StringMash.com

Hash identifier

Paste a hash, or any string you can't place, and see what it most likely is.

60 characters
Updates as you type
Most likelybcrypt
Length60 characters

Show the steps
  1. bcrypt. A slow, salted password hash. The number after the second $ is the cost: each step up doubles the work.
  2. This reads only the shape of the string. Nothing is looked up or sent anywhere, and a hash can't be turned back into its input.

Using the identifier

Paste the string and you get the most likely type, the other types it could be, and what each one is used for. When the string isn't a hash at all, which happens often, the identifier says what it is instead and links to the tool that decodes it.

It only reads the shape of the string: its prefix, its length and the characters it uses. Nothing is looked up or sent anywhere, and no hash can be turned back into its input.

What is this string?

How to recognise a string by eye
What you seeWhat it probably is
Starts $2a$, $2b$ or $2y$, then two digits and $bcrypt password hash; the digits are the cost
Starts $argon2id$ (or $argon2i$, $argon2d$)Argon2 password hash
Starts $6$, $5$ or $1$sha512crypt, sha256crypt or md5crypt, from a Linux /etc/shadow file
Starts $y$yescrypt, used for /etc/shadow on several Linux distributions
32 hex digitsMD5, or NTLM or MD4, which are the same length
40 hex digitsSHA-1, or RIPEMD-160
64 hex digitsSHA-256, or SHA3-256
128 hex digitsSHA-512, or SHA3-512, BLAKE2b or Whirlpool
Starts eyJ, with two dotsA JSON Web Token: decode it, it's not a hash
Letters, digits, + and /, often ending in =Base64: decode it, it's not a hash
8-4-4-4-12 hex digits with hyphensA UUID: an identifier, not a hash
%20, %2F and other % codesURL encoding
’, é and similarGarbled text: fix it with the mojibake fixer

Why some hashes can't be told apart

A plain hash is just a number written in hex, and the only thing its shape gives away is its length. MD5, NTLM and MD4 all produce 128 bits, 32 hex digits, so a 32-digit hash could be any of them. The identifier lists every algorithm of that length with the most common first. Where it came from usually settles it: a Windows password dump suggests NTLM, a download page's checksum suggests MD5.

Password hashes are easier. Formats such as bcrypt, Argon2 and the Linux crypt family start with a $ prefix that names the scheme, followed by its settings and a salt, so they identify themselves.

Questions

How can I tell if a hash is MD5 or SHA-1?

By length: MD5 is 32 hex digits, SHA-1 is 40.

Can you find the password from the hash?

No. A hash can't be reversed. This tool only names the type.

What is a $2b$ hash?

A bcrypt password hash. The two digits after it are the cost factor, and the rest holds the salt and the hash.

Is my string a hash or Base64?

Hex hashes use only 0–9 and a–f. Base64 mixes upper and lower case letters, digits, + and /, and often ends with =.

Sources

Added . What's new