Free tool by MD Niamul

Free SHA-256 Hashing Code Generator GTM Variables That Format and Hash Email, Phone and Address for Every Ad Platform

Give It Your Variable. Get Ready Code for Each Platform’s Rules.

Runs in your browser
8 platform formats
Test a value live

Every ad platform wants customer data cleaned in its own way before it is hashed. Tell this free hashing code generator where your email, phone or address value lives and it writes a GTM SHA-256 hash variable for each one, a single Custom HTML tag that pushes all hashes to the dataLayer, and plain JavaScript. Use it to hash email for Meta CAPI, to build enhanced conversions hashing code for Google, and for TikTok, Pinterest, Snapchat, LinkedIn and Microsoft.

8Platform formats
12Customer data fields
850+Projects delivered
600+Five-star reviews
MD Niamul, creator of the free sha-256 hashing code generator
upworkTop Rated Plus
SHA-256 for GTMFree Code Generator
OfficialStape Partner

What the Hashing Code Generator Builds

Email Hashing
Phone to E.164
Gmail Dot Rule
GTM Custom JavaScript
Custom HTML Tag
dataLayer Event
Google Enhanced Conversions
Meta Conversions API
TikTok Events API
Pinterest
Snapchat
LinkedIn
Microsoft UET
ES5 SHA-256
Live Value Tester
Rules Table
Excel Download
No Double Hashing
FREE HASHING CODE GENERATOR

Generate Your SHA-256 Hashing Code

Tick your fields, name your variables and choose your platforms. The code updates as you type.

SHA-256 Hashing Code GeneratorGTM variables · Custom HTML tag · Plain JavaScript · Setup steps · Rules table
Free · No login

1. Your fields

Tick what you have. Then say where each value comes from: a GTM variable name, a dataLayer key such as user_data.email, a JavaScript expression, or the CSS selector of a form field.

2. Platforms

3. Options

Your code

Test a value

Type a made-up sample to see what each selected platform would receive. The result comes from the same functions that are printed in your code, so it shows exactly what the code will produce. Nothing you type here leaves your browser.

The code is written in your browser. We keep a simple log of the options chosen: the platforms, the fields and the source types. Your variable names, your code and the test values you type are not logged and stay in your browser.

Follows each platform’s published rulesCopy or download every fileTest values stay in your browser
WHAT IT BUILDS

What Does the Hashing Code Generator Give You?

Your own variables, filled into code that formats each value the way the platform asks, then hashes it.

GTM Custom JavaScript Variables

One per field and format. Each returns the hash straight away and needs nothing else.

One Custom HTML Tag

Reads every field, hashes it and pushes one dataLayer event with a clear object per platform.

Shared Variables Where Rules Match

When two platforms want the same format, they share one variable, named after both.

Phone Number Formatting

E.164 with a “+” for Google, TikTok and Microsoft. Digits only for Meta, Pinterest and Snapchat.

Live Value Tester

Type a sample and see the formatted value and the hash per platform, from the same functions as your code.

Rules Table

Field by platform: the format rule, hashed or plain, and the exact parameter name.

GTM Setup Steps

Numbered steps, the trigger to create and every Data Layer Variable to add.

Excel Download

The rules, your variables and the code in one workbook for your notes or your developer.

How Does the Hashing Code Generator Work?

Three steps. The code is written in your browser.

01

Tick your fields

Email, phone, name, address, date of birth, gender or customer ID. Say where each value comes from.

02

Choose your platforms

Pick one or several. The generator works out which fields share a format.

03

Copy the code

Take the GTM variables or the single tag, test a sample value, then check it in GTM Preview.

Why Does Each Platform Need a Different Hash?

A SHA-256 hash turns a value such as an email address into a fixed string of 64 letters and numbers. Ad platforms compare your hash with the hashes of their own users. If the two match, the conversion is matched to a person.

The catch is that one changed character gives a completely different hash. [email protected] and [email protected] do not match. So each platform publishes rules for cleaning a value before it is hashed, and the rules are not the same. Meta wants a phone number as digits only with the country code. Google wants the same number in E.164 format with a “+” in front. Google removes the dots from Gmail addresses. Microsoft removes dots and “+suffixes” from every address.

