |
| SHA-256 | Currently considered secure | General-purpose integrity checks, digital signatures, blockchain, most new applications |
| SHA-512 | Currently considered secure | Same use cases as SHA-256, with a larger output; can be faster on 64-bit hardware |
Frequently asked questions
MD5 and SHA-1 are still common for non-security checksums like verifying a download completed without corruption or generating a quick cache key, since they’re fast and short. SHA-256 is the current standard for security-sensitive integrity checks, digital signatures, and blockchain applications. SHA-512 offers a larger output and is used where a longer digest is preferred, such as some password-hashing schemes and high-assurance protocols.
No - both have known collision vulnerabilities (researchers can construct two different inputs that produce the same hash), which makes them unsuitable for digital signatures, password storage, or any use case where an attacker might try to forge content that matches a given hash. They remain fine for non-adversarial purposes like checksums, but SHA-256 or SHA-512 should be used wherever security matters.
Hash functions are deterministic - they always produce identical output for identical input, and even a one-character change in the input produces a completely different hash. That determinism is exactly what makes hashes useful for verifying that two files or messages are byte-for-byte the same without comparing their full contents.