Menu

MariaDB SHA1() Function

Learn MariaDB SHA1() syntax, its 40-character SHA-1 result, the SHA() alias, and why it is not for password storage.

Posted on By Updated on
On this page

MariaDB SHA1(str) computes the SHA-1 digest of str and returns a 40-character hexadecimal string. SHA(str) is a synonym. If str is NULL, the result is NULL. See the official SHA1() documentation.

Syntax

SHA1(str)

Example

SELECT SHA1('Hello, World!');

Result:

0a0a9f2a6772942557ab5355d76af442f8f65e01

The output contains 160 bits represented as 40 hexadecimal characters. SHA-1 is a legacy digest and should not be chosen for new security-sensitive designs. It is also a fast hash, not a password-storage algorithm. Do not store application passwords using SHA1() or SHA(). Use a maintained password-hashing library, such as one implementing Argon2id, bcrypt, or PBKDF2; see the OWASP Password Storage Cheat Sheet.

For the SHA-2 family of MariaDB digest functions, see SHA2().

Summary

SHA1() returns a 40-character SHA-1 digest; SHA() is its alias. The result is a one-way digest, not reversible encryption, and should not be used to store application passwords.