Password Hash Checker
Find out whether a password produces a given hash. Paste the hash, type the password, and add a salt if one was used. The algorithm is detected from the hash length.
How it works
A hash is a one-way fingerprint, so a password cannot be read back out of it. What you can do is hash a guess the same way and compare the results. If they are identical, the guess is the original password. This tool does exactly that: it hashes what you type, with the salt if you supply one, and compares it to the digest you pasted.
The algorithm is picked from the digest length: 32 hex characters is MD5, 40 is SHA-1, 64 is SHA-256, 96 is SHA-384 and 128 is SHA-512. You can also override it. Base64 digests and prefixes such as sha256: are understood.
When a correct password shows no match
Check the salt first. Systems differ in whether it goes before or after the password, and some add a separator or hash more than once. Also look for invisible differences: a trailing space or newline, different character encoding for non-English text, or a hash that was made from the password in lowercase. This tool encodes text as UTF-8.
Bcrypt, Argon2 and scrypt hashes are recognised but not checked, because they need dedicated libraries. To create a plain hash instead, use the Hash Generator, or see how a strong password scores in the Password Strength Checker.
Frequently asked
Is my password sent anywhere?
No. The hash is computed in your browser with built-in Web Crypto and a local MD5 routine. The password, salt and hash never leave your device.
Why can't it check bcrypt, Argon2 or scrypt hashes?
Those formats are deliberately slow, carry their own salt and cost settings, and need a dedicated library. This tool checks plain digests such as MD5 and SHA-256. For bcrypt or Argon2, use your language's own verify function, such as password_verify in PHP.
My hash has a salt. How do I check it?
Enter the salt in the salt field and choose whether it was put before or after the password. If the system joined them differently, for example with a separator, include that separator in the salt.
Is a plain SHA-256 hash a safe way to store passwords?
No. Fast hashes can be guessed billions of times per second on ordinary hardware. Passwords should be stored with a slow, salted algorithm such as Argon2id, bcrypt or scrypt.