MD5 Hash Generator

Paste text, optionally tick Include salt, and press the button to get the 32-character hex MD5 digest with a copy button. Nothing leaves your browser.

Paste or type any text, press Generate MD5 Hash, and you get the 32-character hexadecimal MD5 digest of that exact input, with a copy button. Tick Include salt and the tool hashes your text with the salt appended to the end of it (text + salt). A random 32-character hex salt is filled in when the page loads, and you can replace it with your own. The hash is computed in your browser; the text is never sent to a server.

MD5 is deterministic, so the same input always gives the same hash, here and in every other MD5 tool: "hello" is always 5d41402abc4b2a76b9719d911017c592. That's what makes it useful for checksums and lookups, and also why it's no longer used for passwords.

What you can set

  • Text. Any length, including line breaks. Leading and trailing whitespace is part of the input, and a single changed character produces a completely different hash.
  • Include salt. Off by default. When on, the salt in the field below is concatenated after your text before hashing. There is no option to prepend it or to apply multiple rounds.
  • Salt value. Pre-filled with 16 random bytes as hex. Edit it freely; if you're matching a hash produced elsewhere, paste that system's salt here and check how that system ordered text and salt.

Worked examples

InputMD5
(empty string)d41d8cd98f00b204e9800998ecf8427e
hello5d41402abc4b2a76b9719d911017c592
Hello8b1a9953c4611296a827abf8c47804d7
password5f4dcc3b5aa765d61d8327deb882cf99
The quick brown fox jumps over the lazy dog9e107d9d372bb6826bd81d3542a419d6

The "hello" and "Hello" rows show the avalanche effect: one bit of difference in the input changes about half the bits in the output. The empty-string hash is worth recognizing, since it shows up in logs whenever a program hashes a missing value by mistake.

What MD5 is good for now

MD5 was published by Ron Rivest in 1992 and produces a 128-bit digest. Collisions (two different inputs with the same hash) have been cheap to manufacture since 2004, and preimage attacks on password hashes are practical because MD5 is fast and enormous rainbow tables exist. So: don't use it to store passwords, sign documents or verify downloads against an attacker. It remains fine for jobs where nobody is trying to fool you.

  • Checksums against accidental corruption.Comparing an MD5 before and after a file copy catches truncation and bit flips.
  • Cache keys and deduplication. Hashing a URL or a record to a fixed 32-character key for a cache or a database index.
  • Gravatar and legacy APIs. Gravatar looks up avatars by the MD5 of a lowercased, trimmed email address, and a number of older APIs still sign requests with MD5.
  • Matching old database rows. If a legacy system stored MD5(password + salt), this tool with Include salt reproduces that value for testing a migration.

For anything security-related, use the SHA256 Hash Generator or the SHA512 Hash Generator, which take the same text-plus-optional-salt input, and for passwords use a purpose-built slow hash such as bcrypt or Argon2 rather than any of these. If you need to encode rather than hash (reversibly, for transport), that's the Base64 Generator. The SHA1 Hash Generator covers the other legacy digest you'll still meet in Git and old certificates. All of these are under all developer & test data tools.

Frequently asked questions

Can I decrypt or reverse an MD5 hash?

No. MD5 is a one-way hash, not encryption; there is no key and nothing to decrypt. Online 'MD5 decrypters' are lookup tables of hashes for common strings, which is exactly why MD5 is unsafe for passwords.

Why does my hash not match another tool's?

Usually whitespace or the salt. Check for a trailing newline or space, make sure Include salt is off if the other tool used none, and if it used a salt, confirm whether it went before or after the text. This tool appends it after.

Is my text uploaded anywhere?

No. The hash is calculated in your browser with a JavaScript MD5 implementation. Nothing is sent to a server.

How long is an MD5 hash?

Always 128 bits, shown as 32 hexadecimal characters, regardless of how long the input is.