About the MD5 Hash
MD5 (RFC 1321) produces a 128-bit digest, written as 32 hex characters. The same input always gives the same hash — md5("") is d41d8cd98f00b204e9800998ecf8427e — and a one-character change gives a completely different one. Text is hashed as UTF-8, so the result matches md5sum, PHP's md5() and Node's crypto.createHash('md5') for the same bytes (watch out for a trailing newline added by echo).
The Web Crypto API deliberately omits MD5, so this page uses a small JavaScript implementation that is checked against the RFC 1321 test vectors. Files are read locally with the File API and never uploaded, which makes it convenient for comparing a download against a published MD5 checksum.
MD5 is cryptographically broken: practical collision attacks have existed since 2004 and were used to forge a CA certificate in 2008. It is still fine for non-adversarial uses such as cache keys, deduplication, ETags and detecting accidental corruption, but not for signatures, certificates or password storage.
How to use it
- Type or paste text, or click “Hash a file”.
- Read the MD5 digest in the large box.
- Switch between hex, HEX and Base64 if needed.
- Copy the value.