File Hash Checker
Get SHA-256, SHA-1, SHA-512, MD5 or CRC32 of files of any size and check them against a hash or a whole SHA256SUMS list. Streams in your browser; no upload.
- Runs in your browser
- Your data never leaves your browser
- Free · No Sign-Up
Scan with WeChat to share this tool
Examples, details and FAQ Worked examples, how it compares with other tools, and answers to common questions.
Example: Checking a Node.js Download
Node.js puts a SHASUMS256.txt file in every release folder. For v24.21.0 it has 34 lines, one per download. After downloading node-v24.21.0-darwin-arm64.tar.gz (52,909,993 bytes), drop it on the tool and paste all 34 lines. The card shows:
node-v24.21.0-darwin-arm64.tar.gz 50.5 MB ✓ OK
SHA-256 bed7eea5325e1108f32ce5228ddd6a5f0f08a499ee42aa7442aea583702f6057
Matches the SHA-256 listed for node-v24.21.0-darwin-arm64.tar.gz (line 3).
Below the box: 1 OK · 0 failed and 33 listed files were not selected, with the first five names. That is the same result as sha256sum -c --ignore-missing SHASUMS256.txt on Linux, without a terminal.
A download that stopped early looks different. The first 30,000,000 bytes of the same file give FAILED and “Does not match the SHA-256 listed for node-v24.21.0-darwin-arm64.tar.gz (line 3). First difference at character 1.” The expected and actual values are shown one above the other, with the differing part highlighted.
The file name is used only to pick the line. If your browser saved the file as node-v24.21.0-darwin-arm64 (1).tar.gz, the tool finds the line by value and says the name is different.
Example: An npm Integrity Value
package-lock.json stores an integrity field in Subresource Integrity form: the algorithm, a dash, and the digest in Base64. For hash-wasm 4.12.0 the registry gives:
"integrity": "sha512-+/2B2rYLb48I/evdOIhP+K/DD2ca2fgBjp6O+GBEnCDk2e4rpeXIK8GvIyRPjTezgmWn9gmKwkQjjx6BtqDHVQ=="
Paste the whole line. The tool decodes the Base64 to the 128-digit SHA-512 fbfd81da…a0c755, turns SHA-512 on, and marks hash-wasm-4.12.0.tgz (530,236 bytes, from the registry tarball URL) as OK. Docker digests such as ubuntu@sha256:… work the same way.
What You Can Paste
| Source | Example |
|---|---|
| Bare hex, any case, full-width digits | E3B0C442…B855 |
GNU sha256sum, shasum, SHA256SUMS | <hash> file.iso, <hash> *file.iso |
| BSD and OpenSSL tags | SHA256 (file.iso) = <hash>, SHA2-256(file.iso)= <hash> |
Windows certutil -hashfile file SHA256 | header line, hash line, “completed successfully” |
PowerShell Get-FileHash | table or Format-List output (upper-case hex) |
GnuPG --print-md, old certutil | hex in groups of 2 or 8, wrapped over lines |
| Base64, SRI, prefixed | 47DEQpj8…uFU=, sha512-…, sha256:<hash> |
| SFV (CRC32) | game.zip 1A2B3C4D |
File names with a backslash or a line break are escaped in GNU lists: the line starts with \ (GNU coreutils output modes). The tool reads that form and writes it when it exports such names, and shasum -a 256 -c accepts its exported lists.
Mistakes are named, not hidden. A hash with a stray x at the end gives “Line 1: “x” at character 65 is not a hex digit”. A SHA-224 or SHA3 value is reported as unsupported. The earlier version of this tool removed spaces and searched for the computed hash inside the pasted text, so a value with an extra character still showed “Matches”.
Large Files
Browsers cannot hash a file in pieces with the built-in Web Crypto API (digest() takes the whole buffer). The old version therefore read the whole file into memory: a 1 GB file added about 2 GB to the tab, SHA-256 + MD5 froze the page for 12 seconds, and a 3 GB file failed with “Could not read the file”. The tool now streams the file through hash-wasm, one worker per algorithm.
