SHA-256
Compute SHA-256, HMAC-SHA-256, or double SHA-256 (Bitcoin-style) of any text.
Calculate SHA-256, HMAC-SHA-256, or double SHA-256 hashes from text. Free, offline, runs in your browser. Read more Show less
What is SHA-256?
SHA-256 is a member of the SHA-2 family, standardized by NIST in FIPS 180-4. It produces a 256-bit (32-byte) digest, usually displayed as 64 hexadecimal characters. It is a cryptographic hash: even a single bit change in the input produces a completely different output, and no known practical collision attack exists.
SHA-256 is used in TLS, Bitcoin, Git, code signing, and file integrity verification. It is not a password-hashing function; use Argon2, scrypt, or bcrypt for that.
How to calculate a SHA-256 hash
Type or paste your text into the input box. The tool uses the browser's native Web Crypto API, so it is fast and the bytes never leave your device.
For example, the UTF-8 text abc produces:
ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad
HMAC-SHA-256
Enable HMAC to add a secret key. HMAC-SHA-256 is the recommended message authentication code for new systems and is used by TLS, JWT (HS256), and many APIs.
Double SHA-256
Enable Double SHA-256 to compute sha256(sha256(input)). This is used in Bitcoin (block hashing, address generation) and by some checksum systems. It is not the same as SHA-512 or SHA-256/256.
Frequently asked questions
Is SHA-256 safe?
Yes. SHA-256 is currently secure against collision and preimage attacks. The NIST recommendation is to continue using SHA-2 until migration to SHA-3 is required.
SHA-256 vs SHA-3
Both are secure. SHA-2 is more widely deployed and better supported by hardware. SHA-3 uses a different construction (Keccak sponge) and provides defense in depth if SHA-2 is ever broken.
Why is my hash different from another tool?
Check character encoding (UTF-8 vs UTF-16), line endings (LF vs CRLF), trailing whitespace, and whether either tool applies HMAC. Small differences change the entire hash.