SHA256 Hash Generator
Paste any text, optionally tick a salt, and get its 64-character SHA-256 hex digest with a copy button.Type or paste some text, press Generate SHA256 Hash, and the SHA256 Hash Generator returns its SHA-256 digest as a 64-character hex string with a copy button. The digest is computed on the page itself when you press the button; nothing is uploaded. An optional salt field lets you append a string to the text before hashing, which is how many stored-password schemes work.
The three inputs
- Text. Required. Multi-line input is fine. The hash covers exactly what's in the box, so a trailing space or newline changes every character of the output.
- Salt. Pre-filled on page load with 16 random bytes shown as 32 hex characters, and editable. The form insists on a value here even when you're not using it.
- Include salt. Unticked by default. When ticked, the tool hashes
text + salt, the salt simply concatenated after the text. This is plain salted hashing, not HMAC-SHA256, so it won't match an HMAC computed elsewhere.
What you get
One lowercase hexadecimal string, 64 characters long, representing the 256-bit digest. SHA-256 is deterministic: the same input always gives the same output. The text "abc", for example, hashes to ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad on every correct implementation, which is a handy way to verify a tool.
About SHA-256
SHA-256 is one of the SHA-2 family, published by NIST in 2001 alongside SHA-224, SHA-384 and SHA-512. It processes input in 512-bit blocks through 64 rounds and, unlike SHA-1 and MD5, has no known practical collision or preimage attacks. It's the hash inside TLS certificates today, the proof-of-work function in Bitcoin, the checksum on most software downloads, and the algorithm behind Git's optional SHA-256 object format.
Two caveats. First, SHA-256 is fast, which is exactly what you don't want for passwords; a GPU can try billions of candidates per second, so even salted SHA-256 is weak password storage compared with bcrypt, scrypt or Argon2. Second, the salt on this page is appended by concatenation. If you're reproducing a specific system's hashes, check whether it uses salt-first, text-first or an HMAC before trusting a match. The SHA2 Hash Generator and SHA512 Hash Generator cover the other family members with the same controls.
Ways people use it
- Verifying a download. Hash a small text file's contents and compare against the checksum a vendor published, or use the "abc" test above to sanity-check a script.
- Building content-addressed keys. Hashing a URL or document body to get a fixed 64-character cache key or filename.
- Reproducing a stored hash. Given a known salt from a config and a test password, confirm how an application combines them before writing a migration.
- Teaching the avalanche effect. Hash "hello" and then "hellO" and compare; every character changes, which is the point of the demonstration.
If you need a secret worth hashing, the Random Password Generator and Memorable Password Generator make them, and the Base64 Generator handles the reversible encoding people sometimes confuse with hashing. See all developer & test data tools for the rest.
Frequently asked questions
- Can a SHA-256 hash be decrypted?
No. Hashing is one-way; there is no key and nothing to decrypt. The only way to find an input is to guess and compare, which is infeasible for anything other than short or common strings.
- Is SHA-256 secure for passwords?
On its own, no. It is too fast, so attackers can test billions of guesses per second. Use a slow, purpose-built algorithm such as bcrypt, scrypt or Argon2 for password storage.
- How long is a SHA-256 hash?
256 bits, shown here as 64 hexadecimal characters. Base64 encoding of the same digest would be 44 characters.
- How is the salt applied?
When Include salt is ticked, the salt is appended to the end of your text and the combined string is hashed. It is plain concatenation, not HMAC.



