Skip to content
secureSHA-2 · 256 bits · 2001

SHA-256

The default cryptographic hash for the modern web. TLS certificates, Bitcoin, GitHub's new object IDs: all SHA-256 underneath.

By ·

SHA-256 is one member of the SHA-2 family designed by the NSA and standardized by NIST in 2001. It's the default cryptographic hash for new systems: TLS certificate signatures, the Bitcoin proof-of-work hash, JWT's HS256 / RS256 signing, AWS Signature V4, Git's next-generation content addressing. Anywhere you'd reach for a hash today and don't have a reason to pick something else, the right answer is usually SHA-256. It produces a 256-bit (32-byte) digest and is implemented natively in every CPU shipped in the last decade via the Intel SHA-NI / ARMv8 cryptography extensions, so its real-world throughput is excellent. There are no known practical attacks against SHA-256; the closest theoretical result is a length-extension attack which is mitigated by using HMAC-SHA256 (or by switching to SHA-3 / BLAKE3 which are immune by construction).

Recommended uses

  • ·Default cryptographic hash for new designs
  • ·File integrity checksums shared publicly
  • ·HMAC-SHA256 for API request signing
  • ·Building blocks for Merkle trees (Bitcoin, Git, ZK proofs)

Known attacks / caveats

  • ·Length-extension attack on the bare construction; use HMAC-SHA256 if you need MAC semantics

Designed by

NSA, published 2001.

Hash some text →Compare against other algorithms →

Frequently asked questions

Is SHA-256 secure in 2026?
Yes. SHA-256 has no practical breaks as of 2026. Caveats worth knowing: Length-extension attack on the bare construction; use HMAC-SHA256 if you need MAC semantics.
What is SHA-256 used for?
Default cryptographic hash for new designs. File integrity checksums shared publicly. HMAC-SHA256 for API request signing. Building blocks for Merkle trees (Bitcoin, Git, ZK proofs).
How long is the output of SHA-256?
256 bits, which is 32 bytes, or 64 characters when written as hexadecimal. The length is fixed regardless of how large the input is.
Can SHA-256 be used to hash passwords?
No, and this is the most consequential mistake people make with it. SHA-256 is a fast general-purpose hash, and fast is exactly the wrong property for passwords: it lets an attacker with a stolen database test billions of guesses. Use a purpose-built password hashing function such as Argon2id instead.
Who created SHA-256?
NSA, published in 2001.