Do you need to hash at all?

Often you do not. The Google tag, the Meta Pixel, the TikTok Pixel, the Pinterest JavaScript tag and Microsoft’s UET tag can take a plain value and hash it for you in the browser. You need your own hashing code when you build the payload yourself: Conversions API and Events API calls, server-side setups that expect hashed keys, offline uploads, and custom tags or templates that do not hash. The tool shows what each platform you pick does for you.

How to use a GTM SHA-256 hash variable

A GTM SHA-256 hash variable is a Custom JavaScript variable that reads your value, formats it and returns the hash. A Custom JavaScript variable must return its answer straight away, and the browser’s built-in hashing answers later, so each variable carries its own small SHA-256 function. The code is written in ES5, the older JavaScript style, because Custom JavaScript variables and Custom HTML tags are checked against it.

The Custom HTML tag is the other route. It uses the browser’s built-in hashing when it is available and pushes one event, such as user_data_hashed, that your other tags can use as a trigger.

Is hashed data anonymous?

No. Hashing is not anonymisation. A hashed email still points to one person, and the platform can match it. It is still personal data, so you still need consent or another legal basis to collect and send it, and your tags should respect the visitor’s consent choice.

What this tool cannot check

  • It formats values by each platform’s published rules. It cannot see your website, so it cannot check that your variable really holds an email or a phone number. Test in GTM Preview.
  • Platforms change their rules. The rules here follow the platforms’ documentation as read in October 2026. Check the platform’s help page before a big launch.
  • Some rules could not be confirmed and the tool says so instead of guessing: a hashed street key for the Google tag, TikTok’s name and address fields, and how the Snapchat Pixel and LinkedIn Insight Tag treat plain values.
  • A phone number with no country code cannot be fixed safely. Set a default country calling code, or make your site pass the full number.
  • It does not send anything to an ad platform and cannot tell you your match rate.

Which Platforms Hash for You, and When You Must Hash Yourself

A quick guide. The tool’s rules table has the format for every field.

PlatformDoes the browser tag hash plain values?You hash yourself forPhone format
Google AdsYes. The Google tag and GTM user-provided dataThe sha256_ keys, server and custom setupsE.164 with “+”
MetaYes. Pixel advanced matchingConversions APIDigits only, with country code
TikTokYes. Pixel identifyEvents APIE.164 with “+”
PinterestYes, for email in the JavaScript tagImage tag and Conversions APIDigits only, with country code
SnapchatCheck Snapchat’s help pageConversions APIDigits only, with country code
LinkedInCheck LinkedIn’s help pageConversions API (email)No phone field
Microsoft AdsYes. UET formats and hashes email; phone must already be E.164Offline conversion uploadsE.164 with “+”

Who Is This Generator For?

GTM specialists

Stop rewriting the same hashing variable for every client and platform.

Developers

Get the exact format per platform without reading seven sets of documentation.

Agencies

Hand over a clear setup: the code, the variables to create and the rules behind them.

Store and site owners

Understand what your tracking sends before you hire someone to build it.

MORE FREE TOOLS

More Free Marketing Tools by MD Niamul

33 free tools for tracking, analytics, advertising and SEO. No login needed.

Free GA4 Event Checker

Validate GA4 event names and parameters against Google’s rules before you publish.

Open the GA4 event checker →

Free Form Tracking Listener Generator

Get GTM listener code for HubSpot, GoHighLevel, iframe and native forms that pushes a clean dataLayer event.

Open the listener generator →

Free dataLayer Generator

Build ready-to-paste dataLayer code for GA4 ecommerce and lead events.

Open the dataLayer generator →

Free Meta CAPI Payload Builder

Build and validate a Conversions API event with hashed user data and a matching pixel call.

Open the CAPI builder →

Trusted by 600+ Brands & Agencies

MYLENE
HOVER BOARDS
GT SOLI
CAMBRIDGE
BIENEN CORB 24
ZULU SHACK CREATIVE
ADPSY LLC
HIGH PERFORMANCE MEDIA
ADS PERFORMANCE
LEGESI
TESTIMONIAL

Analytics & Conversion Tracking Client Testimonials

Hear from our clients. Loved by 600+ businesses worldwide.

