๐Ÿ› ๏ธ Developer ยท Updated October 11, 2026 ยท 7 min read

Generate a Hash Online That Matches sha256sum

text digest ๐Ÿ”’

To generate a hash of a piece of text, paste it into GrabCast's Hash Generator and read the MD5, SHA-1, SHA-256, SHA-384, SHA-512 and CRC32 values, which all update on every keystroke in your browser. If the result disagrees with what your terminal or your code printed, the input bytes differ, and the cause is almost always a trailing newline, a Windows line ending, an invisible character or a different Unicode form. A hash is a one-way fingerprint: the same bytes always give the same digest, but there is no key that turns the digest back into the text, which is what separates it from encryption. This guide is for developers, QA testers and anyone checking a value someone else computed. It covers why identical-looking words produce different output, how to confirm your setup with published test vectors, where hex versus Base64 trips people up, and everyday jobs such as cache keys and webhook signatures, with exact values you can reproduce.

๐Ÿ”’ Try the Hash Generator tool now โ€” freeOpen โ†’
Hash Generator showing the invoice.paid payload with HMAC off and plain hex digests from MD5 to CRC32
The same payload as plain hex digests.
๐Ÿ’ก Why reproducible digests matter

A digest is only useful if two parties compute it the same way. A download page publishes a SHA-256 value, a partner signs a webhook with HMAC, a cache layer keys results by an MD5 of the request, and all of them assume byte-for-byte identical input. One stray newline changes every character of the output, and nothing in the result hints at why. Because hashing is one-way, you cannot inspect a digest to see what went in; the only way to debug is to control the input precisely. Teams lose hours chasing signature mismatches that turn out to be a pretty-printed payload or an editor that appended a line break. Knowing exactly which bytes go in turns that mystery into a two-minute check.

Generate a hash of the right bytes: newlines and line endings

A hashing function reads bytes, not what you see on screen. SHA-256 of hello is 2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824. SHA-256 of hello followed by a newline is 5891b5b522d5df086d0ff0b110fbd9d21bb4fc7163af34d08286a2e846f6be03. Nothing about the second value looks related to the first, and that is by design.

Unicode forms, encodings and invisible characters

Accented letters can be stored two ways. The word cafรฉ typed on a Mac may use a single precomposed character, while text from another system may store an e plus a combining accent. They look identical, yet their SHA-256 values start with 850f7dc4 and 81ef060b respectively.

Check your hash setup against known test vectors

Before debugging your own data, confirm the pipeline with inputs whose digests are published. If these match, your tool and encoding are fine and the difference is in the payload.

Everyday uses: cache keys, ETags and HMAC signatures

Developers digest short strings constantly. A cache key might be the SHA-256 of a normalized query, an ETag the MD5 of a response body, and a deduplication job might compare digests instead of whole records. For anything an attacker could tamper with, use HMAC, which mixes a secret key into the calculation.

If you work with signed tokens, the JWT Decoder shows how HMAC signatures appear inside a real token.

Step-by-step

1234
1Open the Hash Generator, stay on the Text tab, and paste the exact string, checking the end of the box for a stray space or empty line.
Hash Generator on the Text tab with the JSON payload {"event":"invoice.paid","id":"evt_1042","amount":4900} typed into the box
Paste the exact payload.
2Read the digest you need from the six rows; MD5, SHA-1, SHA-256, SHA-384, SHA-512 and CRC32 are all computed at the same time.
Six digest rows for the payload: MD5 34e21e3c, SHA-1 e7ced393, SHA-256 93e8fb75, SHA-384, SHA-512 and CRC32 da3b7bae
All six digests appear at once.
3Switch Output to hex, HEX or Base64 to match what the other system prints, and tick HMAC with the shared key if you are checking a signature.
HMAC ticked with the secret key whsec_test_9f3a and Output set to Base64, so the rows read HMAC-MD5 to HMAC-SHA-512
Tick HMAC, add the key and match the output format.
4Paste the value you were given into the verify box; a green row confirms a match, and a red result tells you which algorithm its length suggests.
Expected value pasted into the verify box with a green Match - SHA-256 message and the HMAC-SHA-256 row outlined
A green line confirms the signature matches.

Common mistakes to avoid

โš ๏ธComparing a browser digest with echo output that includes a newline, then concluding one of the tools is broken.
โš ๏ธHashing a pretty-printed copy of a webhook payload instead of the raw body the sender signed, so the HMAC can never match.
โš ๏ธMixing output formats, such as comparing a hex digest from one system with a Base64 digest from another.
โš ๏ธUsing MD5 or CRC32 where an attacker could craft collisions; they are fine for accidental-change detection but not for security decisions.

Pro tips

โœ“Keep a note of the empty-string and abc test vectors; checking them first rules out tool and encoding problems in seconds.
โœ“When input comes from users, trim whitespace and apply Unicode NFC normalization before digesting, and document that rule for every consumer.
โœ“Use SHA-256 as the default for new work; it is widely supported and not broken, unlike MD5 and SHA-1.
โœ“Log the byte length alongside any digest in your application; a length mismatch points straight at hidden characters.
โœ“For whole files, switch to the Files tab, which digests files up to 2 GB each on your device and exports a sha256sum-style checksum list or a CSV. CRC32 shows n/a while HMAC is ticked, because HMAC needs a cryptographic hash.

Frequently asked questions

Why does my SHA-256 differ from sha256sum in the terminal?

Usually because echo adds a newline. Run printf '%s' yourtext | sha256sum or echo -n instead. If the values still differ, look for Windows line endings, trailing spaces or a different Unicode form of an accented letter.

Which encoding does the Hash Generator use?

UTF-8, the encoding used by most web APIs, Linux tools and modern programming languages. If your code converts strings to UTF-16 or a legacy code page first, its digest will not match.

Can I get the digest in Base64 instead of hex?

Yes. The Output menu offers lowercase hex, uppercase HEX and Base64. The underlying bytes are the same; only the printed representation changes, so pick whatever the other system expects.

Can a hash be reversed or decrypted?

No. Hashing has no decryption key; it is designed to be one-way. Sites that claim to reverse MD5 or SHA-1 simply look the digest up in huge tables of previously hashed common words, which is why short or guessable input is never protected by hashing alone. When you need the original data back, use encryption instead.

Is the string I type sent anywhere?

No. Digests are computed in your browser with the Web Crypto API and a built-in MD5 routine. Even so, avoid typing live secrets into any web page when a test value will do.

๐Ÿ“Œ Bottom line

To generate a hash that matches everyone else's, match the bytes first. Strip hidden newlines, agree on UTF-8 and a Unicode form, compare the same output format, and prove your setup with the empty-string and abc test vectors. Remember that a digest is a one-way fingerprint, not encryption. The Hash Generator shows six algorithms at once, verifies pasted values and handles HMAC for webhook checks, all on your device.

Open the Hash Generator tool โ†’

Related guides

Browse more: all text and developer guides ยท the Hash Generator tool