Hash identifier

Paste a hash to see which algorithm made it, judged by prefix, alphabet and length. Then test a guess: we hash it and compare.

Try

The likely algorithm appears here as you paste.

Hash formats at a glance

AlgorithmShapeExample (of “hello”, where shown)Where you see it
MD532 hex5d41402abc4b2a76b9719d911017c592File checksums, legacy password tables
NTLM32 hex(same shape as MD5)Windows account passwords
SHA-140 hexaaf4c61ddcc5e8a2dabede0f3b482cd9aea9434dGit object ids, old TLS certificates
SHA-25664 hex2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c…Download checksums, Bitcoin, JWT HS256
SHA-512128 hex9b71d224bd62f378…def46f73bcdec043 (128 c…Checksums, signing
CRC-328 hex3610a686ZIP, PNG and Ethernet error checks
bcrypt$2b$ + cost + 53 chars (60 total)$2b$12$…Web app passwords (Rails, Laravel, Node)
Argon2id$argon2id$v=19$m=…,t=…,p=…$salt$hash$argon2id$v=19$m=65536,t=3,p=4$…Modern password storage
SHA-512 crypt$6$salt$86 chars$6$rounds=5000$…Linux /etc/shadow
yescrypt$y$…$y$j9T$…Linux /etc/shadow (newer distros)
MD5 crypt$1$salt$22 chars$1$…Old Unix and Cisco configs
phpass$P$ + 31 chars (34 total)$P$B…WordPress, phpBB
MySQL 4.1+* + 40 uppercase hex*2470C0C06DEE42FD1618BB99005ADCA2EC9D1E1…MySQL user table

How hash identification works

A hash function always produces the same number of bits, whatever the input. MD5 gives 128 bits, SHA-1 160, SHA-256 256 and SHA-512 512. Written in hex, each character carries 4 bits, so the length tells you the bit size: 128 ÷ 4 = 32 characters for MD5. That is why length is the first clue.

Length alone can't separate algorithms of the same size (MD5 and NTLM, SHA-256 and SHA3-256). Password hashes solve this by labelling themselves: the modular crypt format starts with $id$, where the id names the algorithm, followed by settings and a salt.

Because hashing is one-way, the only way to “reverse” one is to hash candidates and compare. The test box above does exactly that for MD5 and the SHA family, entirely on your device. Never paste a production password you care about into any website.

Not sure it's a hash at all? Base64 and hex encodings can look similar but decode back to readable data. Run it through the encoding identifier, or decode hex directly with the hex to text converter.

Questions people ask

How do I identify a hash type?

Check three things: prefix, alphabet and length. A prefix such as $2b$ (bcrypt), $6$ (SHA-512 crypt) or $argon2id$ names the algorithm outright. Without a prefix, count the hex characters: 32 is usually MD5, 40 SHA-1, 64 SHA-256 and 128 SHA-512. Paste it above and the identifier does this for you.

Can a hash be decrypted?

No. A hash is a one-way function, not encryption, so there is no key that turns it back into the input. What “hash crackers” do is guess: they hash millions of candidate passwords and look for the same output. You can test your own guesses above.

Is a 32-character hex string always MD5?

Most often, but not always. NTLM (Windows passwords) and MD4 are also 128 bits, which is 32 hex digits, and a UUID with the dashes removed has the same shape. Context, such as where you found it, settles it.

What is the difference between SHA-256 and SHA3-256?

Both give 256-bit (64 hex character) outputs, so they look identical. SHA-256 is from the SHA-2 family (NIST FIPS 180-4); SHA3-256 uses the Keccak sponge design (NIST FIPS 202). Only hashing a known input tells them apart.

Why does bcrypt give a different hash for the same password?

Each bcrypt hash includes a random 22-character salt, so the same password hashes differently every time. To check a password, the library reads the salt and cost from the stored string and hashes again.

Is the hash I paste sent anywhere?

No. Identification and the guess test run in your browser; MD5 is computed by a small script and the SHA family by your browser’s built-in Web Crypto API.