CSP Builder
Build and risk-score Content-Security-Policy headers visually.
OpenSHA-1, SHA-256 and SHA-512. - runs entirely in your browser. Free, fast and private.
Hash strings, tokens, or file contents you provide.
Choose SHA-1, SHA-256, SHA-384, or SHA-512.
Web Crypto hashes the input entirely in-browser.
Copy lowercase hex for checksums or integrity checks.
You downloaded a release and the site published a SHA-256. Hash Generator lets you hash the same string or checksum input locally and compare digests without installing OpenSSL for a one-off check.
Reach for it for cache keys, webhook HMAC debugging prep, fixture digests, or quick integrity comparisons on short text. Prefer SHA-256 or SHA-512 for new work. SHA-1 remains available for legacy comparisons only.
Pitfall: hashing a password and calling it "storage." Hashes without salt and a proper KDF are not password storage. Another trap is comparing digests across different encodings (UTF-8 vs UTF-16) and thinking the algorithm failed.
Tip: clear the input after hashing secrets or API keys so they do not linger in the field.
Digests are computed with the Web Crypto API inside this page. Your input string is not sent to OneDevToolkit to be hashed.
Processes data instantly with no server round-trips.
Your data never leaves your browser. Nothing is uploaded.
Works in any modern browser. Nothing to download or install.
No limits, no sign-up, no credit card required.
Works on desktop, tablet and mobile devices.
Beautiful in both themes. Your preference is saved.
Keyboard shortcut
Match a published digest against text you hashed locally.
Produce SHA-256 strings for keys and fixtures without a CLI.
Hash sample bodies while you design signature checks.
Answers for this tool. For site-wide help, open the FAQ hub.
No. Digests are computed with Web Crypto in your browser.
Generators and hashers run locally. Still, never paste production secrets into any site if your security policy forbids it.
Results live in page memory until you leave or clear. Favourites/history do not save password fields unless you explicitly store them in Vault.
When applicable, tools rely on Web Crypto or well-known libraries. Read on-page notes for exact algorithms (SHA-256, bcrypt-style notes, etc.).
After load, crypto helpers typically work offline. Confirm network independence for your threat model.
Browser CSPRNG (crypto.getRandomValues) powers secure generators when the tool states so.
Treat generated secrets like passwords - share only through approved password managers, never chat apps.
OneDevToolkit aids technical workflows; it is not a certification product. See Compliance for processing model language.
Always check you are on your real OneDevToolkit domain before entering sensitive material.
Contact us via Contact with responsible-disclosure details - do not include live production secrets.