Crypto & Hash Tools
Crypto & Hash Tools is a free suite of 14 developer utilities for hashing, message authentication, checksums, identifiers and regular expressions. Every calculation happens locally in your browser, so your input never travels over the network. There are no accounts, no uploads, and no tracking.
The tools are organized into five categories — hash generators, HMAC tools, checksum tools, UUID tools, and regex tools — each explained below. Use this page as an overview to choose the right tool for a task, then jump to the dedicated tool page for detailed guidance, security notes, and the working tool itself.
What Crypto & Hash Tools Provides
A focused set of cryptographic and text-processing utilities that run entirely in the browser: hash generators for the MD5 and SHA-2 families, keyed HMAC generators, a CRC32 checksum calculator, a UUID v4 generator and validator, and four regular-expression tools (tester, explainer, generator, and cheat sheet).
Each tool page combines the interactive tool with a technical explanation of the algorithm, step-by-step usage, common use cases, how the algorithm works internally, security and privacy considerations, and a FAQ. The goal is not just to compute a value but to help you understand what that value means and when it is appropriate to use it.
Choosing the Right Hash Algorithm
Pick a hash based on what you are protecting against. For modern integrity verification, digital signatures, and content-addressed storage, use a SHA-2 function such as SHA-256 or SHA-512. SHA-256 is the most common choice and is sufficient for the large majority of applications; SHA-512 offers a larger security margin and can be faster on 64-bit hardware for large inputs.
SHA-384 is a truncated variant of SHA-512 that gives a longer digest than SHA-256 without the full 128-character output of SHA-512. It is most often seen in specific certificate and signature profiles.
MD5 and SHA-1 are cryptographically broken for collision resistance and should not be used for new security designs. They remain useful only for non-adversarial checks and for reproducing legacy checksums. None of these fast hashes are suitable for password storage — use a dedicated password hash such as bcrypt, scrypt, or Argon2 instead.
Hashing vs Encryption
Hashing is one-way: you compute a fixed-length digest from input, but you cannot recover the input from the digest. It is suited to verification and fingerprinting — confirming that data has not changed, or addressing content by its digest.
Encryption is two-way: ciphertext can be turned back into plaintext with the correct key. Use encryption when you need to read the data back later. A common mistake is treating a hash as a way to "store" data securely; because hashing is irreversible, hashed data cannot be retrieved, only re-computed and compared.
Hashing vs HMAC
A plain hash proves only integrity — that the data has not changed. It can be computed by anyone and proves nothing about who produced it.
An HMAC combines a hash function with a secret key, so it proves both integrity and authenticity — the tag could only have been produced by someone who knows the key. Use HMAC-SHA256 or HMAC-SHA512 for API request signing, webhook verification, and any context where you need to confirm the origin of data. HMAC provides authentication, not confidentiality; the message itself is not hidden.
Checksums vs Cryptographic Hashes
A checksum such as CRC32 is designed to detect accidental corruption — bit flips during transmission or storage. It is fast and lightweight, which is why it appears in archive formats and network protocols.
A cryptographic hash is designed to resist deliberate manipulation: it should be infeasible to craft two different inputs with the same digest. CRC32 has no such property — collisions are trivial to produce — so it must not be used to detect tampering or for any security purpose. Use a checksum for accidental-error detection and a cryptographic hash for adversarial integrity.
UUIDs and Identifiers
A UUID is a 128-bit identifier standardized by RFC 4122. The UUID Generator produces version 4 UUIDs, which use 122 random bits to make collisions practically impossible without central coordination. They are well suited to database primary keys, session IDs, and distributed-system identifiers.
The UUID Validator checks that a string matches the RFC 4122 structure and reports the claimed version. A UUID is an identifier, not a secret — do not use one as a password or security token. Validation confirms format only, not that the identifier refers to a real record.
Regular Expression Tools
Four regex tools cover different points in the workflow. The Regex Tester runs a pattern against text with live highlighting and flags. The Regex Explainer breaks a pattern into tokens and describes each one. The Regex Generator provides ready-made patterns for common validations. The Regex Cheat Sheet is a searchable syntax reference.
