Skip to the tool

SHA-256 hash generator

The modern default digest, for text or any file, computed by your browser's own cryptography. SHA-256 first, the rest of the family beneath.

Guide

Verify a download, step by step

  1. Find the published SHA-256 on the download page, usually next to the file or in a SHA256SUMS file. Copy it.
  2. Switch this tool to File and choose the file you downloaded. It is read locally, not uploaded.
  3. Paste the published value into the compare field.
  4. A green MATCH badge on the SHA-256 row means byte-for-byte identical: install with confidence.
  5. No match? Re-download first, transfers do get corrupted. If it still fails, treat the file as untrustworthy.

Examples

Worked examples

An OS image

Linux distributions publish SHA256SUMS beside every ISO. Hash your 4 GB image with a local tool (it exceeds this page's 200 MB comfort limit) or verify a smaller netinst image right here.

An installer from a mirror

You fetched a setup file from a mirror, but the project's own site publishes the hash. If the mirror's file matches the project's hash, the mirror did not tamper with it.

Pinning a document

Hash a contract PDF and record the digest in the covering email. Either side can re-hash later to prove the file has not changed since.

Method

How it works

SHA-256 belongs to the SHA-2 family standardised by NIST. Your input is processed in 512-bit blocks through 64 rounds of mixing, producing a 256-bit digest with the avalanche property: flip one input bit and on average half the output bits flip. The computation here is your browser's native crypto.subtle.digest, the same code path TLS uses.

Built by Wolds Cyber. Files and text are hashed on your device; nothing is transmitted.

FAQ

Frequently asked questions

Why is SHA-256 the recommended default?

It is fast, universally supported and has no known practical attacks. It anchors TLS certificates, code signing and most published download checksums today.

How long is a SHA-256 hash?

64 hexadecimal characters, representing 256 bits. If the published value is 40 characters it is SHA-1, and 96 or 128 characters mean SHA-384 or SHA-512.

Does verifying a hash prove a download is safe?

It proves the file is byte-identical to the one whose hash was published. If an attacker controls the download page, they can publish the hash of their tampered file too, so a hash from a second, trusted channel is worth more.

SHA-256 or SHA-512, does it matter?

Both are unbroken. SHA-512 is a little faster on 64-bit CPUs and longer; SHA-256 is the compatibility default. For integrity checking, match whatever the publisher used.

Can SHA-256 be reversed?

No. The only way back is guessing inputs and comparing outputs. For a large random input that is beyond any computing power that exists or is projected.

Is the file uploaded to hash it?

No. Your browser's Web Crypto API hashes it on your machine. This page works offline once loaded.

More tools

Related tools

File checksum verifierThe file-first version of this page. Hash generatorAll five digests side by side for any input. JWT decoderWhere HS256 signing meets the SHA-256 you just used.
Skip to the tool

SHA-256 hash generator

The modern default digest, for text or any file, computed by your browser's own cryptography. SHA-256 first, the rest of the family beneath.

Hashed as UTF-8, exactly as typed. A trailing space or newline changes every hash.

Type text above and the hashes appear instantly.

Everything runs in your browser. Text and files are hashed on your device and never uploaded.

Guide

Verify a download, step by step

  1. Find the published SHA-256 on the download page, usually next to the file or in a SHA256SUMS file. Copy it.
  2. Switch this tool to File and choose the file you downloaded. It is read locally, not uploaded.
  3. Paste the published value into the compare field.
  4. A green MATCH badge on the SHA-256 row means byte-for-byte identical: install with confidence.
  5. No match? Re-download first, transfers do get corrupted. If it still fails, treat the file as untrustworthy.

Examples

Worked examples

An OS image

Linux distributions publish SHA256SUMS beside every ISO. Hash your 4 GB image with a local tool (it exceeds this page's 200 MB comfort limit) or verify a smaller netinst image right here.

An installer from a mirror

You fetched a setup file from a mirror, but the project's own site publishes the hash. If the mirror's file matches the project's hash, the mirror did not tamper with it.

Pinning a document

Hash a contract PDF and record the digest in the covering email. Either side can re-hash later to prove the file has not changed since.

Method

How it works

SHA-256 belongs to the SHA-2 family standardised by NIST. Your input is processed in 512-bit blocks through 64 rounds of mixing, producing a 256-bit digest with the avalanche property: flip one input bit and on average half the output bits flip. The computation here is your browser's native crypto.subtle.digest, the same code path TLS uses.

Built by Wolds Cyber. Files and text are hashed on your device; nothing is transmitted.

FAQ

Frequently asked questions

Why is SHA-256 the recommended default?

It is fast, universally supported and has no known practical attacks. It anchors TLS certificates, code signing and most published download checksums today.

How long is a SHA-256 hash?

64 hexadecimal characters, representing 256 bits. If the published value is 40 characters it is SHA-1, and 96 or 128 characters mean SHA-384 or SHA-512.

Does verifying a hash prove a download is safe?

It proves the file is byte-identical to the one whose hash was published. If an attacker controls the download page, they can publish the hash of their tampered file too, so a hash from a second, trusted channel is worth more.

SHA-256 or SHA-512, does it matter?

Both are unbroken. SHA-512 is a little faster on 64-bit CPUs and longer; SHA-256 is the compatibility default. For integrity checking, match whatever the publisher used.

Can SHA-256 be reversed?

No. The only way back is guessing inputs and comparing outputs. For a large random input that is beyond any computing power that exists or is projected.

Is the file uploaded to hash it?

No. Your browser's Web Crypto API hashes it on your machine. This page works offline once loaded.

More tools

Related tools