Category guide

Cryptography Tools

A digest, a message authentication tag, and encrypted text solve different problems. Choose the operation required by your protocol, use a known test value, and keep secrets out of copied examples. These tools process input in the browser, without a server-side calculation.

Choose the right tool

SHA-256 Hash Generator

Use SHA-256 to calculate a reproducible digest when a specification calls for that exact algorithm.

SHA-512 Hash Generator

Use SHA-512 when a file format or integration explicitly requires its 512-bit digest.

HMAC Generator

Use HMAC when two parties share a secret key and need to verify message authenticity.

AES-GCM Encrypt / Decrypt

Use the AES-GCM page for this site's password-based encrypted-text envelope and test decryption locally.

All tools

Example workflow: check an integration signature

  1. Read the integration specification for the exact HMAC algorithm, secret-key encoding, and message bytes.
  2. Enter a nonproduction test key and message in HMAC Generator, then compare the output with a published test value.
  3. Investigate mismatches in UTF-8 encoding, whitespace, line endings, and output representation before changing algorithms.

Before you use the result

A plain hash does not authenticate a sender and should not be used as password storage. HMAC requires careful secret-key handling. The AES page produces a versioned envelope for this site's own format, so do not assume another application's ciphertext can be decrypted here.

Start with the required algorithm

Many integrations name an exact SHA or HMAC variant. A SHA-256 digest is not interchangeable with SHA3-256 or a shortened SHA-512 value, even if the displayed hexadecimal strings have the same length. Use the page that matches the specification and compare the result with a trusted test vector. The SHA-256 and SHA-512 pages are useful for deterministic fingerprints, not for proving who created the message.

Use HMAC Generator when a protocol requires a keyed digest. Its result depends on both the exact message bytes and the secret key. Do not paste a production secret into a shared screenshot or bug report. If you need confidentiality rather than a digest, read the envelope details on AES-GCM Encrypt/Decrypt and test encryption and decryption with the same tool before storing output.

What this category does not verify

The pages calculate values; they do not decide whether your protocol is safe, manage keys, or rotate secrets. They also do not turn a hash into a password storage scheme. CRC tools in the Checksums category detect accidental changes and serve a different purpose from cryptographic authentication. For production integrations, verify message construction, encoding, and key management in the application that will use the output.