Hash identifier
Paste a hash to see which algorithm made it, judged by prefix, alphabet and length. Then test a guess: we hash it and compare.
The likely algorithm appears here as you paste.
Hash formats at a glance
| Algorithm | Shape | Example (of “hello”, where shown) | Where you see it |
|---|---|---|---|
| MD5 | 32 hex | 5d41402abc4b2a76b9719d911017c592 | File checksums, legacy password tables |
| NTLM | 32 hex | (same shape as MD5) | Windows account passwords |
| SHA-1 | 40 hex | aaf4c61ddcc5e8a2dabede0f3b482cd9aea9434d | Git object ids, old TLS certificates |
| SHA-256 | 64 hex | 2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c… | Download checksums, Bitcoin, JWT HS256 |
| SHA-512 | 128 hex | 9b71d224bd62f378…def46f73bcdec043 (128 c… | Checksums, signing |
| CRC-32 | 8 hex | 3610a686 | ZIP, PNG and Ethernet error checks |
| bcrypt | $2b$ + cost + 53 chars (60 total) | $2b$12$… | Web app passwords (Rails, Laravel, Node) |
| Argon2id | $argon2id$v=19$m=…,t=…,p=…$salt$hash | $argon2id$v=19$m=65536,t=3,p=4$… | Modern password storage |
| SHA-512 crypt | $6$salt$86 chars | $6$rounds=5000$… | Linux /etc/shadow |
| yescrypt | $y$… | $y$j9T$… | Linux /etc/shadow (newer distros) |
| MD5 crypt | $1$salt$22 chars | $1$… | Old Unix and Cisco configs |
| phpass | $P$ + 31 chars (34 total) | $P$B… | WordPress, phpBB |
| MySQL 4.1+ | * + 40 uppercase hex | *2470C0C06DEE42FD1618BB99005ADCA2EC9D1E1… | MySQL user table |
How hash identification works
A hash function always produces the same number of bits, whatever the input. MD5 gives 128 bits, SHA-1 160, SHA-256 256 and SHA-512 512. Written in hex, each character carries 4 bits, so the length tells you the bit size: 128 ÷ 4 = 32 characters for MD5. That is why length is the first clue.
Length alone can't separate algorithms of the same size (MD5 and NTLM, SHA-256 and SHA3-256). Password hashes solve this by labelling themselves: the modular crypt format starts with $id$, where the id names the algorithm, followed by settings and a salt.
Because hashing is one-way, the only way to “reverse” one is to hash candidates and compare. The test box above does exactly that for MD5 and the SHA family, entirely on your device. Never paste a production password you care about into any website.
Not sure it's a hash at all? Base64 and hex encodings can look similar but decode back to readable data. Run it through the encoding identifier, or decode hex directly with the hex to text converter.
Questions people ask
How do I identify a hash type?
Check three things: prefix, alphabet and length. A prefix such as $2b$ (bcrypt), $6$ (SHA-512 crypt) or $argon2id$ names the algorithm outright. Without a prefix, count the hex characters: 32 is usually MD5, 40 SHA-1, 64 SHA-256 and 128 SHA-512. Paste it above and the identifier does this for you.
Can a hash be decrypted?
No. A hash is a one-way function, not encryption, so there is no key that turns it back into the input. What “hash crackers” do is guess: they hash millions of candidate passwords and look for the same output. You can test your own guesses above.
Is a 32-character hex string always MD5?
Most often, but not always. NTLM (Windows passwords) and MD4 are also 128 bits, which is 32 hex digits, and a UUID with the dashes removed has the same shape. Context, such as where you found it, settles it.
What is the difference between SHA-256 and SHA3-256?
Both give 256-bit (64 hex character) outputs, so they look identical. SHA-256 is from the SHA-2 family (NIST FIPS 180-4); SHA3-256 uses the Keccak sponge design (NIST FIPS 202). Only hashing a known input tells them apart.
Why does bcrypt give a different hash for the same password?
Each bcrypt hash includes a random 22-character salt, so the same password hashes differently every time. To check a password, the library reads the salt and cost from the stored string and hashes again.
Is the hash I paste sent anywhere?
No. Identification and the guess test run in your browser; MD5 is computed by a small script and the SHA family by your browser’s built-in Web Crypto API.