SHA-256 Hash Generator Guide: UTF-8, SHA-384 and SHA-512
ToolMellow ·
A cryptographic hash turns a byte sequence into a fixed-length digest. ToolMellow hashes well-formed Unicode text encoded as UTF-8 with SHA-256, SHA-384 or SHA-512, then displays lowercase hexadecimal. Choose Algorithm and press Generate hash. The operation runs in a local browser worker and does not upload your input for hashing.
This is a text digest tool. It does not calculate a byte-exact checksum of an arbitrary uploaded file, encrypt data, recover original text, verify a signature or provide a password-storage system. This guide explains what the result means, why visually similar input can differ, and how to compare known test values without confusing representation with security.
How to generate a text hash
Open SHA-256 hash generator and paste text, open a local text file or leave the editor empty. Algorithm defaults to SHA-256; SHA-384 and SHA-512 are also available. Press Generate hash explicitly. Typing alone does not generate a digest, and changing the input or algorithm invalidates the previous result.
Read the selected algorithm with the result, then use Copy result or Download. Empty input is permitted and produces a real nonempty digest. Wrap lines changes visual wrapping only. Before comparing another application’s value, confirm that both sides hash the same byte sequence with the same algorithm and use comparable output representations.
- Keep trailing spaces and line endings deliberate; do not remove them merely to make a comparison pass.
- Use a fixed known example such as
abcto check the selected algorithm before investigating a real payload. - Retain the original data and the trusted expected digest separately from screenshots or shortened display values.
SHA-256, SHA-384 and SHA-512 output lengths
These are three members of the SHA-2 family. Their digest lengths are fixed regardless of whether the input is empty, a short word or a longer permitted text. A hexadecimal character represents four bits, so a 256-bit digest has 64 hexadecimal characters. Leading zero bytes remain represented; this tool does not shorten the output. The workspace’s byte badge counts the UTF-8 hexadecimal text: 64, 96 or 128 bytes, rather than the raw digest byte length listed below.
Choose the algorithm required by the receiving format or comparison process. SHA-384 uses its own initialization and is not simply a prefix of a normal SHA-512 digest. A SHA-512 result cannot be compared directly with a SHA-256 result as if the extra characters were optional. Longer output alone does not make a password-storage scheme or establish that your surrounding application is secure. This interface does not offer SHA-1, MD5, SHA-3, HMAC or a salt/key setting.
| Algorithm | Digest bits | Digest bytes | Hex characters |
|---|---|---|---|
SHA-256 | 256 | 32 | 64 |
SHA-384 | 384 | 48 | 96 |
SHA-512 | 512 | 64 | 128 |
NIST FIPS 180-4: Secure Hash StandardW3C Web Cryptography API: Digest and SHA algorithms
Known SHA-256 examples: empty text and abc
The table gives complete lowercase SHA-256 digests of exactly the stated UTF-8 input. The empty-string example has zero input bytes; it is not the digest of a space or a newline. The abc example has the three ASCII bytes 61 62 63 in hexadecimal. These are fixed test examples, not a measurement of your input.
Copy the full digest rather than a shortened preview. If a reference writes hexadecimal in uppercase, letter case in the representation is different from the underlying digest bytes; ToolMellow emits lowercase. A Base64 representation of the same digest bytes would be another encoding, not another hashing algorithm. This tool provides no output-format selector.
| Exact UTF-8 input | Complete SHA-256 hexadecimal digest |
|---|---|
| Empty string | e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 |
abc | ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad |
NIST FIPS 180-4: Secure Hash StandardWHATWG Encoding: UTF-8 and text decoding
UTF-8 bytes, spaces and Unicode normalization
Before hashing, the tool checks for unpaired Unicode surrogates, then converts the input string to UTF-8. It does not trim spaces, remove a leading U+FEFF already present in the supplied string or apply Unicode normalization. A trailing space, case change or different byte representation can change the digest. The hash operation uses the string supplied to the worker.
Two strings can look the same while differing in bytes. For example, precomposed U+00E9 and the sequence U+0065 U+0301 can display the same accented letter but have different UTF-8 encodings. Likewise, LF and CRLF are different byte sequences. Browser text editing or import can affect the supplied string, so do not infer byte identity from appearance alone.
WHATWG Encoding: UTF-8 and text decodingECMAScript: String isWellFormedWHATWG HTML: Textarea values and line endings
Opening a text file is not hashing its original bytes
The file control reads through File.text(), which decodes UTF-8 text, removes a leading UTF-8 BOM and replaces malformed UTF-8 sequences. A file must be smaller than 4,000,000 bytes, and its loaded text must fit the one-million UTF-16-unit input limit. A filename extension does not establish the character encoding.
