File Hash Checker

Get SHA-256, SHA-1, SHA-512, MD5 or CRC32 of files of any size and check them against a hash or a whole SHA256SUMS list. Streams in your browser; no upload.

  • Runs in your browser
  • Your data never leaves your browser
  • Free · No Sign-Up
SHA-256 starts automatically. Select more algorithms to calculate them for the current files; each algorithm uses its own background worker. Keep the page open until hashing finishes.
Algorithms
Choose or drop files to start hashing. Further imports add files to the list, up to 1,000 files. Folder drops keep relative paths; Choose a folder is available on computers. Files have no fixed size limit.
Expected hash or checksum list
Optional. Paste a hash, a line like “3a1f… file.iso”, SHA256SUMS, certutil or Get-FileHash output, or Base64 / SRI.The expected value can enable its algorithm automatically. Each file shows whether it matches; a mismatch marks the first different character. A file name may differ when its hash matches. Open a checksum text file of at most 1 MB. Its contents replace the expected value and are checked against the current files.

Drop files or a folder, or click to choose Any size · read on this device, never uploaded

Files are read on this device by a background worker. Nothing is uploaded or saved.

Read the full guide File Hash Checker: Verifying Downloads with SHA-256 in the Browser
Examples, details and FAQ Worked examples, how it compares with other tools, and answers to common questions.

Example: Checking a Node.js Download

Node.js puts a SHASUMS256.txt file in every release folder. For v24.21.0 it has 34 lines, one per download. After downloading node-v24.21.0-darwin-arm64.tar.gz (52,909,993 bytes), drop it on the tool and paste all 34 lines. The card shows:

node-v24.21.0-darwin-arm64.tar.gz   50.5 MB   ✓ OK
SHA-256  bed7eea5325e1108f32ce5228ddd6a5f0f08a499ee42aa7442aea583702f6057
Matches the SHA-256 listed for node-v24.21.0-darwin-arm64.tar.gz (line 3).

Below the box: 1 OK · 0 failed and 33 listed files were not selected, with the first five names. That is the same result as sha256sum -c --ignore-missing SHASUMS256.txt on Linux, without a terminal.

A download that stopped early looks different. The first 30,000,000 bytes of the same file give FAILED and “Does not match the SHA-256 listed for node-v24.21.0-darwin-arm64.tar.gz (line 3). First difference at character 1.” The expected and actual values are shown one above the other, with the differing part highlighted.

The file name is used only to pick the line. If your browser saved the file as node-v24.21.0-darwin-arm64 (1).tar.gz, the tool finds the line by value and says the name is different.

Example: An npm Integrity Value

package-lock.json stores an integrity field in Subresource Integrity form: the algorithm, a dash, and the digest in Base64. For hash-wasm 4.12.0 the registry gives:

"integrity": "sha512-+/2B2rYLb48I/evdOIhP+K/DD2ca2fgBjp6O+GBEnCDk2e4rpeXIK8GvIyRPjTezgmWn9gmKwkQjjx6BtqDHVQ=="

Paste the whole line. The tool decodes the Base64 to the 128-digit SHA-512 fbfd81da…a0c755, turns SHA-512 on, and marks hash-wasm-4.12.0.tgz (530,236 bytes, from the registry tarball URL) as OK. Docker digests such as ubuntu@sha256:… work the same way.

What You Can Paste

SourceExample
Bare hex, any case, full-width digitsE3B0C442…B855
GNU sha256sum, shasum, SHA256SUMS<hash> file.iso, <hash> *file.iso
BSD and OpenSSL tagsSHA256 (file.iso) = <hash>, SHA2-256(file.iso)= <hash>
Windows certutil -hashfile file SHA256header line, hash line, “completed successfully”
PowerShell Get-FileHashtable or Format-List output (upper-case hex)
GnuPG --print-md, old certutilhex in groups of 2 or 8, wrapped over lines
Base64, SRI, prefixed47DEQpj8…uFU=, sha512-…, sha256:<hash>
SFV (CRC32)game.zip 1A2B3C4D

File names with a backslash or a line break are escaped in GNU lists: the line starts with \ (GNU coreutils output modes). The tool reads that form and writes it when it exports such names, and shasum -a 256 -c accepts its exported lists.

