Compare file integrity with a SHA-256 checksum
Calculate the digest of the actual bytes and compare it with a trusted reference.
Select the file, not its name
Choose the SHA-256 operation and select a file up to 10 MB. The browser reads the file’s bytes and computes the digest using the Web Crypto API. The filename is not included in the hash.
The output is a 64-character lowercase hexadecimal value in a text file. Renaming a file without changing its bytes produces the same digest. Changing even one byte generally produces a different digest.
Use a known fixture
A file containing exactly the three ASCII bytes abc, without a newline, has the digest shown below. Save that exact file to verify your workflow. A text editor that appends a newline will produce a different result.
An empty file is also a valid hash input. SHA-256 works on binary data as well as text; this operation does not decode or convert the selected file.
ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad
A hash is not a safety certificate
Matching a trusted digest gives evidence that the bytes match the reference. It does not prove that the file is harmless or that its source is legitimate. Obtain the reference digest through a trusted channel.
If an attacker controls both a download and its published checksum, a match does not establish authenticity. Digital signatures and authenticated distribution serve different purposes.
Record and compare carefully
Compare all 64 characters, not only a short prefix. Check that both sides refer to the same release and file format. A compressed archive and its extracted file have different hashes.
The downloaded digest contains only the hexadecimal value, so you can compare it with your operating system’s SHA-256 utility. The file never leaves your device through this tool.
Open tool