The decoded string is then encoded to UTF-8 for the digest, so the result can differ from a checksum computed directly on the original file bytes. Binary documents, images, a BOM, another character encoding or replacement characters can matter. For byte-exact file verification, use a method that reads and hashes raw bytes with the expected algorithm; this workspace is not that file-checksum method.
W3C File API: Blob text readingWHATWG Encoding: UTF-8 and text decoding
What a matching or different hash tells you
For a useful comparison, establish the same algorithm, byte sequence and full digest representation on both sides. A mismatch means those computed digests differ; it does not identify whether the cause is editing, encoding, a wrong algorithm, transport damage or another change. Known vectors help separate basic operation from assumptions about the real input.
A matching unkeyed digest supports consistency with the expected value, but is not a signature, identity check or proof that content is harmless. Cryptographic hashes have a finite output space and are not mathematically unique identifiers for every possible message. Trust the expected digest’s source: if both content and reference value are replaced, matching them alone cannot establish authenticity.
| Comparison issue | Check before drawing a conclusion |
|---|---|
| Different algorithms | Confirm SHA-256, SHA-384 or SHA-512 on both sides |
| Same visible text, different digest | Inspect UTF-8 encoding, normalization, spaces and line endings |
| Downloaded-file checksum differs | Determine whether the other method hashes original binary bytes |
| Matching digest from an unknown source | Establish a trusted reference; this is not authentication |
NIST FIPS 180-4: Secure Hash StandardW3C Web Cryptography API: Digest and SHA algorithms
A hash cannot be decrypted, but guesses can be tested
Hashing produces a digest rather than ciphertext with a decryption key. ToolMellow has no decrypt or original-text recovery function. Encryption, Base64 encoding and hashing have different roles: Base64 reversibly represents bytes, while encryption needs a cryptographic scheme and keys. A digest is not a compressed version from which arbitrary input can be reconstructed.
That does not mean every hashed input is impossible to guess. Someone can hash candidate values and compare them, especially when the original is short or predictable. A published hash therefore is not a blanket secrecy guarantee. Adding a hashing step alone does not solve authentication, key management or secure storage.
NIST FIPS 180-4: Secure Hash StandardOWASP: Password Storage Cheat Sheet
Why plain SHA-256 is not a password-storage system
This tool runs an unkeyed SHA-2 digest without a password-specific work factor, salt management or account-verification procedure. Choosing SHA-384 or SHA-512 changes the digest but does not add those capabilities. Entering a salt-like string manually is also not equivalent to implementing a complete password-storage scheme.
Password storage needs a construction designed for that purpose and appropriate application controls. Follow current password-storage guidance for the system you are building. HMAC and digital signatures address keyed authentication with different constructions; ToolMellow’s text digest does not generate or verify either. Keep real credentials out of public examples and screenshots.
OWASP: Password Storage Cheat SheetW3C Web Cryptography API: Digest and SHA algorithms
Use result as input hashes hexadecimal text
After generating a digest, Use result as input puts its hexadecimal characters into the editor. Generating again hashes the UTF-8 bytes of that text. It does not automatically feed the raw 32, 48 or 64 digest bytes into another hash operation, and this interface does not provide a raw-byte input mode.
If a protocol requires a second hash of raw digest bytes, a text operation on the visible hexadecimal result is a different computation. Identify the required representation at every step instead of assuming “hash twice” defines one universal operation. Repeating an unkeyed digest here does not turn it into password storage or keyed authentication.
WHATWG Encoding: UTF-8 and text decodingW3C Web Cryptography API: Digest and SHA algorithms
Input limits, Web Crypto and HTTPS
The input ceiling is 1,000,000 JavaScript UTF-16 code units, not one million UTF-8 bytes or visible graphemes. Emoji and combining sequences illustrate why those counts differ. The selected SHA-2 digest output remains its fixed hexadecimal length, so a permitted result fits the input ceiling for reuse; practical browser memory and worker availability still matter.
The browser must expose crypto.subtle in an appropriate secure context, such as HTTPS or a trustworthy local context including localhost. If the API is unavailable, the tool displays its support error. HTTPS alone does not guarantee every browser or embedding environment supports the required API. A standardized algorithm is not evidence that this browser, website or implementation has FIPS validation or certification.
ECMAScript: String isWellFormedW3C Web Cryptography API: Digest and SHA algorithmsW3C Secure Contexts: Potentially trustworthy origins
Troubleshoot a failed or unexpected text hash
If generation fails, read the error, confirm a supported algorithm and secure-context Web Crypto availability, and inspect the input for unpaired surrogates. An import-limit error differs from a hashing error. Do not change text until you know which byte representation the expected result describes.
