Calculate or verify SHA-256 in your browser
Choose Text (UTF-8) or File, then press Calculate SHA-256. For a file, select the original download instead of pasting its contents into the text box. The tool reads its raw bytes locally; it does not upload the file.
To check a download, paste the publisher’s SHA-256 into Expected SHA-256.
Paste 64 hexadecimal digits, one GNU line (hash *file, or the hash followed
by two spaces and the filename), or
one BSD line (SHA256 (file) = hash). Uppercase and outer whitespace are accepted,
up to 4096 characters; lists and escaped GNU records are not supported.
The filename is an inert label: that path is not opened or its name verified.
The comparison checks every digit and updates when you edit the
reference, without reading the file again.
A match means the calculated checksum equals your reference. It does not prove that the file is safe or authentic. Obtain the expected checksum from a trusted source: an attacker who can replace both the file and the reference can make them match.
Test vector
The exact text abc, without a trailing line ending, produces:
ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad
The output contains 64 hexadecimal digits representing 256 bits. Empty text and empty files are valid inputs, with the same empty-input digest.
Text and file bytes are different inputs
Text is encoded as UTF-8. Spaces, capitalization, accents and line endings
affect the input bytes. The tool does not trim text or normalize Unicode.
Visually identical strings can use different Unicode sequences; LF and
CRLF are also different bytes.
File mode hashes the original bytes without text conversion. Renaming a file does not change its checksum if its bytes stay identical. Filesystem metadata such as its path is not hashed, but metadata embedded inside the file is part of its contents and does affect the digest.
The text comparator helps locate line-by-line changes. Base64 represents bytes as text; it is reversible encoding, not a checksum.
Limits and larger files
Text input is limited to 1,000,000 characters. File input is limited to 20 MiB (20,971,520 bytes) and checked before reading. Web Crypto requires the complete input in memory; this tool does not stream files. A browser can still run out of resources below that limit.
For larger files, use a system utility from the Windows, macOS and Linux checksum guide. It also explains how to compare a complete digest in a terminal.
Changing the input or clearing the tool discards any pending result. A native calculation already in progress may finish internally, but its obsolete output will not be shown.
Privacy and security boundaries
The tool does not transmit or persist your text, file bytes, filenames or checksums, and does not add them to the URL. Its calculation uses the browser’s Web Crypto API over HTTPS.
SHA-256 is not encryption and has no decryption operation. Predictable inputs can nevertheless be guessed by hashing candidates. This tool does not add salt, create HMACs or verify digital signatures; do not use a plain SHA-256 digest as a password-storage scheme.
Frequently asked questions
Why does my checksum not match?
Check that you selected the exact file, used SHA-256 rather than a different algorithm, and copied the entire trusted reference. A different file version, an incomplete download or text conversion can change the result. Investigate a mismatch before using the file.
Is an uppercase checksum a different hash?
No. Uppercase and lowercase hexadecimal letters represent the same digest. The output uses lowercase; comparison accepts either case.
Can I hash an image, PDF or ZIP?
Yes, in File mode, provided the file is no larger than 20 MiB. Its extension does not affect the algorithm; the tool hashes its bytes without opening its contents.
Technical references
SHA-256 is specified in NIST FIPS 180-4. The Web Crypto digest documentation describes the browser API and its lack of streaming support.