SHA256 example
curl -X POST https://aisenseapi.com/services/v1/sha256_hash \
-H "Content-Type: application/json" \
-d '{"data":"Hello"}'{
"sha256_hash": "185f8db32271fe25f561a6fc938b2e264306ec304eda518007d1764826381969"
}Each endpoint uses its own response key. There is no generic hash field.
Available algorithms
| Endpoint | Response key | Result for Hello |
|---|---|---|
| /md5_hash | md5_hash | 8b1a9953c4611296a827abf8c47804d7 |
| /sha1_hash | sha1_hash | f7ff9e8b7bb2e09b70935a5d785e0cc5d9d0abf0 |
| /sha256_hash | sha256_hash | 64-character hexadecimal string |
| /sha512_hash | sha512_hash | 128-character hexadecimal string |
| /sha3_256_hash | sha3_256_hash | 64-character hexadecimal string |
| /sha3_512_hash | sha3_512_hash | 128-character hexadecimal string |
| /blake2b_hash | blake2b_hash | 64-character hexadecimal string |
| /blake3_hash | blake3_hash | 64-character hexadecimal string |
| /whirlpool_hash | whirlpool_hash | 128-character hexadecimal string |
| /crc32_checksum | crc32_checksum | 4157704578 |
crc32_checksum is returned as an integer. The nine cryptographic hash endpoints return hexadecimal strings. SHA3-256, SHA3-512, BLAKE2b-256 and Whirlpool were added on 2 October 2026 and BLAKE3 on 3 October; BLAKE2b-256 is BLAKE2b with a 32 byte output, not the first half of BLAKE2b-512, and BLAKE3 input is at most 1 MiB.
Password hashes: Argon2id, bcrypt and scrypt
Three endpoints hash a password the slow, salted way: POST /argon2id_hash (64 MiB, three passes), POST /bcrypt_hash (cost 12, at most 72 bytes) and POST /scrypt_hash (N 2^17, r 8, p 1). Send JSON {"password":"..."} or a text/plain body, 1 to 1024 bytes. Every call gives a new string that carries its algorithm, salt and cost, in the PHC format for Argon2id and scrypt and the modular crypt format for bcrypt, so it verifies in PHP, Python, Node and most other libraries.
curl -X POST https://aisenseapi.com/services/v1/argon2id_hash \
-H "Content-Type: application/json" \
-d '{"password":"correct horse battery staple"}'
{"argon2id_hash":"$argon2id$v=19$m=65536,t=3,p=1$mWHnZ4Nxo3vEDMtb9cO7/A$PUXcfBGwUfBbXE1GgMiw4yPbY31fklKc0mRW99HBcsQ"}POST /password_verify with password and hash checks one. The algorithm is read from the string, a $2y$ string from PHP included, and the answer is match, algorithm and params with the cost that was read. A string that asks for more work than these profiles is refused with 400, so nobody chooses how much a verification costs you.
Use test data. The hash is kept by nobody here, but the password travels to a public service, and a real password belongs to the application that uses it. One call is 100 to 230 ms of CPU, so the routes have a budget of 200 operations per IP address per day on top of the 5000 calls every address has, and 20 000 per day for everyone. The hashing runs in a process of its own, one computation at a time; while it is busy the answer is 503 with Retry-After 1, and the rest of the API is untouched.
Input formats
JSON
Send an object with a data field.
{ "data": "Hello" }Plain text
Set Content-Type: text/plain and send the text as the request body.
curl -X POST .../sha256_hash \
-H "Content-Type: text/plain" \
--data-binary "Hello"File upload
Upload a file with multipart/form-data. The endpoint hashes the submitted file content.
Choose the right result
SHA256 or SHA512
Use a modern hash when you need a content fingerprint or integrity comparison.
SHA3 or BLAKE2b
Use SHA3 when a standard asks for it, or when you want a hash built differently from SHA2. BLAKE2b-256 is fast and gives the same length as SHA256.
Whirlpool
Use it for compatibility with systems that store Whirlpool fingerprints, such as some file catalogs and older archive tools.
MD5 or SHA1
Use these only when an existing format or legacy integration requires them.
CRC32
Use a checksum for quick accidental-corruption checks where cryptographic strength is not required.
File comparison
Hash two files and compare the values to check whether their bytes match.
Security notes
MD5 and SHA1 are not suitable for security-sensitive collision resistance. None of these endpoints should be used to store passwords. Password storage requires a slow, salted password-hashing function.
A hash is not encryption. It cannot be decoded back to the original input. Do not send confidential input to a public service when the hash can be calculated inside your own application. None of the ten digests here is a password hash; for passwords use the Argon2id, bcrypt and scrypt endpoints above, with test data.
Verify a hash
POST /hash_verify checks data against a digest from any endpoint on this page. Name the algorithm in an algorithm field when you know it, and always for sha3_256, sha3_512, blake2b, blake3 and whirlpool, whose lengths collide with SHA256 and SHA512. Password hashes are checked by /password_verify. Without the field the algorithm is recognized from the hash itself: an integer means crc32, hex strings map by length. A mismatch is a result with match: false, and computed is always included so the difference is visible.
curl -X POST https://aisenseapi.com/services/v1/hash_verify
-H "Content-Type: application/json"
-d '{"data": "Hello", "hash": "185f8db32271fe25f561a6fc938b2e264306ec304eda518007d1764826381969"}'
{ "match": true, "algorithm": "sha256", "computed": "185f8db3..." }