Madison Jonas, client of MD Niamul
Madison JonasGoogle Ads clientLinkedIn recommendation
★★★★★

“I had an excellent experience working with MD on my Google Ads account. Everything was set up perfectly and worked smoothly without any issues or troubleshooting needed. His expertise and attention to detail made the whole process effortless.”

Mehboob Khan, client of MD Niamul
Mehboob KhanGoogle Analytics projectsLinkedIn recommendation
★★★★★

“I worked with Niamul on multiple Google Analytics projects and was impressed by his expertise and precision. He has a strong grasp of tracking, reporting, and optimization, always ensuring accurate insights. He is proactive, reliable, and easy to collaborate with.”

Jacco Bouw, client of MD Niamul
Jacco BouwShopify, GA4 & Google Ads trackingLinkedIn recommendation
★★★★★

“MD Niamul is extremely skilled. He fixed my Shopify, Google Analytics, and Google Ads conversion tracking perfectly. Everything works exactly as it should now, and he even added an extra data layer, which was very helpful. Outstanding service, fast delivery, and highly recommended.”

Ryan S Kemp, client of MD Niamul
Ryan S KempCMO, Co-Founder, Zulu Shack CreativeLinkedIn recommendation
★★★★★

“Reliable, knowledgeable, and truly trustworthy. I’ve been working with Niamul for over a year, and he consistently delivers exceptional results across all analytics tasks. His expertise, communication, and commitment make him my go-to specialist for tracking, measurement, and data accuracy.”

Casper Klein, client of MD Niamul
Casper KleinMeta Pixel & server-side trackingLinkedIn recommendation
★★★★★

“MD N delivered flawless Meta Pixel, CAPI, and server-side tracking. He understood our goals quickly, explained everything clearly, and ensured full transparency. Communication was smooth, updates were consistent, and the results improved our data accuracy and ad performance.”

600+

Five-star reviews from businesses and agencies in the USA, Canada, UK and Australia.

Read All Reviews

Video Testimonials: Hear It From Our Clients

FAQ

Frequently Asked Questions About the Free SHA-256 Hashing Code Generator

Is the hashing code generator free?

Yes. It is free with no login. The code is written in your browser.

How do I create a SHA-256 hash variable in GTM?

Tick the field, type the name of your GTM variable and choose the platform. Copy the code from the GTM variables tab, then in Google Tag Manager go to Variables, New, Custom JavaScript, paste it and save it with the name shown.

How should I hash an email for Meta CAPI?

Trim the spaces, make it lowercase, then hash it with SHA-256 and send it as em. For a phone number Meta wants digits only, with the country code and no leading zeros, sent as ph.

What format does Google want for enhanced conversions?

Lowercase and trim the email, and remove the dots before the @ on gmail.com and googlemail.com addresses. Phone numbers go in E.164 format with a “+”. First and last name are hashed. City, region, postcode and country are sent as plain text.

Do I need to hash data before sending it to the Google tag or the Meta Pixel?

Usually not. Both can take plain values and hash them in the browser. You hash yourself for Conversions API and Events API payloads, server-side setups that expect hashed keys, offline uploads and custom tags that do not hash.

Why does the code include its own SHA-256 function?

A Custom JavaScript variable in GTM must return its value straight away. The browser’s built-in hashing gives its answer later, so it cannot be used there. The Custom HTML tag does use the built-in hashing when it is available.

Is hashed data anonymous?

No. A hashed email is still personal data because it can be matched back to a person. You still need consent or another legal basis to send it.

What happens if my value is already hashed?

The code spots a 64-character hash and passes it on unchanged, in lowercase. It never hashes twice, because a hash of a hash matches nobody.

Are the values I type into the tester sent anywhere?

No. Test values are worked out in your browser and are not stored, logged or sent. We only log which platforms, fields and source types were chosen.

Need Hashed Data and Server-Side Tracking Set Up for You?

I am MD Niamul, a conversion tracking and web analytics specialist and an official Stape partner. I set up enhanced conversions, Conversions API and server-side tagging, with customer data formatted and hashed correctly for each platform and tested end to end.