UtilityToolsLab

© 2026 UtilityToolsLab. Built and maintained by the UtilityToolsLab Team.

Free eBooks·About·Changelog·Privacy Policy·Terms of Service·Report a bug
HomeHashing & ChecksumsSHA-256 Generator

Related Tools

SHA-256 Hash Generator

Generate SHA-256 hashes from text or raw hex bytes, with hex, Base64 and Base64URL output. Updates live as you type. All client-side via Web Crypto API.

You Might Also Like

All Hashing & Checksums

Case Converter

Convert text between UPPERCASE, lowercase, Title Case, Sentence case, camelCase, PascalCase, snake_case, and kebab-case.

Lorem Ipsum

Placeholder text in 20 languages — English, Bengali, Hindi, Arabic, Spanish, French, Chinese and more. Paragraphs, sentences, words, lists, optional emoji.

English Lorem Ipsum

Generate free English Lorem Ipsum dummy text for web design, layouts, and mockups. Classic Latin filler text in paragraphs, sentences, words, or lists.

Bangla Lorem Ipsum

Generate free Bangla (Bengali) Lorem Ipsum dummy text for web layouts and mockups. Bengali script filler in paragraphs, sentences, words, or lists.

SHA-256 is the hash function that signs Git commits, verifies npm packages, protects passwords inside bcrypt and Argon2 wrappers, and sits at the core of every TLS certificate chain. This generator computes it from any text or hex input directly in your browser using the built-in Web Crypto API. No server, no network request, no upload.

The hash updates as you type. Switch the output format between 64-character lowercase hex, 44-character Base64 or 43-character Base64URL in one click. Switch the input mode from text to hex bytes to hash a binary value rather than a UTF-8 string.

Worked Example: a Sentence Hash

The page opens with a real sentence already in the input so you see the output immediately. Changing a single character, even just the capitalisation of one letter, produces a completely different 32-byte output. That avalanche effect is SHA-256's most important property. Press Load Sample to cycle through different sentences and watch every hash change with each one. Press Hex bytes mode and paste 48656c6c6f to hash the raw bytes for the ASCII string “Hello” directly and confirm the result matches known test vectors.

What Each Option Controls

  • Text mode encodes the input as UTF-8 before hashing. Every character outside ASCII adds more than one byte (é is 2 bytes, 中 is 3), so the byte count shown below the textarea can exceed the character count.
  • Hex bytes mode decodes your input as a hex string before hashing. Spaces between pairs are ignored. An odd number of hex digits or a non-hex character shows the message “Invalid hex input — only 0-9 and a-f characters allowed, even number of digits.”
  • Hex output is 64 lowercase characters, the format used in Git object IDs and certificate fingerprints.
  • Base64 is 44 characters including a trailing = pad, used in Authorization headers and JSON Web Tokens.
  • Base64URL is 43 characters with + replaced by - and / by _, with no padding. Safe for URLs and JWT signatures without percent-encoding.

Accuracy and What SHA-256 Cannot Do

The digest is computed by crypto.subtle.digest, the same implementation your browser uses for TLS. SHA-256 produces exactly 32 bytes (256 bits) regardless of input size, from an empty string to a gigabyte of data. The empty-string hash is always e3b0c44298fc1c149afbf4c8996fb924...; if you clear the input the tool shows nothing rather than hashing an empty string silently.

SHA-256 is a one-way function: you cannot reverse a hash back to its input. This tool does not attempt that. If you need to verify a password against a stored hash, use a proper bcrypt or Argon2 library. Plain SHA-256 without a salt is not a password storage format.

Mode:

63 bytes UTF-8

Output format: