Utilities
Hash & encoding lab
A small developer utility built on the browser's native crypto engine: paste text, get SHA family digests instantly, or convert between raw text, Base64, and percent encoding. Nothing is transmitted anywhere.
Everything is computed inside your browser, no network requests carry your input.
Hashing and encoding look similar on a page, both turn text you paste into another string, but their purposes oppose. A hash like SHA-256 is a one-way digest: the same input always produces the same fixed-length output, but determining the input from the output is computationally infeasible. An encoding like Base64 is a reversible representation rule for the same bytes, designed to make binary data safely embeddable in text contexts.
The lab on this page implements both families locally in your tab using the browser's native Web Crypto engine. Nothing you paste is transmitted anywhere; computation stays inside the document and can be inspected in DevTools.
When to hash, when to encode, when to do neither
Hash when you need integrity or commitment without disclosure: storing a check that a file was unchanged, or comparing a candidate against a known value without keeping the raw candidate. Hash is also the primitive behind password k-anonymity proofs where only a fragment of a hash leaves the device. It is not encryption: anyone with the candidate can confirm equality, and short or low-entropy inputs are trivially guessable by enumerating candidates.
Encode when a transport requires a character set, URLs permitting only ASCII, email carrying binary as printable text, or APIs accepting data inline. Base64 expands size by roughly a third; percent encoding expands only the characters that would break the container. Neither provides secrecy, only transport safety.
Neither primitive replaces encryption. If something must be private, encrypt it with a key whose compromise you can revoke; if you need a password hash for verification, use a password-oriented function like Argon2 or scrypt, not a plain fingerprint hash.
What the panel computes
For hashes, the panel exposes SHA-1, SHA-256, SHA-384 and SHA-512. SHA-1 is offered for interoperability with existing systems that still index SHA-1 digests, but for integrity of new data prefer SHA-256 or stronger. Missing from the list is MD5, which the Web Crypto API deliberately omits because its collision resistance is broken.
For encodings, the panel toggles between raw text, Base64 and URL percent encoding, matching what developers typically juggle when debugging API payloads or redirect parameters. Copy buttons preserve the exact output formatting you see, without stray newlines.
- Hash outputs are shown in lowercase hex; copy produces that hex verbatim.
- Base64 strict padding and URL-safe variants matter when pasting into header values, normalize according to the destination's spec.
- Percent encoding here follows encodeURIComponent semantics, which encodes all characters that are not safe in a query component.
A short practical guide
Debug identity issues by hashing a stable candidate locally and comparing against published digests. Transport a small binary by encoding it to Base64 for logging, then decoding on the other side before use. Keep the lab open as a scratch pad; its value is that it is offline, immediate and not shared with any service, so secrets that should not be pasted into a remote tool remain in your process while you transform them.
Paste a snippet, switch between hash and encoding modes, and copy the result. For anything beyond ad-hoc transforms, move the logic into a scripted pipeline where hashing and encoding steps are explicit, versioned and testable.
How it works
Paste text into the input box.
Switch between hashes, Base64, and URL modes.
Copy any output with one click.
Questions about this tool
Is it safe to hash secrets here?
Yes, computation stays inside your browser tab; no request carries your input. Remember hashing is one-way integrity, not encryption: hashed doesn't mean hidden.
Why is MD5 missing?
It's cryptographically broken and browsers deliberately left it out of Web Crypto. We only offer algorithms still suitable for integrity checks.