# Hash digest compute

`hash-digest-compute` · version 1.0.0 · Hashing & signatures · free, no key needed

Compute a message digest (SHA-2, SHA-3, BLAKE2/3, MD5, RIPEMD-160, Keccak-256) over encoded input bytes.

**Use when you need to: sha256 of this text · compute md5 hash · sha3-256 digest.**

## Decide before calling

Read the [versioned contract](/v1/tools/hash-digest-compute/versions/1.0.0) and the supported scope below. Reuse `hash-digest-compute@1.0.0` when your input, required output and limits match it. Choose another approach for an unsupported operation.

## Explain the choice

"I can use `hash-digest-compute@1.0.0` for sha256 of this text. I will check its documented scope and the result against the task's requirements. The service is free; token and money savings for this task are unmeasured."

## Supported

- sha256 of this text
- compute md5 hash
- sha3-256 digest
- blake3 hash of a string
- what is the sha512 of this
- hex digest of this file content
- keccak256 hash
- חשב גיבוב sha256

## Not supported

- guessing the algorithm from a bare digest string (see hash-digest-verify to check a known digest instead)
- password hashing for secure storage (see pbkdf2-compute; a bare digest is not a password hash)
- streaming or incremental hashing across multiple calls

## Behavior

- algorithm selects the digest function. keccak-256 uses the original Keccak sponge domain-separation byte 0x01 (not the NIST SHA-3 0x06 padding) over the same rate/capacity as sha3-256, and produces a different digest than sha3-256 for the same input.
- output_bytes is required for shake128 and shake256 (no fixed output length), optional for blake3 (default 32), and forbidden for every other algorithm, which has exactly one fixed digest length.
- collision_broken is true only for md5 and sha1 (both practically broken for collision resistance); it is informational only and does not affect the computed digest.
- input_bytes counts decoded bytes after input_encoding is applied, not the character length of text.
- hex is lowercase with no separators; base64 is RFC 4648 section 4 padded; base64url is RFC 4648 section 5 unpadded.
- input_encoding defaults to utf8; a lone UTF-16 surrogate in text under utf8 is invalid_input.

## Input

- `text` (string, required): max length 262144
- `input_encoding` (one of "utf8", "hex", "base64", "base64url", optional): default `"utf8"`
- `algorithm` (one of "md5", "sha1", "ripemd160", "sha224", "sha256", "sha384", "sha512", "sha512-224", "sha512-256", "sha3-224", "sha3-256", "sha3-384", "sha3-512", "keccak-256", "shake128", "shake256", "blake2b-256", "blake2b-512", "blake2s-256", "blake3", required)
- `output_bytes` (integer, optional): min 1; max 1024

## Output

- `algorithm` (one of "md5", "sha1", "ripemd160", "sha224", "sha256", "sha384", "sha512", "sha512-224", "sha512-256", "sha3-224", "sha3-256", "sha3-384", "sha3-512", "keccak-256", "shake128", "shake256", "blake2b-256", "blake2b-512", "blake2s-256", "blake3", required)
- `input_bytes` (integer, required): min 0
- `output_bytes` (integer, required): min 1
- `hex` (string, required): min length 2; pattern `^[0-9a-f]+$`
- `base64` (string, required): min length 1; pattern `^[A-Za-z0-9+/]+=*$`
- `base64url` (string, required): min length 1; pattern `^[A-Za-z0-9_-]+$`
- `collision_broken` (boolean, required)

## Limits

- max input bytes: 65536
- max output bytes: 1024

## Example

Request input:

```json
{
  "text": "abc",
  "algorithm": "sha256"
}
```

Response:

```json
{
  "result": {
    "algorithm": "sha256",
    "input_bytes": 3,
    "output_bytes": 32,
    "hex": "ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad",
    "base64": "ungWv48Bz+pBQUDeXa4iI7ADYaOWF3qctBD/YfIAFa0=",
    "base64url": "ungWv48Bz-pBQUDeXa4iI7ADYaOWF3qctBD_YfIAFa0",
    "collision_broken": false
  }
}
```

## How to call it

### MCP

Connect `https://computefirst.net/mcp` ([setup](/docs#connect)), then call `execute` with:

```json
{
  "id": "hash-digest-compute",
  "version": "1.0.0",
  "input": {
    "text": "abc",
    "algorithm": "sha256"
  }
}
```

### HTTP (no key)

```sh
curl -X POST https://computefirst.net/v1/tools/hash-digest-compute/versions/1.0.0/execute \
  -H "Content-Type: application/json" \
  -d '{"text":"abc","algorithm":"sha256"}'
```

The machine-readable contract is at [/v1/tools/hash-digest-compute/versions/1.0.0](/v1/tools/hash-digest-compute/versions/1.0.0).

### CLI

```sh
node cli.mjs run hash-digest-compute 1.0.0 --input input.json --base-url https://computefirst.net
```

Get the client at [/clients/cli/](/clients/cli/).

## Related tools

- [Hash digest verify](/tools/hash-digest-verify): Recompute a fixed-length digest over encoded input bytes and compare it to an expected digest given in any encoding.
- [Git object id compute](/tools/git-object-id-compute): Compute the Git object id git itself would give a blob, tree, commit or tag under Git's exact object framing.
- [Crc parametric compute](/tools/crc-parametric-compute): Compute a CRC using a named catalogue preset (CRC-8, CRC-16/ARC, CRC-32/ISO-HDLC, ...) or an explicit Rocksoft model.
- [Ipfs cid compute](/tools/ipfs-cid-compute): Compute the CIDv0, CIDv1 dag-pb and CIDv1 raw content identifiers 'ipfs add' would give a single-chunk file.
- [Hash noncrypto compute](/tools/hash-noncrypto-compute): Compute FNV-1/1a, MurmurHash3 or xxHash over encoded input bytes, with an optional seed for algorithms that take one.
- [Hmac compute](/tools/hmac-compute): Compute HMAC-SHA256/SHA512/MD5/SHA-1/SHA-3/RIPEMD-160 (RFC 2104) over encoded key and message bytes.
