SHA-1 Hash & File Checksum

Calculate a 40-character SHA-1 hash for UTF-8 text or a local file. Compare an expected checksum, copy or download the digest, and understand why Git object IDs differ.

Calculate
0 characters
Result

Your result will appear here.

How to calculate and verify SHA-1

  1. Enter text or choose one local file; a selected file replaces the text as the source.
  2. Optionally paste the expected SHA-1 checksum without a filename, then calculate.
  3. Copy or download the full 40-character digest and check the comparison result.

Working with SHA-1 Hash & File Checksum

SHA-1 is retained for compatibility with existing systems and published checksums. It is not suitable for new collision-resistant security designs. Hashes are calculated from exact file bytes or UTF-8 text.

SHA-1 example: the standard abc test vector

Input
abc
Result
a9993e364706816aba3e25717850c26c9cd0d89d

Questions about SHA-1 Hash & File Checksum

What does the 40-character SHA-1 result represent?

It is the full 160-bit SHA-1 digest in lowercase hexadecimal. Text is encoded as UTF-8; files use their original bytes. Text is limited to 8 MiB and files to 32 MiB, processed in your browser.

Why is a file's SHA-1 different from its Git object ID?

In a SHA-1 repository, Git hashes an object header plus the content, not just the file bytes. For a blob, the header includes blob, the byte length and a null byte. This tool calculates raw SHA-1, not Git object IDs or HMAC-SHA-1. Use the HMAC tool for keyed hashes.

How do I compare a checksum, and why might it not match?

Paste only the expected hexadecimal hash. Comparison ignores letter case and surrounding whitespace. Input case, spaces, CRLF versus LF, a final newline or a UTF-8 BOM change the bytes and the digest. No text normalisation is applied; file names and paths are excluded.

Can SHA-1 be decrypted? Is it still secure?

SHA-1 is a hash, not reversible encryption. This tool does not recover original text or verify signatures. Collision attacks make SHA-1 unsuitable for new security-sensitive designs. Use it for existing checksum compatibility; prefer SHA-256 for new file checks and Argon2id or another dedicated scheme for password storage.

Are my files, tokens or text uploaded?

No. These tools process your input in your browser. The website serves the page and its code, but your input is not sent to a conversion server or saved in an account.

Explore all developer tools

Encoding & Files

Move between text, bytes, URLs and embedded images without changing your original data.

Data & Text Inspection

Read structured data, inspect tokens and understand exactly what changed.

Hashes, IDs & Schedules

Check file integrity, generate identifiers and make sense of times and recurring schedules.

Your input and files are processed on your device. Keep sensitive results out of shared clipboards and use a trusted device for private keys and tokens.