Skip to content

SHA-256 Hash Generator and File Checksum Verifier

Get the SHA-256 fingerprint of any text or file and confirm a download is genuine by comparing it with the publisher's checksum. Your files stay on your device.

Type some text or choose a file to see its hashes.

How to verify a file with SHA-256

  1. Choose File and drag the download onto the drop area, or choose Text to hash a string.
  2. Wait for the progress bar on large files. The SHA-256 appears at the top of the results, highlighted, with the file name and size.
  3. Paste the published checksum into the compare box. A green Match confirms the file is intact; a red message means it's different.
  4. Copy the hash with its copy button if you need to record it or share it with someone.

Features

  • SHA-256 listed first and highlighted, with SHA-384, SHA-512, SHA-1 and MD5 below it.
  • Computed by Web Crypto, the hashing engine built into modern browsers.
  • Checksum verification that ignores spaces and letter case and tells you which algorithm matched.
  • Text and file modes, with drag and drop for any file type.
  • Large-file support with a progress bar and a warning above 100 MB.
  • Uppercase or lowercase output, with a copy button on every row.

Why use Fileora's SHA-256 generator

The point of verifying a checksum is to trust nothing but the maths, and that includes the tool doing it. Fileora never receives your file: the browser reads it locally and hashes it with its own Web Crypto implementation. Private installers, signed contracts and backups stay on your machine, and the check runs even if you go offline after the page loads.

There's no charge, no account and no limit on how many files you check. It works on a phone too, which is handy for confirming an app package or firmware file you've downloaded to a mobile device.

Related tools: the MD5 generator for older download pages that only publish MD5, the hash generator for all five algorithms side by side, and the JWT decoder for tokens signed with HS256 or RS256, both of which use SHA-256 internally.

Checking SHA-256 on the command line

If you prefer a terminal, every major system can calculate SHA-256 too, and the result should be identical to the one shown here:

  • Windows (PowerShell): Get-FileHash file.iso uses SHA-256 by default.
  • macOS: shasum -a 256 file.iso
  • Linux: sha256sum file.iso

Linux and macOS print the hash followed by the file name. Paste only the 64-character hash into the compare box.

What makes a checksum trustworthy

A checksum only proves that your file matches the one the checksum was made from. If an attacker replaces both the file and the checksum on a compromised site, they will still match. So take the checksum from the official source, ideally a page served over HTTPS or a signed release note, and not from the same mirror you downloaded the file from. That is also why SHA-256 is preferred to MD5: with MD5, an attacker can prepare a harmful file that shares a checksum with the genuine one.

Frequently asked questions

What is SHA-256?

SHA-256 is a member of the SHA-2 family of hash functions, standardised by the US National Institute of Standards and Technology. It produces a 256-bit value, shown as 64 hexadecimal characters. It's the checksum most software publishers list today, and it is used inside TLS certificates, code signing, Git and many blockchains.

How do I verify a download with SHA-256?

Find the SHA-256 checksum on the official download page. Choose File here, drop in the downloaded file, and paste the checksum into the compare box. A match confirms the file is byte-for-byte identical to the one the publisher hashed. A mismatch means it's corrupted or different, so don't open it.

Is SHA-256 still secure?

Yes. No practical collision or preimage attack against SHA-256 is known, which is why it's recommended for integrity checks, signatures and certificates. Its main limitation is speed: because it's fast, it shouldn't be used on its own to store passwords.

Can a SHA-256 hash be reversed?

No. SHA-256 is a one-way function, not encryption. There's no key, and no method is known for working back from a hash to its input. The only approach is guessing inputs and hashing each one, which only succeeds for short or common text.

What is the difference between SHA-256 and SHA-512?

Both belong to SHA-2 and are considered secure. SHA-512 gives a longer, 128-character hash and can be faster on 64-bit processors, while SHA-256 is shorter and far more widely published. Both are shown in the results, along with SHA-384, SHA-1 and MD5.

Why doesn't my SHA-256 match the one from the command line?

Usually a hidden newline. Commands like echo add a line break to the end of the text unless you use echo -n, and that changes the hash. Line endings (Windows CRLF versus Unix LF) and trailing spaces have the same effect. For files, make sure you are hashing the exact file, not a renamed or re-saved copy.

Can't find the tool you need, or something isn't working?

Tell us which tool you'd like next or what went wrong. We read every message, and requests decide what we build next.

Opens your email app. Please don't attach private files.