Secure passwords and hashes
Pick a length and character types to get a cryptographically random password with a strength estimate. Hash text or files with MD5, SHA-1, SHA-256, SHA-384 or SHA-512 — all in your browser.
Secure password
…Generated with your browser's cryptographic random number generator. Nothing is sent or stored.
Hash text or a file
- MD5
… - SHA-1
… - SHA-256
… - SHA-384
… - SHA-512
…
MD5 and SHA-1 are fine for checksums but broken for security. Never store passwords with a plain hash — use bcrypt, scrypt or Argon2.
How to use it
- 1Choose the length and the character types (A–Z, a–z, 0–9, symbols).
- 2Copy the password — press refresh for a new one.
- 3To hash, type text or drop a file and copy the MD5 or SHA value you need.
Related tools
Frequently asked questions
Are the passwords really random?
Yes. They come from your browser's cryptographic random generator (crypto.getRandomValues) with unbiased sampling, and every selected character type is guaranteed to appear.
How long should a password be?
At least 16 characters for important accounts. 20 characters using all four types gives about 129 bits of entropy.
Are generated passwords stored or sent anywhere?
No. They are created on your device and disappear when you leave the page.
Should I store passwords as MD5 or SHA-256 hashes?
No. Plain hashes are too fast to guess; use bcrypt, scrypt or Argon2 for passwords. MD5 and SHA-1 are fine only for checksums.
How do I check a download's checksum?
Click “Hash a file”, choose the download and compare the SHA-256 value with the one published by the vendor.