Skip to content

Hash Task

Overview

The Hash Task generates cryptographic hash values from text using industry-standard algorithms (SHA-512, SHA-256, SHA-1, or MD5). Hashes are one-way functions that convert data into fixed-length strings, perfect for data integrity checks, cache keys, API signatures, and deduplication.

When to use this task:

  • Generate unique identifiers from data
  • Verify data integrity and detect tampering
  • Create API signatures for authentication
  • Generate cache keys from request parameters
  • Deduplicate content by comparing hashes
  • Create idempotency keys for APIs
  • Generate consistent IDs from variable inputs

Key Features:

  • Four hash algorithms (SHA-512, SHA-256, SHA-1, MD5)
  • One-way cryptographic function
  • Deterministic (same input = same hash)
  • Fast computation
  • Hexadecimal output
  • Variable support
  • Collision resistant (SHA-256+)

Quick Start

1. Add Hash task
2. Select algorithm (SHA-256 recommended)
3. Enter text to hash
4. Returns hexadecimal hash string
5. Save

Configuration

Builder fields

The Field column is the label as it appears in the task builder; Key is the name the value is stored under and referenced by.

Field Key Type Default Notes
Algorithm hash_type select MD5 Options: MD5 · SHA-1 · SHA-256 · SHA-512
Input input text –

Hash Algorithm

SHA-512 (recommended for security)
SHA-256 (standard, widely used)
SHA-1 (legacy, not for security)
MD5 (checksums only, not secure)

Input Text

Input: Hello World
Input: {{task_55001_email}}{{task_55001_timestamp}}
Input: {{task_46001_request_body}}

Any text, including variables from previous tasks.

Output Fields

Field Description Example
task_33001_run Success status true
task_33001_run_text Result message Successfully hashed.
task_33001_hash Generated hash (hex) a591a6d40bf420404a011...

Hash Algorithm Comparison

Algorithm Length Use Case Security
SHA-512 128 hex chars Maximum security, sensitive data ✓✓✓ Excellent
SHA-256 64 hex chars Standard security, most common ✓✓✓ Excellent
SHA-1 40 hex chars Legacy systems only ⚠️ Deprecated
MD5 32 hex chars Checksums, non-security uses ❌ Broken

Recommendation: Use SHA-256 for most cases, SHA-512 for maximum security.

Real-World Examples

Fingerprint a payload to spot repeats

Webhook In
  └─ Hash          SHA-256 of the incoming order reference

{{task_33001_hash}} is a short, fixed-length fingerprint of the input. The same input always produces the same hash, so two payloads that hash alike are the same payload.

Mask an identifier before sending it out

Webhook In
  └─ Hash          SHA-256 of the ID number
      └─ Webhook Out   send the hash, not the ID

Hashing is one-way. The receiving system can match records by fingerprint without ever holding the original value.

Verify a value has not changed

Schedule
  └─ Google Sheets   get_rows — read the current config row
      └─ Hash        SHA-256 of the row

Compare {{task_33001_hash}} against the hash you stored last time. Different hash, something changed.

Best Practices

Algorithm Selection

  1. SHA-256 - Default choice for most use cases
  2. SHA-512 - When maximum security required
  3. SHA-1 - Only for legacy system compatibility
  4. MD5 - Only for non-security checksums

Security Considerations

✓ DO use for:
- Data integrity verification
- Idempotency keys
- Cache keys
- Content deduplication
- API signatures (with secret)

❌ DON'T use for:
- Direct password storage (use bcrypt/argon2)
- Encryption (hash is one-way)
- Sensitive data exposure (hash is deterministic)

Input Preparation

  1. Normalize data - Remove whitespace, consistent formatting
  2. Sort parameters - Ensure consistent order
  3. Include context - Add secrets for signatures
  4. Document format - Specify what's being hashed

Collision Handling

  • SHA-256/512: Virtually impossible to find collisions
  • SHA-1: Known collision attacks exist
  • MD5: Collisions easily generated
  • Always use SHA-256+ for security-sensitive applications

Troubleshooting

Different Hash Each Time

Issue: Same input produces different hashes

Causes:

  • Input includes timestamp or random data
  • Variable not properly resolved
  • Extra whitespace or formatting

Solution:

# Include only stable data
Wrong: {{task_46001_data}}{{current_timestamp}}
Right: {{task_46001_data}}

# Debug input
Code Task: return {input_debug: input.task_46001_data};

Hash Comparison Fails

Issue: Hashes don't match when they should

Causes:

  • Case sensitivity in input
  • Extra whitespace
  • Different encoding
  • Variable order changed

Solution:

# Normalize before hashing
Formatter: LOWERCASE {{input}}
Find Replace: Remove extra spaces

# Use same input format
Document expected format clearly

Security Concerns

Issue: Need to hash passwords

Solution:

❌ Don't use Hash task for passwords
✓ Use proper password hashing:
  - bcrypt
  - argon2
  - PBKDF2 with salt

Hash task is for data integrity, not password storage.

Frequently Asked Questions

Can I reverse a hash?

No, hashes are one-way functions. Cannot retrieve original input from hash.

Are hashes unique?

Practically yes for SHA-256/512. Collisions are mathematically possible but virtually impossible to find.

Can I use this for passwords?

No, use dedicated password hashing libraries (bcrypt, argon2) that include salting and key stretching.

What's the difference between SHA-256 and SHA-512?

SHA-512 is more secure (longer hash) but slower. SHA-256 is industry standard and sufficient for most uses.

Can I hash files?

Yes, provide file content as input. For large files, consider using Code task with streaming hashing.

Is MD5 secure?

No, MD5 is cryptographically broken. Use only for non-security checksums. Never for passwords or integrity verification.

Do I need a secret key?

Not for basic hashing. For API signatures (HMAC), combine data with secret before hashing.


  • Variable - Store hash for later comparison
  • If Task - Compare hashes to verify integrity
  • Merge Data - Combine data before hashing
  • Code Task - Complex hashing logic or HMAC
  • Webhook Out - Include hash in API requests