Compute SHA-256, SHA-1, SHA-384, and SHA-512 of any text or file in one pass — then paste the checksum from a download page and get a plain match / no match verdict. Everything runs locally.
How to verify a download
- Switch to A file (checksum) and drop the file you downloaded.
- Copy the published checksum from the download page into the compare field.
- Read the verdict: green names the matching algorithm; red means the bytes differ — or the published value uses an algorithm not computed here.
Why checksums exist
A checksum is a fingerprint of exact bytes: change one bit and the hash changes completely. Projects publish them so you can prove your download arrived intact and unmodified — the defense against corrupted transfers and tampered mirrors. The compare field does the part humans are bad at: eyeballing 64 hex characters. It normalizes case, spaces, and separators, then checks all four computed digests, so you don’t even need to know which algorithm the site used.
The four algorithms, honestly ranked
SHA-256 is today’s default — what release pages publish and what you should emit.
SHA-512 is its bigger sibling (faster on some 64-bit systems, common in shadow files and
some ecosystems). SHA-384 appears mostly in certificate chains. SHA-1 is computationally
broken for security purposes and labeled legacy here — still fine for spotting corrupted
downloads, wrong for anything an attacker might target. Text mode hashes UTF-8 bytes, matching
sha256sum exactly, so results agree with your terminal. (Random IDs rather than fingerprints?
That’s the UUID generator; encoded blobs decode next door in
Base64.)
Private by design
Uploading a file to “check its hash” hands the whole file to someone else — precisely backwards. Here WebCrypto digests it on your device; nothing is transmitted, and the verdict is computed where the file already lives.