Hash Generator (MD5, SHA-256)→Specialized Version
#️⃣

Session ID Generator

Session ID Generator

Session ID

Bytes of entropy, hex encoded — OWASP recommends at least 16.

  • 50ade687af8388a557a376ca66472c25d6be0c71e0745e8f965f22afb945d7e50ad7c2372aa22c44d6570b62f53f022d

Values come from crypto.getRandomValues, the browser's CSPRNG. They are generated locally and never sent anywhere — but a secret that has been displayed on screen is only as private as the screen.

Session ID Generator

A session identifier is what turns a stateless HTTP request into a logged-in user. It is a bearer credential with a specific set of well-documented attacks, and the defences are mostly about the cookie rather than the value.

Length and Randomness

OWASP recommends at least 128 bits of entropy — 16 random bytes, 32 hex characters — from a cryptographically secure generator. Sequential or predictable session IDs allow an attacker to guess a valid session and assume that user's identity outright.

The Cookie Attributes Are the Real Defence

AttributeEffectSet it to
HttpOnlyJavaScript cannot read the cookieAlways
SecureSent only over HTTPSAlways
SameSiteControls cross-site sendingLax or Strict
PathLimits which paths receive it/ usually
DomainOmit to avoid sharing with subdomainsOmit
Max-AgeIdle and absolute lifetimeBoth, explicitly
HttpOnly is what turns a cross-site scripting bug from "session stolen" into "script ran". SameSite is the primary defence against cross-site request forgery.

Regenerate on Privilege Change

Session fixation works by getting a victim to use a session ID the attacker already knows, then waiting for them to log in. The fix is one line: issue a new session ID on login, and again on any privilege escalation. Do not merely add data to the existing session.

Two Timeouts, Not One

An idle timeout ends a session after inactivity; an absolute timeout ends it after a fixed period regardless. Both are needed — an idle timeout alone lets a stolen session live indefinitely as long as it is used.

Server-side invalidation is what makes logout mean anything. Deleting the cookie without deleting the server record leaves a working credential in whatever captured it.

Storage

Sessions in a shared store — Redis, a database — allow revocation, "log out everywhere", and horizontal scaling. Signed-cookie sessions avoid the store at the cost of losing all three. For anything with an account and a password, the store is usually worth it.

The Avalanche Effect

A one-character change produces a completely different digest — not a similar one. That property is what makes a hash useful as a fingerprint:

InputMD5CRC32
hello5d41402abc4b2a76b9719d911017c5923610a686
hello.d94c10e437d18531e122ed0b45badd2a0a39d4f1
Hello8b1a9953c4611296a827abf8c47804d7f7d18982
hello and Hello differ by one bit of one byte, and share no part of their output. RIPEMD-160 of hello is 108f07b8382412612c048d07d13f814118445acd, and of Hello is d44426aca8ae0a69cdbc4021c64fa5ad68ca32fe — same story.

Digest Length and Collision Resistance

AlgorithmOutputBirthday boundStatus
CRC3232 bits~77,000 valuesChecksum only
MD5128 bits2⁶⁴ in theoryBroken — collisions in seconds
SHA-1160 bits2⁸⁰ in theoryBroken — SHAttered, 2017
RIPEMD-160160 bits2⁸⁰No practical attack
SHA-256256 bits2¹²⁸Current standard
SHA-512512 bits2²⁵⁶Standard, faster on 64-bit
The birthday bound is where a 50% chance of *some* collision appears among random inputs. MD5 and SHA-1 fall far short of theirs because both have practical collision attacks — you can construct two different files with the same digest, which is precisely what a signature must prevent.

Never Hash a Password With These

A general-purpose hash is designed to be fast, which is exactly wrong for passwords: speed helps the attacker. Use a deliberately slow KDF — bcrypt, scrypt or Argon2id — with a per-password salt. A GPU tries billions of SHA-256 guesses a second and a few thousand bcrypt guesses a second, and that gap is the entire defence.

Frequently Asked Questions

Is this SESSION truly random?

Yes, generation uses cryptographically secure random number generation (CSPRNG) suitable for security-sensitive applications.

Can two generated values ever be the same?

While theoretically possible, the probability is astronomically low. For UUIDs, there are 2^122 possible values—collision is practically impossible.

Are generated values stored anywhere?

No, all generation happens locally in your browser. Nothing is sent to any server, ensuring complete privacy.

Related Tools

Explore other tools you might find useful:

More Hash Generator (MD5, SHA-256) tools

You might also need