Measured on 2026-10-01 in desktop Chromium on an Apple M1 Max: a 1 GB file took 4.3 seconds for SHA-256, with the tab using about 100 MB more memory, and the page stayed responsive. The 4,080,486,400-byte Ubuntu 24.04.5 server ISO matched the SHA-256 in the official SHA256SUMS. The progress line shows percent, speed and time left, and Stop cancels.
How It Compares
Tested on 2026-10-01 in desktop Chromium with the same files, watching network requests in DevTools. None of these tools uploaded the file. The list test pastes two sha256sum lines whose hashes are swapped: abc.txt is given the hash of empty.bin and the other way round, so both files should fail.
| Tool | Empty file | 3 GB file | Swapped two-line list |
|---|---|---|---|
| This tool | e3b0c442…b855 | correct | both FAILED, by file name |
| emn178 Online Tools (SHA256 File Checksum) | no output | correct, 83 s | no compare box |
| BrowserTools.jp | correct | nothing after 120 s, no error | one-line box; nothing highlighted |
| PiliApp (kr.piliapp.com) | correct | nothing after 150 s, no error | both marked “일치” (match) |
| tool.lu (MD5) | no output | nothing after 80 s, no error | one MD5 value only |
PiliApp compares values only, so a list that pairs the wrong hash with a file name still passes. BrowserTools.jp, PiliApp and tool.lu all hashed a 1 GB file but showed nothing for 3 GB; emn178 reads in pieces and finished.
Limits
- Algorithms: SHA-256, SHA-1, SHA-384, SHA-512, MD5 and CRC32. SHA-224, SHA3, BLAKE2 (Arch Linux
b2sums.txt) and BLAKE3 are not computed; such values are reported as unsupported. - Up to 1,000 files per session and checksum lists up to 1 MB.
- No signature check. A matching hash shows the file equals the list. To trust the list, verify its signature: Node.js explains this under Verifying binaries, and Ubuntu in How to verify your Ubuntu download.
- MD5, SHA-1 and CRC32 are weak. MD5 and SHA-1 collisions can be made on purpose (SHAttered for SHA-1). They still catch a broken download.
- Folder picking uses the browser’s folder dialog and is hidden on small screens; dropping a folder works wherever drag and drop does.
- Text, not files? Use the Hash Generator. For a keyed hash, use the HMAC Generator.
FAQ
Is the file uploaded anywhere?
No. A background worker in your browser reads the file from disk in 1 MB pieces and hashes it. The page makes no network request with the file, and nothing is stored. The only request is for the hashing script itself, from this site.
Is there a file size limit?
No fixed limit. The file is read as a stream, so memory use stays near 100 MB even for a 4 GB ISO. Time grows with size: on an Apple M1 Max, SHA-256 of a 1 GB file took about 4 seconds. Keep the tab open until it finishes.
Which hash should I use?
Use the one the publisher lists. Most projects publish SHA-256 (Node.js, Ubuntu); Firefox also publishes SHA-512. If you can choose, use SHA-256. MD5 and SHA-1 have practical collision attacks and CRC32 only detects accidental damage, so use them only when they are the only value offered.
Why does the tool say my hash has 63 hex digits?
Every supported algorithm has a fixed length: CRC32 8 hex digits, MD5 32, SHA-1 40, SHA-256 64, SHA-384 96, SHA-512 128. A value of another length lost or gained a character when it was copied. The tool reports the line and the length instead of guessing.
Does a matching hash prove the download is safe?
It proves the file is byte-for-byte the one in the checksum list. If an attacker can change both the file and the list, both still match. Projects that sign the list (Node.js SHASUMS256.txt.asc, Ubuntu SHA256SUMS.gpg) let you check the list with GnuPG first.