Skip to main content

hash_sha1

Compute the SHA-1 (160-bit) hash of a UTF-8 string. Returns a 40-character lowercase hexadecimal digest.

warning

SHA-1 is cryptographically broken and must not be used for security-sensitive purposes such as digital signatures, certificate fingerprints, or password hashing. It is provided here for compatibility with legacy systems, checksums, and protocols that still require SHA-1 (e.g. Git object IDs).

Parameters​

ParameterTypeRequiredDescription
inputstringYesThe UTF-8 string to hash.

Response​

FieldTypeDescription
hashstringLowercase hexadecimal digest.

Examples​

Hash a non-empty string​

{
"input": "hello world"
}

Result:

{
"hash": "2aae6c35c94fcfb415dbe95f408b9ce91ee846ed"
}

Hash an empty string​

The SHA-1 digest of the empty string is a well-known constant and a useful baseline for verifying tool output:

{
"input": ""
}

Result:

{
"hash": "da39a3ee5e6b4b0d3255bfef95601890afd80709"
}

Errors​

Each failure carries a precise code in the response. Argument-schema and server errors are JSON-RPC protocol errors; a rejected value is returned as a tool result with isError: true (so the agent can read the code and self-correct).

CodeWhenDelivered as
invalid_argumentsThe input field is missing or not a string.protocol error (invalid_params)
internal_errorAn unexpected server error.protocol error (internal_error)

Notes​

  • The input is always treated as a UTF-8 string. If you need to hash raw bytes, hex-encode them first.
  • The digest is always 40 lowercase hex characters (160 bits).
  • SHA-1 output is deterministic — the same input always produces the same digest.
  • For new applications requiring a secure hash, prefer hash_sha256, hash_sha512, or hash_blake3.