Hash Identifier
Found a hash in a database, a config file or a log and need to know what it is? Paste it, and the identifier recognises structured formats such as bcrypt, Argon2, scrypt, SHA-crypt, phpass and Django PBKDF2 with certainty, and lists the likely algorithms for plain hexadecimal or Base64 hashes by length, with a note on how secure each is.
- Runs in your browser
- No sign-up
- Free to use
Analysed in your browser. Nothing is sent.
| Possible type | Likelihood | Notes |
|---|
How to use Hash Identifier
- Paste the hash.
- Read the possible types and how likely each is.
- Check the notes on security and parameters.
- Use the matching tool to generate or verify the hash.
Hash Identifier features
Structured formats
bcrypt, Argon2, scrypt, SHA-crypt, MD5-crypt, APR1, phpass, Django, passlib, LDAP, MySQL.
Parameters
Shows cost factors, iterations and memory settings.
Plain hashes
MD5, SHA-1, SHA-2, SHA-3 and others by length.
Base64 digests
Recognises encoded digests by decoded size.
Security notes
Explains which algorithms are weak.
Private
Nothing is sent anywhere.
When to use Hash Identifier
- Auditing how an application stores passwords.
- Migrating users between systems with different hash formats.
- Understanding a checksum in a download page or API.
- Learning to recognise hash formats.
Hash Identifier FAQ
Can the tool tell MD5 from NTLM?
Not with certainty: both are 32 hexadecimal characters. Context decides, such as a Windows system for NTLM. The tool lists both with likelihoods.
Why is bcrypt identified for certain?
Its format includes a marker ($2b$), the cost and a fixed length, which no other format shares.
Does identifying a hash reveal the password?
No. Identification only tells you the algorithm. Hashes cannot be reversed; weak ones can only be attacked by guessing.
Which password hashes are considered secure?
Argon2id, bcrypt and scrypt with appropriate parameters, and PBKDF2 with many iterations. Plain MD5, SHA-1 or SHA-256 are not suitable for passwords.
Is the hash sent anywhere?
No. Everything happens in your browser.
What if nothing matches?
The value may be truncated, encoded in an unusual way, or not a hash at all. Check that the whole value was copied.
Reading a hash like a label
Many hashes carry their own label. Modern password hashes use the modular crypt format: a dollar sign, an identifier, parameters and the salted hash, as in “$2b$12$…” for bcrypt with cost 12. Framework formats such as Django’s “pbkdf2_sha256$…” do the same. These can be identified with certainty, and their parameters tell you how strong the storage is.
Plain digests carry no label. A 64-character hexadecimal string is most likely SHA-256, but SHA3-256 and BLAKE2s produce the same length. Here the identifier can only rank candidates by how common they are. Context, the system the hash came from, usually settles it.
Identification has practical uses. Security reviews check that passwords are stored with a slow, salted algorithm and that work factors are adequate. Migrations need to know the old format so that users can be upgraded at their next login. Developers meeting a checksum in an API want to know which function to call.
If a password database uses unsalted MD5 or SHA-1, it should be upgraded: rehash each password with Argon2id or bcrypt when the user next logs in, or wrap the old hashes in a modern algorithm immediately. Identifying the format is the first step.