Regex is powerful for matching and extracting text, but it is not a parser. For nested structures such as HTML or complex file formats, use a proper parser. Watch for ReDoS — patterns with nested or overlapping quantifiers can cause catastrophic backtracking on certain inputs.
Why Browser-Only Processing Matters
Every tool runs as browser JavaScript. Text you paste is hashed, signed, or matched on your own device — there is no backend that receives your data. This makes the tools safe to use with API keys, webhook secrets, tokens, and other confidential values that you would not want to send to a third-party service.
Because the computation is local, most tools continue to work offline once the page has loaded. An internet connection is only needed to load the page initially. Read the full details in the privacy policy.
Common Developer Workflows
- Verify a downloaded file against a publisher's SHA-256 checksum before installing it.
- Reproduce an HMAC signature while debugging a webhook or signed API request.
- Confirm a CRC32 value from a ZIP archive or network protocol during integration.
- Generate UUID v4 primary keys, or validate identifiers from a database export before using them in a query.
- Prototype a validation regex in the tester, explain an inherited pattern, then ship it.
- Compare SHA-2 family outputs side by side to choose the right digest length for a project.
Security Limitations
These tools compute correct values, but correctness does not equal security. MD5 and SHA-1 are collision-broken; CRC32 is not cryptographic; and no fast hash — including SHA-256 and SHA-512 — is appropriate for password storage on its own. For passwords, use bcrypt, scrypt, or Argon2, which add a salt and a configurable work factor.
HMAC authentication depends on keeping the secret key confidential and comparing tags in constant time. Regex validation checks format, not safety. Each tool page states its own limitations explicitly; treat them as guidance for using the output responsibly, not as a security guarantee.
Tool Category Guide
The five categories below group tools by purpose. Each category lists its tools with a one-line description and a link to the full tool page.
Hash Generators
Generate MD5, SHA-1, SHA-256, SHA-384 and SHA-512 hashes from any text, entirely in your browser.
- MD5 — Generate an MD5 hash from any text directly in your browser.
- SHA1 — Generate a SHA-1 hash from any text directly in your browser.
- SHA256 — Generate a SHA-256 hash from any text directly in your browser.
- SHA384 — Generate a SHA-384 hash from any text directly in your browser.
- SHA512 — Generate a SHA-512 hash from any text directly in your browser.
HMAC Tools
Create keyed HMAC-SHA256 and HMAC-SHA512 signatures for API authentication and webhook verification.
- HMAC SHA256 — Generate an HMAC-SHA256 signature from a message and secret key.
- HMAC SHA512 — Generate an HMAC-SHA512 signature from a message and secret key.
Checksum Tools
Calculate CRC32 checksums for quick, non-cryptographic data integrity checks.
- CRC32 — Calculate a CRC32 checksum for quick data integrity verification.
UUID Tools
Generate random UUID v4 identifiers and validate UUID strings against RFC 4122.
- UUID Generator — Generate RFC 4122 version 4 UUIDs with one click.
- UUID Validator — Validate the structure and version of any UUID string.
Regex Tools
Test, explain, generate and reference regular expressions with live matching.
- Regex Tester — Test regular expressions with live matching and highlighting.
- Regex Explainer — Understand what each part of a regular expression does.
- Regex Generator — Generate ready-to-use regex patterns for common validations.
- Regex Cheat Sheet — Searchable reference for regular expression syntax.
Frequently Asked Questions
A short set of common questions is answered below; for the full set, see the FAQ page.
- Is my input uploaded to a server?
- No. Every tool runs as browser JavaScript. The text you enter is hashed, signed, or matched on your device and is never transmitted over the network.
- Is hashing the same as encryption?
- No. Hashing is one-way and cannot be reversed; encryption is two-way and needs a key to decrypt. Use a hash for verification and encryption when you need to recover the original data.
- Which hash should I use for a new project?
- SHA-256 is the standard choice for integrity verification and signatures. Use SHA-512 when you need a larger margin. Avoid MD5 and SHA-1 for new security designs.
- Can I store passwords with these hashes?
- No. Fast hashes are unsuitable for password storage. Use a dedicated password hash such as bcrypt, scrypt, or Argon2, which add a salt and a work factor.
- Do the tools work offline?
- Once a page is loaded, most tools continue to work offline because the computation happens in your browser. An internet connection is only needed to load the page initially.