SHA2 Hash Generator

Paste text and get its SHA-224 hash, a 56-character hex digest from the SHA-2 family, with an optional salt appended before hashing.

The SHA2 Hash Generator computes the SHA-224 digest of whatever text you paste. SHA-224 is a member of the SHA-2 family, and its output is a 56-character hexadecimal string that appears on a card with a copy button. You can optionally append a salt: the page fills the salt field with a fresh random 16-byte hex value on every load, and ticking Include salt hashes your text with that value added to the end. The hash is computed in your browser; the text never leaves the page.

How to use it

  • Text: paste any string. Whitespace and line breaks count, so "abc" and "abc " produce different hashes.
  • Include salt: off by default. Tick it and the hash is computed over text + salt, in that order, with no separator.
  • Salt value: pre-filled with a random 32-hex-character string (16 bytes). Replace it with your own if you are reproducing a hash from another system. The field must not be empty, even when the checkbox is off.

The same text with the same salt always gives the same hash, so you can verify a value someone else produced as long as they also concatenated text then salt. Note that this is plain concatenation, not HMAC; if a system uses HMAC-SHA224 with a key, the results will not match.

SHA-224 and the SHA-2 family

SHA-2 is not one algorithm but six, published by NIST: SHA-224, SHA-256, SHA-384, SHA-512, SHA-512/224 and SHA-512/256. The number is the digest length in bits. SHA-224 runs the same compression function as SHA-256 with different starting values and drops the last 32 bits of the result, which is why its output is 56 hex characters rather than 64. It exists mostly for systems that need a digest sized to match 112-bit security levels (Triple DES key sizes, older TLS cipher suites). In day-to-day work you will see SHA-256 far more often, and for that use the SHA256 Hash Generator; for the 128-character digest use the SHA512 Hash Generator.

A known test vector, useful for checking the tool: the SHA-224 of the three letters abc (no salt) is 23097d223405d8228642a477bda255b32aadbce4bda0b3f7e36c9da7.

All SHA-2 variants are one-way. You cannot recover the text from the hash, and changing a single character in the input changes roughly half the bits of the output. That makes them right for checksums, integrity verification and signatures. They are fast by design, which makes them wrong for storing passwords directly; use bcrypt, scrypt or Argon2 for that, and treat the salt option here as a way to reproduce a legacy scheme, not as a recommendation.

Typical uses

  • Verifying a value from another system. A colleague says a field was hashed with SHA-224 and a known salt; paste both here and compare.
  • Generating fixed test fixtures. Hash a few strings to seed a test that checks hashing code, with the vector above as a sanity check.
  • Comparing two texts without sharing them. Each side hashes their copy; if the digests match, the texts are identical to the byte.
  • Learning the differences between hashes. Hash the same input with this page, the SHA1 Hash Generator (40 characters, deprecated) and the MD5 Hash Generator (32 characters, broken for security) to see the output sizes side by side.

For encoding rather than hashing, when you need to get text back out, use the Base64 Generator. All of these are listed under all developer & test data tools.

Frequently asked questions

Which SHA-2 variant does this page use?

SHA-224 only. The output is always 56 hexadecimal characters (224 bits). If you need SHA-256 or SHA-512, this site has separate pages for each.

Can I decrypt a SHA2 hash back to the text?

No. SHA-2 hashes are one-way. The only way to find an input is to guess candidates and hash each one, which is why short or common inputs are recoverable by lookup tables and long random ones are not.

How is the salt applied?

It is appended to your text (text then salt, no separator) before hashing. It is not HMAC. To reproduce a hash from another system, paste that system's salt into the field and tick Include salt.

Is it safe to hash a password here?

The hash is computed in your browser and nothing is uploaded. But a bare SHA-224, salted or not, is not how passwords should be stored; use a slow password hash such as bcrypt or Argon2 in real systems.