SHA-1 Hash Generator

Generate the 160-bit SHA-1 digest of text or a file, locally in your browser.

Loading tool…

About the SHA-1 Hash

SHA-1 (FIPS 180-4) outputs 160 bits, shown as 40 hex characters; for example sha1("abc") = a9993e364706816aba3e25717850c26c9cd0d89d. It is computed here with the browser's native crypto.subtle.digest('SHA-1', …), on the UTF-8 bytes of your text or the raw bytes of a chosen file.

SHA-1 is no longer collision resistant. In 2017 the SHAttered attack produced two different PDFs with the same SHA-1, and in 2020 chosen-prefix collisions became practical. Browsers stopped trusting SHA-1 TLS certificates in 2017. Do not use it for new signatures; SHA-256 is the usual replacement.

You will still meet SHA-1 in legacy systems: Git object IDs (Git is migrating to SHA-256 and detects the known collision technique), older HMAC-SHA1 APIs and TOTP authenticator codes, where HMAC's construction keeps it safe for now. Note that a Git blob ID hashes a blob <size>\0 header plus the content, so it differs from the plain SHA-1 of the file.

How to use it

  1. Enter text or choose “Hash a file”.
  2. Read the SHA-1 digest at the top.
  3. Pick hex, upper-case hex or Base64 output.
  4. Copy the value.

Frequently asked questions

Is SHA-1 still secure?
Not for collision resistance, so not for signatures or certificates. HMAC-SHA1 is still considered secure, but new designs should use SHA-256.
Why is my file's SHA-1 different from its Git hash?
Git hashes “blob <size>\0” followed by the content. Run git hash-object file to get the Git ID.
How long is a SHA-1 hash?
20 bytes: 40 hex characters or 28 Base64 characters.

Related tools