Skip to content
← All tools

[ CHECK / #256 ]

File checksum

Calculate a local file’s SHA-256 and compare an expected checksum.

◉ Stays in your browser

01 / Your file

Hashes the file’s actual bytes, without decoding or uploading them. The 20 MiB limit keeps the complete file comfortably in memory.

02 / Your result

Your result will appear here.
Start with your own input or try an example.

What it does

Check whether a downloaded file agrees with a checksum from its publisher, or make a fingerprint to compare copies later. Select a local file up to 20 MiB and optionally paste an expected SHA-256. The tool hashes the exact bytes in your browser and reports whether the values match; it does not upload the file.

Useful when

  • Compare a downloaded archive with its publisher’s SHA-256.
  • Check whether two small file copies have the same fingerprint.
  • Record a checksum before sharing a document or configuration file.

How to use it

  1. Choose a local file up to 20 MiB, or try the small built-in example.
  2. Optionally paste a trusted SHA-256 value, then calculate the checksum.
  3. Review the match result and copy or download the hexadecimal checksum.

A few useful details

Does a matching checksum mean a file is safe?

No. It means the calculated digest equals the value you supplied. A malicious file can have a matching checksum too. Obtain the expected value from a source you trust; this tool is not a malware scan or a signature verifier.

Why is there a 20 MiB limit?

The browser’s Web Crypto digest API takes the complete file in memory. The limit bounds memory use. Use an appropriate local command-line checksum tool for larger files.

Does renaming the file change its checksum?

No. Only the file bytes are hashed; its name and metadata are not included. Editing content, changing a text file’s line endings, or recompressing an archive can change its checksum.

What is inside the .sha256 download?

The file contains only the 64-character hexadecimal digest and a newline. It does not include a filename and is not a multi-file sha256sum manifest.