Free · Runs on your device · No signup

Hash Generator and File Checksum Verifier

Generate and compare SHA-256, SHA-384, or SHA-512 file checksums locally to verify downloaded bytes against an expected digest.

Input and results stay in browser memory in this tab. Nothing is uploaded, logged, saved, or added to the URL. File hashing uses one bounded in-memory buffer because Web Crypto does not expose streaming digest.
Input mode

Enter text and choose an action.

Why this tool is different

Generate a deterministic SHA checksum from UTF-8 text or exact file bytes and optionally compare it with an expected hexadecimal digest. Hashing is one-way representation, not encryption, and ordinary digest comparison is not a digital signature check.

Requirements and recommendations

Generate or compare a checksum

  • Choose Text or File mode and SHA-256, SHA-384, or SHA-512.
  • Optionally enter an expected digest from an authoritative source.
  • Review the exact Match or Does not match result.
How OpenFileTools processes it

Local processing, explicit choices.

The browser passes bounded UTF-8 text or exact file bytes to Web Crypto subtle.digest. Comparison normalizes harmless case and whitespace and checks the exact algorithm length.

Quick technical summary

What this tool changes.

PropertyBehavior
ProcessingBrowser only; no image upload
OriginalNever changed
AlgorithmsSHA-256, SHA-384, SHA-512
File modeBounded to 200 MB; complete in-memory digest
Digital signature verificationNo

Verify exact bytes with a published digest

Choose SHA-256, SHA-384, or SHA-512, select a file or enter text, and optionally paste an expected digest. A match means the calculated bytes equal the bytes represented by that expected checksum.

  • Use the same algorithm named by the publisher.
  • Expected hexadecimal case and harmless whitespace can be normalized.
  • A mismatched digest should be investigated before the file is trusted.

Checksums verify integrity, not publisher identity

A checksum can confirm equality with an expected value, but it cannot prove who created that expected value. When origin matters, obtain the digest from an authenticated source and use a verified digital signature when one is provided.

Frequently asked

Questions, answered.

What does a matching SHA-256 checksum prove?

It proves the file bytes match the bytes represented by the expected SHA-256 digest you supplied.

What if the checksum does not match?

Confirm the algorithm and file version, re-download from the authoritative source, and do not treat the file as verified.

Is SHA-256 better than MD5 for new verification workflows?

OpenFileTools intentionally provides SHA-256, SHA-384, and SHA-512 rather than legacy MD5 or SHA-1.

Is my file uploaded?

No. The browser uses Web Crypto locally.

Related guide

Learn more about this task.

Read the related guide