Developer Tools
Create lowercase hexadecimal SHA checksums with native Web Crypto, compare an optional expected digest, and hash UTF-8 text or a local file without uploading its contents.
Simple workflow
How to use Hash Generator & File Checksum
- 1Choose UTF-8 text or one local file.
- 2Select SHA-256, SHA-384 or SHA-512 and optionally paste an expected digest.
- 3Generate, compare and copy the lowercase hexadecimal checksum.
Good to know
Frequently asked questions
Are selected files uploaded?
No. Native Web Crypto processes the selected bytes in this browser. Filename, bytes and digest are not sent anywhere.
What is the file-size limit?
Files are capped at 50 MiB because the browser digest API reads the complete input into memory rather than streaming it.
Does a matching checksum prove a file is safe?
No. It proves only that the bytes match the expected digest. It does not scan for malware or establish that the expected value is trustworthy.
How is text encoded?
Text is encoded as UTF-8 before the selected SHA digest is calculated.
Practical guide
Generate SHA checksums for UTF-8 text or a local file
SHA-256, SHA-384 and SHA-512 use the browser’s native Web Crypto digest implementation. Text is encoded as UTF-8, while file mode hashes the selected file bytes without uploading them.
An optional expected hexadecimal checksum is compared case-insensitively after strict length validation. Matching proves that the bytes correspond to the expected digest; it does not scan a file for malware or prove that its source is trustworthy.
Worked example
Verify the standard SHA-256 text vector
- Start with
- abc
- Choose
- Choose Text and SHA-256.
- You get
- The digest begins ba7816bf and is returned as 64 lowercase hexadecimal characters.
Tips for a useful result
- Obtain an expected checksum from a trusted source before comparing it.
- Changing one byte should produce a different digest.
- Use SHA-256 or stronger for modern integrity checks.
File memory limit and privacy
Native Web Crypto digest is not a streaming API, so this page reads a selected file into memory and caps files at 50 MiB. It supports one file at a time.
Text, filenames, file bytes, generated digests and expected values remain in the browser. They are not uploaded, stored or included in analytics.
Authoritative external sources
- MDN: SubtleCrypto.digest() (external)
Documents the browser-native SHA digest algorithms and the non-streaming input model.
Keep going