Skip to content
TNToolsNexus

Hash generator & checksum verifier

SHA-256, SHA-1, SHA-384, and SHA-512 of any text or file — with a paste-to-compare checksum verifier. Runs locally, nothing uploaded.

Hash

Your text and files never leave your browser — hashing runs on your device.

Compute SHA-256, SHA-1, SHA-384, and SHA-512 of any text or file in one pass — then paste the checksum from a download page and get a plain match / no match verdict. Everything runs locally.

How to verify a download

  1. Switch to A file (checksum) and drop the file you downloaded.
  2. Copy the published checksum from the download page into the compare field.
  3. Read the verdict: green names the matching algorithm; red means the bytes differ — or the published value uses an algorithm not computed here.

Why checksums exist

A checksum is a fingerprint of exact bytes: change one bit and the hash changes completely. Projects publish them so you can prove your download arrived intact and unmodified — the defense against corrupted transfers and tampered mirrors. The compare field does the part humans are bad at: eyeballing 64 hex characters. It normalizes case, spaces, and separators, then checks all four computed digests, so you don’t even need to know which algorithm the site used.

The four algorithms, honestly ranked

SHA-256 is today’s default — what release pages publish and what you should emit. SHA-512 is its bigger sibling (faster on some 64-bit systems, common in shadow files and some ecosystems). SHA-384 appears mostly in certificate chains. SHA-1 is computationally broken for security purposes and labeled legacy here — still fine for spotting corrupted downloads, wrong for anything an attacker might target. Text mode hashes UTF-8 bytes, matching sha256sum exactly, so results agree with your terminal. (Random IDs rather than fingerprints? That’s the UUID generator; encoded blobs decode next door in Base64.)

Private by design

Uploading a file to “check its hash” hands the whole file to someone else — precisely backwards. Here WebCrypto digests it on your device; nothing is transmitted, and the verdict is computed where the file already lives.

Last updated:

Frequently asked questions

How do I verify a downloaded file's checksum?
Switch to file mode, drop the file, and paste the checksum from the download page into the compare field — the tool says which algorithm matched (green) or that nothing did (red). Case, spaces, and colon separators in the pasted value are ignored automatically.
Where is MD5?
Deliberately absent: browsers' WebCrypto doesn't implement it, and modern projects publish SHA-256 checksums. If a legacy system hands you only an MD5, that's a sign to ask it for something better — though we may add a verified MD5 later for archaeology.
Is SHA-1 still OK to use?
For integrity checksums (did the download corrupt?), yes. For anything security-related (signatures, certificates, password anything), no — collisions are practical since 2017, which is why the tool labels it legacy.
Do all four hashes get computed from the same bytes?
Yes — one read of your text or file, four digests. Text is hashed as UTF-8 bytes, which matches what every command-line tool (sha256sum, shasum) produces for the same content.
Is my file uploaded to compute the hash?
No — that would defeat the purpose. Hashing runs in your browser via WebCrypto; the file never leaves your device.

Related tools

UUID Generator

Generate 1–100 cryptographically random version-4 UUIDs — uppercase and no-hyphen options, copy all in one click. Local, private.

Base64 Encode / Decode

Encode text to Base64 and decode it back — Unicode-safe, URL-safe variant included, instant, and nothing leaves your browser.

JSON Formatter

Format, validate, and minify JSON as you paste — 2/4-space or tab indentation, clear syntax errors, copy or download. Private.