Developer tools · SHA hash calculator
How SubtleCrypto.digest Computes a SHA-256 Hash in the Browser
· How it works
sha-256 cryptography browser-apis
Every modern browser can hash bytes natively through Web Crypto. This post follows one string from TextEncoder through crypto.subtle.digest to a hex digest, and explains each step's constraints.
A hash without npm install — the situations where a native digest beats a bundled library
You can calculate a digest for a short text value without installing a hashing package or posting data to a remote hash website. Browsers expose crypto.subtle.digest on secure origins. A hash is a deterministic fixed-length fingerprint of bytes; it does not hide the input or prove who supplied it. ToolAcre uses the browser implementation rather than shipping a hand-written SHA algorithm, and keeps the string being hashed in the tab.
Text is not bytes — encoding the input with TextEncoder to UTF-8 before hashing, and why this step decides the answer
The text “café” and the bytes fed into a hash are not the same kind of object. TextEncoder maps the string to UTF-8 bytes (63 61 66 C3 A9 for café), while a naive Latin-1 conversion would have used E9 for the final character and produced a different digest. Even visually identical text can have different Unicode normalization forms. Agree on encoding and normalization before comparing hashes across JavaScript, a CLI and a server. ToolAcre’s text mode explicitly performs its UTF-8 conversion before hashing.
The digest call — crypto.subtle.digest with an algorithm name and an ArrayBuffer, and why it returns a promise
crypto.subtle.digest("SHA-256", bytes) returns a Promise because cryptographic work may be asynchronous; await it before reading the output. The method takes the entire input buffer rather than a streaming iterator. SHA-256 emits 256 bits (32 bytes) regardless of whether the input had three characters or three million. The secure-context restriction means HTTPS or localhost is required for the SubtleCrypto API, and the tool reports its absence instead of inventing a fallback.
From ArrayBuffer to hex — turning the result bytes into the 64-character string people recognise
The Promise resolves to an ArrayBuffer of bytes, not the familiar string of hex digits. Convert each byte to two base-16 characters with a leading zero as needed, yielding exactly 64 lowercase characters for SHA-256. This hex representation doubles the length of the 32 bytes, but does not change the digest. Base64 could represent the same 32 bytes more compactly; a comparison only makes sense after confirming the algorithm, input encoding and output representation match.
Worked example — hashing a short string step by step, showing the bytes at each stage
For the ASCII text abc, UTF-8 produces the bytes 61 62 63. SHA-256 of those exact bytes is ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad. Test this in ToolAcre and another trusted hash implementation: changing abc to abc followed by a newline gives a different result. If outputs differ, inspect hidden whitespace and byte encoding before suspecting the cryptographic primitive. The displayed digest is a reproducible test vector, not a claim that abc is a secret.
Secure contexts — why crypto.subtle is only available on HTTPS and localhost
crypto.subtle is a secure-context API. A production HTTPS page and a localhost development page generally expose it; an ordinary insecure remote HTTP page may not. The tool also needs enough memory to hold the input and the output. Where Web Crypto is unavailable, silently switching to an unreviewed JavaScript hash would make a security-sensitive result depend on a different implementation. Fail clearly and choose a secure environment instead.
What this does not cover — keyed hashing (HMAC) and incremental hashing of very large inputs, which the one-shot digest API does not provide
The one-shot digest API is not incremental hashing for huge files. SHA-256 is not a password storage scheme: fast unsalted hashes make guessing cheap, so password storage needs a purpose-built, salted, deliberately costly KDF. SHA-1 may be displayed for legacy interoperability, but its collision resistance is broken and it is not a good choice for new integrity or signature systems. HMAC is keyed authentication, not the same operation as digesting unauthenticated bytes.
Takeaway: the browser already has a hash function — the ToolAcre SHA hash calculator uses exactly this API, so its output is the browser's own
The browser already provides SHA-256: encode text as bytes, await digest, then format its result for comparison. ToolAcre SHA hash calculator follows that path for pasted text and labels SHA-1 as legacy-only. Compare abc with the known result first, then hash the actual non-sensitive material whose bytes and encoding you understand.