SHA1 Hash Generator
Create 160-bit SHA-1 hashes of text or files.
SHA-1 · 160 bits
Result will appear here...
SHA-1 Hash Generator
Generate the SHA-1 hash of text or a file online. The 160-bit digest (40 hex characters) is computed in your browser and updates as you type.
What is SHA-1?
SHA-1 (Secure Hash Algorithm 1) was published by NIST in 1995 as FIPS 180-1. For two decades it was the default hash for TLS certificates, Git commits, software signing, and countless protocols. It processes the message in 512-bit blocks and produces a 160-bit result — for example, SHA-1("abc") = a9993e364706816aba3e25717850c26c9cd0d89d.
Security note
SHA-1 is deprecated for security. The 2017 SHAttered research produced two different PDF files with the same SHA-1 hash, and cheaper chosen-prefix collisions arrived in 2020. Do not use SHA-1 for digital signatures, certificates, or password hashing. It remains fine for non-adversarial integrity checks and legacy interoperability.
Features
- Text or file input, up to 200 MB, hashed locally
- Hex, uppercase, or Base64 output
- Hash each line for bulk lists
- Compare a computed hash against a known value
Alternatives
For new work choose the SHA256 Hash Generator or the whole SHA2 family, or the modern SHA3-256. To sign data with a shared secret, use the HMAC Generator.
Frequently Asked Questions
Is SHA-1 still secure?
No. A practical collision was demonstrated in 2017 (the SHAttered attack) and a chosen-prefix collision followed in 2020. Browsers and certificate authorities stopped trusting SHA-1 certificates years ago. Use SHA-256 or SHA-3 for anything security-related.
Why does Git still use SHA-1?
Git uses SHA-1 to name objects, and it added collision detection to resist the known attack while it migrates to SHA-256. For content addressing without an active attacker, SHA-1 is adequate, which is why many systems still rely on it.
How long is a SHA-1 hash?
160 bits — 40 hexadecimal characters, or 20 bytes. That is longer than MD5 (128 bits) but shorter than SHA-256.