Check a File Checksum Without Uploading It
Drop in a file and get its checksum. Paste the one the publisher wrote next to the download and the page tells you whether they agree, so you can see that the copy on your disk is the copy they released.
What a matching checksum proves, and what it does not
It proves the bytes on your disk are the bytes that were hashed. That catches a download that was cut short, a disk that corrupted a block, and a mirror serving an older build. It is the common case and the checksum does it well.
What it cannot do on its own is prove the file is genuine. If an attacker can replace the download, they can usually replace the checksum printed beside it, and both will agree. The checksum only becomes evidence of authenticity when it reaches you by a different route than the file: a signed release note, the project's repository, a package manager that pins it, or a key you already trust. A hash and a file served from the same page tell you the transfer worked, nothing more.
Which algorithm to tick
Use SHA-256 unless the publisher gives you something else. SHA-512 is also fine and slightly faster on 64-bit machines. SHA-1 is here because old projects still publish it, and MD5 is not offered at all: the browser's crypto interface refuses to implement it, and for a reason worth knowing.
MD5 and SHA-1 are both broken against a deliberate attack. Two different files can be constructed to share an MD5, and the same has been demonstrated for SHA-1, so a matching MD5 no longer rules out that the file was swapped on purpose. Against accidental corruption they still work, which is why they have not disappeared.
Size limits
The whole file is read into memory, because the browser's digest interface takes one buffer rather than a stream. Files up to a few hundred megabytes are comfortable. Past that it depends on the device, and a phone will give up well before a laptop. If the browser runs out of room it says so, and the file is still untouched.
Why doing this in a tab is reasonable
The usual advice is to run sha256sum or Get-FileHash, and that advice is good. This page exists for the times you cannot: a borrowed machine, a locked-down work laptop, or someone who should not have to open a terminal to check that an installer arrived intact. The file is read with the File API and hashed with crypto.subtle, both built into the browser, and no part of it is sent anywhere.
Frequently asked questions
Does my file get uploaded?
No. The browser reads the file from your disk into this tab and hashes it there, using the crypto interface built into the browser itself. No network request carries the file or the result. You can disconnect from the internet after the page loads and the tool still works, which is the easiest way to satisfy yourself that it is true.
The checksums do not match. What now?
Download the file again first, because a truncated transfer is the most common cause by far. If the second copy gives the same hash as the first, the file is intact and the published checksum is for a different build, so check the version and the platform. If a fresh download gives a third value, something between you and the server is altering the file.
Why is there no MD5 option?
The browser’s crypto interface does not implement MD5, so no page can offer it without shipping its own implementation. That is a defensible omission: MD5 collisions can be constructed deliberately, so a matching MD5 does not rule out a file being swapped. It still detects accidental corruption, which is why older projects publish it.
How big a file can I hash?
A few hundred megabytes is comfortable on a desktop. The whole file has to fit in memory at once because the digest interface takes a buffer rather than a stream, so very large images and archives may fail on a phone or an older machine. The browser reports the failure and your file is untouched.
Can I paste a checksum file instead of one line?
Paste the line you want and the comparison ignores everything that is not a hex digit, so a line like "a1b2c3... filename.iso" still works. If the file lists several hashes for several downloads, paste only the line for the one you have.
Last updated October 4, 2026