MariaDB SHA2() Function
Learn MariaDB SHA2() syntax, supported digest lengths, NULL behavior, and why a fast SHA-2 digest is not a password hash.
On this page
MariaDB SHA2(str, hash_len) computes a digest from the SHA-2 family. The supported lengths are 224, 256, 384, and 512 bits; 0 is equivalent to 256. The result is a hexadecimal string, or NULL if the input is NULL or the hash length is invalid. MariaDB notes that SHA2() requires TLS support in the server build. See the official SHA2() documentation.
Syntax
SHA2(str, hash_len)
Examples
Calculate a SHA-256 digest:
SELECT SHA2('Hello, World!', 256);
Result:
dffd6021bb2bd5b0af676290809ec3a53191dd81c7f70a4b28688a362182986fUsing 0 selects the same 256-bit digest:
SELECT SHA2('Hello, World!', 0);
SHA2() is a fast, general-purpose hash function. It can be useful for checksums and digest comparisons, but it is not a password-hashing function. Do not store application passwords using SHA2(password, 256); an attacker with the digest can test guesses quickly. Use an adaptive password-hashing library such as Argon2id, bcrypt, or PBKDF2 instead. See the OWASP Password Storage Cheat Sheet.
Summary
Use SHA2() when you need a digest from the SHA-2 family. It does not encrypt data and should not be used alone to store application passwords.