When a comparison fails, start with the known abc vector, then compare the real input conditions one at a time. The tool does not diagnose corruption, produce a verification certificate or fetch a reference checksum from a URL. If clipboard access is unavailable, select the digest and copy it manually.
| Symptom | Meaningful next check |
|---|---|
| Web Crypto unavailable | Use an appropriate secure context and compatible browser |
| Unpaired surrogate error | Replace the malformed Unicode input before hashing |
| File/input limit notice | Read the file-byte and UTF-16-unit limits separately |
| Unexpected hash after file import | Check BOM removal, UTF-8 replacement and original bytes |
| Unexpected result after reuse | The hexadecimal text, not raw digest bytes, became input |
W3C Web Cryptography API: Digest and SHA algorithmsWHATWG Encoding: UTF-8 and text decoding
Text downloads, clearing and local privacy
Download saves the hexadecimal result as UTF-8 text in toolmellow-result.txt, not as raw digest bytes, a binary checksum manifest or a report. Clear removes input, output, errors, search/replacement content and editor history while retaining Algorithm and Wrap lines. Refreshing or closing the workspace discards its in-memory work; downloaded files remain on your device.
The application does not upload the supplied text, selected file contents or result to a hashing server. Loading the site still sends ordinary metadata to hosting, and the public site uses Google Analytics for page visits with cookies and browser/device information. Local hashing does not imply anonymity, zero network traffic or zero infrastructure logging. Clear does not guarantee forensic erasure from browser or operating-system memory.
Embed the hash generator with its backlink
Choose the page language and open the integration section below the workspace. Copy or download its HTML snippet into a website area that permits external iframes and scripts. The snippet contains the ToolMellow workspace iframe, sizing script and a visible backlink to the matching localized ToolMellow page. Retain that credit link.
Check the preview on narrow screens, the embedded secure context and clipboard permissions. The embed keeps the same algorithms, text scope and input limits; it does not become a remote hashing API, file-checksum service or password-verification system. The supplied credit link uses nofollow and noopener, and does not guarantee a ranking improvement.
Common questions
How do I generate a SHA-256 hash?
Paste well-formed text or leave it empty, select SHA-256 under Algorithm, and press Generate hash. ToolMellow encodes the supplied string as UTF-8 and displays the complete lowercase hexadecimal digest locally.
Why is a SHA-256 result 64 characters?
SHA-256 has a 256-bit digest. Each hexadecimal character represents four bits, giving 64 characters. SHA-384 gives 96 and SHA-512 gives 128. Input length does not change the selected digest length.
What is the SHA-256 hash of an empty string?
For zero UTF-8 input bytes it is e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855. A space or newline is not empty input and can produce a different digest.
Why did my text hash change?
The algorithm or supplied bytes may differ. Spaces, case, LF versus CRLF, a BOM, Unicode normalization or a different character encoding can matter. Visually similar text does not establish byte identity.
Can a hash be decrypted?
A digest has no decryption key and this tool cannot recover arbitrary original text. However, someone can hash guessed candidates and compare them. A hash of short predictable input is not a secrecy guarantee.
Can I calculate a file checksum here?
The import reads a file as UTF-8 text, removing a leading BOM and replacing malformed UTF-8 before re-encoding for hashing. It is not a byte-exact checksum of arbitrary file contents. Use an appropriate raw-byte hashing method for that task.
Does a matching hash prove authenticity or safety?
No. Matching an unkeyed digest supports consistency with a trusted reference, not identity, authorization or harmlessness. If content and reference are both replaced, comparing them alone cannot authenticate the publisher.
Is SHA-256 suitable for password storage in this tool?
This plain unkeyed digest has no password-specific work factor or salt management. SHA-384/512 selection and repeated text hashing do not add a complete password-storage scheme. Follow current guidance for the actual application.
What happens when I use the hash as input?
The next run hashes the hexadecimal characters as UTF-8 text. It does not hash the raw digest bytes automatically. Those representations produce different computations; this interface has no raw-byte mode.
Does the generator support MD5, SHA-1, SHA-3 or HMAC?
No. It offers SHA-256, SHA-384 and SHA-512 text digests only. It has no key/salt or output-format selector, and does not generate or verify HMACs or digital signatures.
Why does hashing require HTTPS or localhost?
Web Crypto’s crypto.subtle needs an appropriate secure context and browser support. If it is unavailable, generation fails with a support message. HTTPS alone is not a guarantee of compatibility or FIPS certification.
Can I embed this hash generator on my webpage?
Use the localized HTML snippet below the workspace, retain its visible ToolMellow backlink and check iframe/script, secure-context and clipboard support. The embedded tool retains the same text algorithms and limits; it is not a remote hashing API.
Sources and further reading
- NIST FIPS 180-4: Secure Hash Standard
- W3C Web Cryptography API: Digest and SHA algorithms
- WHATWG Encoding: UTF-8 and text decoding
- W3C File API: Blob text reading
- ECMAScript: String isWellFormed
- WHATWG HTML: Textarea values and line endings
- W3C Secure Contexts: Potentially trustworthy origins
- OWASP: Password Storage Cheat Sheet