ParseJar › Security

Hash Generator

Hash text or a file with MD5, SHA-1, SHA-2, SHA-3 and Keccak-256, or compute an HMAC with a secret key. Files are read locally and never uploaded.

Which hash should I use?

  • SHA-256 is the safe default for checksums, content addressing and signatures.
  • MD5 and SHA-1 are broken for security purposes (collisions can be produced), but are still fine for non-adversarial checksums and legacy systems.
  • Keccak-256 is the variant Ethereum uses. It is not the same as the final SHA3-256 standard, because the padding differs. Both are shown so you can tell them apart.
  • Passwords should never be stored with any of these. Use a slow password hash such as Argon2id, scrypt or bcrypt.

HMAC

HMAC combines a secret key with the message, so only someone with the key can produce or check the tag. Webhook signatures from Stripe, GitHub and Slack are HMAC-SHA256 over the raw request body. Paste the exact body and your signing secret to compare.

FAQ

Why does my hash differ from another tool?

Usually invisible differences in the input: a trailing newline, Windows line endings (CRLF), or a different text encoding. This tool hashes exactly the UTF-8 bytes of the text box.

Are files uploaded?

No. Files are read with the File API and hashed in memory on your device.

ParseJar is free. Its sister project ScrapeMole sells pay-per-call data APIs for AI agents.

Related tools