SHA-256 Explained
SHA-256 is the workhorse of modern security — hashing files, signing data and securing blockchains. Here is what it does and where it fits.
What SHA-256 is
SHA-256 is a cryptographic hash function from the SHA-2 family. It converts any input into a 256-bit digest — 64 hex characters — with the same input always producing the same output.
SHA-256("password") =
5e884898da28047151d0e56f8dc6292773603d0d6aabbdd62a11ef721d1542d8
Hash anything with the free SHA-256 generator.
How it behaves
- Fixed size — output is always 256 bits, however big the input.
- Deterministic — same input, same hash.
- One-way — cannot be reversed.
- Avalanche effect — a tiny input change flips ~half the output bits.
- Collision-resistant — infeasible to find two inputs with the same hash.
Where SHA-256 is used
- File and download integrity — verify nothing was altered.
- Digital signatures — sign the digest, not the full data.
- TLS and certificates.
- Blockchains — linking blocks and mining.
- Content addressing — deduplication, Git objects.
SHA-256 vs MD5 and SHA-1
| Algorithm | Output | Status |
|---|---|---|
| MD5 | 128-bit | Broken — collisions found |
| SHA-1 | 160-bit | Broken — collisions found |
| SHA-256 | 256-bit | Secure |
MD5 and SHA-1 are fine as non-security checksums but must not be used where an attacker benefits from collisions. Compare with the MD5 generator.
Hashing is not encryption
You cannot "decrypt" a SHA-256 hash. To check data, you hash a candidate and compare. There is no key and no reversal.
Not for passwords
SHA-256 is fast — great for integrity, terrible for passwords. Use a salted, slow algorithm (bcrypt, scrypt, Argon2) for credentials. See hashing vs encryption.
Verify a download
Publish the SHA-256 of your file; users hash their copy and compare. Any mismatch means corruption or tampering. Do it in-browser with the generator — your files never leave your device.