Call the free Whirlpool hash API endpoint
curl -X POST https://aisenseapi.com/services/v1/whirlpool_hash \
-H "Content-Type: application/json" \
-d '{"data":"Hello world"}'{"whirlpool_hash":"69059b5a5afe634b484da83034ce906343d453a6006c1119b1ee8963b4836396aea8b5565e9f67eeca7b08e608e79e7986a109151b0ff3267827722e7e1b1ab4"}Count the characters in that value and you get 128. That is 64 bytes, or 512 bits. The digest is a constant: any correct Whirlpool implementation returns those same characters for the eleven bytes of Hello world.
Raw bodies work too. Send the bytes as text/plain and you skip the business of escaping quotes and newlines into JSON. A file upload in a multipart field named file hashes the file's bytes the same way.
curl -X POST https://aisenseapi.com/services/v1/whirlpool_hash \
-H "Content-Type: text/plain" \
--data-binary "Hello world"{"whirlpool_hash":"69059b5a5afe634b484da83034ce906343d453a6006c1119b1ee8963b4836396aea8b5565e9f67eeca7b08e608e79e7986a109151b0ff3267827722e7e1b1ab4"}Both calls hash the same eleven bytes, so both return the same line. Trailing newlines are the classic trap. A shell echo quietly appends one, and that single extra byte rewrites every character of the digest.
Response fields
| Field | Type | Description |
|---|---|---|
| whirlpool_hash | string | Exactly 128 characters of lowercase hex. The length never varies with the input. An empty body is refused with HTTP 400 and a fix, like every endpoint in the family. |
Input is treated as bytes. Text is hashed as UTF-8, so accented letters and emoji contribute their encoded bytes rather than any abstract code point. Nothing is trimmed or normalised before hashing.
Where Whirlpool comes from, and where you meet it
Whirlpool was designed by Vincent Rijmen, one of the two designers of AES, and Paulo Barreto. It runs a dedicated 512-bit block cipher in a Miyaguchi-Preneel construction, so its internals look like AES rather than like SHA. It was adopted by ISO as one of the hash functions in ISO/IEC 10118-3, and it has had no practical attacks in its final revision.
You meet it less often than SHA-2, in a handful of places: file catalogs and integrity tools that chose it years ago, some disk encryption software, archive formats that record Whirlpool fingerprints, and standards that list the ISO functions. This endpoint exists for compatibility with those, so you can check a stored Whirlpool value without finding a library that still ships it.
The version matters. The final Whirlpool, sometimes called Whirlpool-T or version 3, is the one PHP, most libraries and this endpoint compute. The two earlier revisions, Whirlpool-0 and Whirlpool-1, produce different digests for the same input, so a value from a very old tool may not match.
The same length as SHA-512, which is a trap for verifying
A Whirlpool digest is 128 hex characters, exactly like SHA-512 and like SHA3-512. Nothing in the digest says which algorithm produced it. When you verify with POST /hash_verify, name the algorithm in an algorithm field; without it a 128-character hash is read as SHA-512, as it always was.
For new systems, SHA-256 remains the interoperability default and the SHA-512 hash API endpoint the usual 512-bit choice. Whirlpool is the right call when something you already have stores Whirlpool values.
Verify a digest, naming the algorithm
POST /hash_verify takes data, an expected hash and, for this algorithm, an algorithm field. The field is required here because a 128-character digest is also what SHA-512 produces, and without it the hash is read as that.
curl -X POST https://aisenseapi.com/services/v1/hash_verify \
-H "Content-Type: application/json" \
-d '{"data":"Hello world","hash":"69059b5a5afe634b484da83034ce906343d453a6006c1119b1ee8963b4836396aea8b5565e9f67eeca7b08e608e79e7986a109151b0ff3267827722e7e1b1ab4","algorithm":"whirlpool"}'{"match":true,"algorithm":"whirlpool","computed":"69059b5a5afe634b484da83034ce906343d453a6006c1119b1ee8963b4836396aea8b5565e9f67eeca7b08e608e79e7986a109151b0ff3267827722e7e1b1ab4"}The comparison runs in constant time, and computed comes back on a mismatch as well, so you see what your input really hashes to. The hash verify API endpoint page covers the full behaviour.
Do not store passwords this way
Never keep passwords as Whirlpool digests. Speed is a design goal of this algorithm, and speed is precisely the wrong property for password storage. Reach for a deliberately slow key derivation function instead: Argon2id, scrypt or bcrypt, each of which salts per password and exposes a tunable work factor. Since 3 October 2026 this service offers all three on their own routes, for test data: Argon2id, bcrypt and scrypt.
Common uses
Callers reach for the free Whirlpool hash API endpoint in a handful of recurring situations.
Checking stored fingerprints
File catalogs and archive tools that recorded Whirlpool digests years ago can be verified today without hunting for a library that still implements the function.
ISO-listed hash functions
When a specification points at ISO/IEC 10118-3 and names Whirlpool, this endpoint produces the exact value a reviewer will check against.
Cross-implementation debugging
When two tools disagree about a Whirlpool value, the revision is the usual reason. Hash the same input here to see what the final version gives.
A second, unrelated digest
Store a Whirlpool digest beside a SHA-2 one when you want fingerprints from two unrelated designs.
Privacy and limits
The input travels in the POST body rather than the URL, so it never lands in a request path or a proxy access log. A hash is still not encryption, and your plaintext reaches this service before it is hashed. Keep genuinely confidential material inside your own process and use this service for testing, tooling and content you are happy to send.
The free Whirlpool hash API endpoint shares the service-wide ceiling of 5000 requests per IP per day. No key, no account and no signup step stand in the way. Every route sits under the base URL https://aisenseapi.com/services/v1, and the whole catalogue is listed on Free public REST APIs.