MD5 Hash

Generate an MD5 checksum in your browser to verify a download.

Free, no limit Nothing uploaded Works offline No sign-up

Broken for security, still useful for checking a download

MD5 is cryptographically broken and has been since 2004. Researchers can construct two different inputs that produce the same hash, deliberately and quickly. That makes it unusable for anything where an attacker might be choosing the input: signatures, certificates and above all passwords.

It is still perfectly good at the job most people use it for, which is detecting accidental corruption. If a project publishes an MD5 for a download and yours matches, your copy arrived intact. A truncated or corrupted file will not produce the same hash by chance.

The output is always 32 hexadecimal characters, whatever the input length. A single character change anywhere produces a completely different hash, which is what makes the comparison useful.

Text being reduced to a fixed length MD5 checksum

How to use it

Paste into the left box and the result appears in the right one as you type. Change any option and it recalculates immediately.

Copy puts the result on your clipboard and confirms it did. Download saves it as a file, which is the easier route when the output is long enough that selecting it by hand is a nuisance. Clear empties the boxes and puts the cursor back where you need it.

Where a sample button appears, it loads a small realistic example. It is there so you can see what the tool expects before pasting your own material, which is quicker than reading a description of the input format.

Keyboard and mobile

The text areas are ordinary form fields, so every shortcut your system already has works: select all, undo, redo, and paste without formatting. Tab moves between the panes and the controls in the order you would expect, and every control is reachable without a mouse.

On a phone the panes stack rather than sitting side by side, and the text areas grow to a comfortable height. Spellcheck and autocorrect are switched off in them, because a tool that silently capitalises your md5 hash input is worse than useless.

If something looks wrong

When the result is not what you expected, the message under the boxes is the first thing to read. It reports what happened rather than a generic failure, so a malformed input names the line to look at and a successful run reports what it did, such as how many lines it kept or how many replacements it made.

A count of zero is informative in itself. It usually means the input did not contain what you thought it did, most often because of capitalisation or an invisible trailing space, both of which are far more common in pasted data than people expect.

Nothing is corrected silently. If the input cannot be handled, the output is left empty and the reason is stated, rather than a partial result being returned that looks plausible and is wrong. A tool that guesses is worse than one that says it could not.

What to use instead, and when

The choice depends on what you are defending against.

  • Verifying a download against a published checksum, MD5 is adequate. Nobody is attacking your file transfer, and corruption is what you are looking for.
  • Verifying anything an attacker could substitute, use SHA-256. Collisions in MD5 are cheap enough to be a practical attack.
  • Storing passwords, use bcrypt, scrypt or Argon2. Never a plain hash of any kind. Fast hashing is exactly the wrong property, and MD5 is very fast.
  • Deduplicating files or building a cache key, MD5 is fine and commonly used, because a deliberate collision gains an attacker nothing.

Which hash function to use

Hash functions are not interchangeable, and choosing on speed alone is how systems end up with passwords stored in something that can be cracked at a billion guesses a second.

FunctionOutputStatusUse it for
MD5128 bitsBroken since 2004Checksums only
SHA-1160 bitsBroken since 2017Nothing new
SHA-256256 bitsCurrent standardSignatures and verification
bcrypt184 bitsCurrent standardPasswords
Argon2ConfigurableCurrent standardPasswords

Broken here has a specific meaning: someone can construct two different inputs that produce the same output. That destroys the guarantee a signature depends on, because a valid signature over one document also validates a different one.

For verifying that a download arrived intact, any of them works, because nobody is attacking a file transfer with a chosen collision. That is why MD5 checksums are still published and still useful.

For passwords, none of the fast functions are acceptable. A password hash needs to be slow and salted on purpose, so that guessing candidates costs real time and a leaked database cannot be attacked with a precomputed table. bcrypt, scrypt and Argon2 are all designed for that, and a plain SHA-256 of a password is a well known error rather than a shortcut.

Safe to use with real data

Most online developer tools post whatever you paste to a server. For a toy example that is fine. For the payload you are actually debugging, which is a production API response with customer records in it, an internal configuration file or a token, it is a data disclosure that nobody signed off.

Everything on this page runs in your browser. The parsing, the conversion and the formatting all happen in memory on your own machine. Nothing is transmitted, nothing is logged, and there is no server that could keep a copy even if someone asked it to.

You can check that yourself: open your browser's network panel, paste something in and watch nothing happen. Then disconnect from the internet and use the md5 hash tool anyway, because once the page has loaded it does not need the network again.

That constraint also shapes what we will build. Anything that genuinely requires a server, such as looking up a value in a database, is not something we can offer honestly under these terms, so we do not offer it at all.

No limits, and no account

There is no cap on how much text you can run through this, no daily quota and no sign up wall at the point where it becomes useful. The MD5 Hash tool costs us nothing to provide because it runs on your device rather than ours, so there is nothing to meter.

There is also nothing to install. It is one page of HTML, one stylesheet and one script, which together come to a fraction of the weight of a single photograph. It loads in well under a second on a phone connection and works immediately.

Why we built it this way

Developer tools that upload your input are a poor bargain. You get a conversion and they get your data, and the thing you pasted was usually the one piece of text you should have been most careful with. Running it locally removes the trade entirely.

The whole site is built on the same rule: if the work can be done in the browser, it is done in the browser. Over a hundred tools work that way, and the handful that genuinely cannot are the ones we have not built.

It also means the tool keeps working when we are not paying attention to it. There is no service to go down, no API key to expire and no rate limit to hit at the moment you need it most. The page you loaded is the whole program, and it will behave the same way in five years as it does today.

FAQ

MD5 Hash

The questions people ask most about this tool.

Not for security. Collisions can be produced deliberately, so it must not be used for signatures, certificates or passwords. For checking a download arrived intact it is still fine.

Not by computation, since it discards information. Common inputs are recoverable from lookup tables, which is one of several reasons passwords must never be stored this way.

MD5 always produces 128 bits, written as 32 hexadecimal characters, regardless of whether the input was one letter or a gigabyte.

bcrypt, scrypt or Argon2, each of which is deliberately slow and salted. A plain hash of any algorithm is the wrong tool.

Completely, with no account, no quota and no paid tier. It runs on your own device, so there is nothing for us to meter and nothing to charge for.

No. Everything happens inside this page, in memory on your machine. Nothing is transmitted, stored or logged, and you can confirm it by watching your browser's network panel while you type.

Yes. Once the page has loaded it never needs the network again, so you can disconnect and carry on working.

None that we impose. The practical limit is your device's memory, which on a modern machine is a very large amount of text.

Yes. The panes stack on a narrow screen and the controls stay reachable. Autocorrect is switched off in the input, so nothing is silently changed as you type.

Yes, freely and with no attribution required. What you paste is yours and so is what comes out.

Need a different conversion?

Over a hundred free tools, all running in your browser. Nothing is uploaded and nothing is capped.