Mistakes are named, not hidden. A hash with a stray x at the end gives “Line 1: “x” at character 65 is not a hex digit”. A SHA-224 or SHA3 value is reported as unsupported. The earlier version of this tool removed spaces and searched for the computed hash inside the pasted text, so a value with an extra character still showed “Matches”.

Large Files

Browsers cannot hash a file in pieces with the built-in Web Crypto API (digest() takes the whole buffer). The old version therefore read the whole file into memory: a 1 GB file added about 2 GB to the tab, SHA-256 + MD5 froze the page for 12 seconds, and a 3 GB file failed with “Could not read the file”. The tool now streams the file through hash-wasm, one worker per algorithm.

Measured on 2026-10-01 in desktop Chromium on an Apple M1 Max: a 1 GB file took 4.3 seconds for SHA-256, with the tab using about 100 MB more memory, and the page stayed responsive. The 4,080,486,400-byte Ubuntu 24.04.5 server ISO matched the SHA-256 in the official SHA256SUMS. The progress line shows percent, speed and time left, and Stop cancels.

How It Compares

Tested on 2026-10-01 in desktop Chromium with the same files, watching network requests in DevTools. None of these tools uploaded the file. The list test pastes two sha256sum lines whose hashes are swapped: abc.txt is given the hash of empty.bin and the other way round, so both files should fail.

ToolEmpty file3 GB fileSwapped two-line list
This toole3b0c442…b855correctboth FAILED, by file name
emn178 Online Tools (SHA256 File Checksum)no outputcorrect, 83 sno compare box
BrowserTools.jpcorrectnothing after 120 s, no errorone-line box; nothing highlighted
PiliApp (kr.piliapp.com)correctnothing after 150 s, no errorboth marked “일치” (match)
tool.lu (MD5)no outputnothing after 80 s, no errorone MD5 value only

PiliApp compares values only, so a list that pairs the wrong hash with a file name still passes. BrowserTools.jp, PiliApp and tool.lu all hashed a 1 GB file but showed nothing for 3 GB; emn178 reads in pieces and finished.

Limits

  • Algorithms: SHA-256, SHA-1, SHA-384, SHA-512, MD5 and CRC32. SHA-224, SHA3, BLAKE2 (Arch Linux b2sums.txt) and BLAKE3 are not computed; such values are reported as unsupported.
  • Up to 1,000 files per session and checksum lists up to 1 MB.
  • No signature check. A matching hash shows the file equals the list. To trust the list, verify its signature: Node.js explains this under Verifying binaries, and Ubuntu in How to verify your Ubuntu download.
  • MD5, SHA-1 and CRC32 are weak. MD5 and SHA-1 collisions can be made on purpose (SHAttered for SHA-1). They still catch a broken download.
  • Folder picking uses the browser’s folder dialog and is hidden on small screens; dropping a folder works wherever drag and drop does.
  • Text, not files? Use the Hash Generator. For a keyed hash, use the HMAC Generator.

FAQ

Is the file uploaded anywhere?

No. A background worker in your browser reads the file from disk in 1 MB pieces and hashes it. The page makes no network request with the file, and nothing is stored. The only request is for the hashing script itself, from this site.

Is there a file size limit?

No fixed limit. The file is read as a stream, so memory use stays near 100 MB even for a 4 GB ISO. Time grows with size: on an Apple M1 Max, SHA-256 of a 1 GB file took about 4 seconds. Keep the tab open until it finishes.

Which hash should I use?

Use the one the publisher lists. Most projects publish SHA-256 (Node.js, Ubuntu); Firefox also publishes SHA-512. If you can choose, use SHA-256. MD5 and SHA-1 have practical collision attacks and CRC32 only detects accidental damage, so use them only when they are the only value offered.

Why does the tool say my hash has 63 hex digits?

Every supported algorithm has a fixed length: CRC32 8 hex digits, MD5 32, SHA-1 40, SHA-256 64, SHA-384 96, SHA-512 128. A value of another length lost or gained a character when it was copied. The tool reports the line and the length instead of guessing.

Does a matching hash prove the download is safe?

It proves the file is byte-for-byte the one in the checksum list. If an attacker can change both the file and the list, both still match. Projects that sign the list (Node.js SHASUMS256.txt.asc, Ubuntu SHA256SUMS.gpg) let you check the list with GnuPG first.