Checksum Manifest Verifier

Compare local files with SHA-256 or SHA-512 entries from a checksum manifest and report missing or mismatched files.

Files stay on your device No sign-up Free to use
How this works

The tool runs in this browser. Your file or text is not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Privacy details

Verify checksums controls

Drop your files here

or choose them from your device

Up to 20 files and 40 MiB total. Ambiguous basenames, absolute paths and dot/parent path segments are refused. No files are fetched online.

    Up to 20 entries and 64 KiB. GNU: digest followed by two spaces and filename. BSD: SHA256 (filename) = digest. Relative folder paths map to selected basenames.

    How to use Checksum Manifest Verifier

    1. Paste a trusted supported SHA-256 or SHA-512 manifest.
    2. Choose the local files, avoiding duplicate basenames, and run verification.
    3. Inspect match, mismatch, missing and extra rows before deciding what to keep.

    Example: Checksum Manifest Verifier

    Verify three known file bytes against a SHA-256 record.

    You add
    Choose abc.txt containing exactly UTF-8 abc with no newline. Manifest: ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad abc.txt
    You get
    The selected abc.txt is marked match with SHA-256. Adding a newline changes the digest and makes this record fail.

    Supported inputs and limits

    Manifest up to 64 KiB and 20 entries; up to 20 files and 40 MiB total. Supported GNU or BSD SHA-256/SHA-512 records. Basename matching only; ambiguous duplicate names are refused. No downloads, signature verification or proof that an untrusted checksum list is authentic.

    Where your input is processed

    This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

    A match depends on trusting the manifest

    The verifier proves that selected bytes agree with the supplied digest. An attacker who replaces both a file and its checksum can still produce a match. This tool does not validate a signature or the publisher’s identity. Obtain a checksum through the appropriate trusted channel for your workflow.

    Basenames do not distinguish duplicate directory copies

    Relative manifest paths are mapped to selected basenames. Two chosen files with the same basename are ambiguous and refused instead of guessed. Absolute and parent-traversal paths are not accepted. Missing entries and extra selections are reported separately; extra files are listed rather than silently included in hash verification.

    Questions about Checksum Manifest Verifier

    Does a matching hash prove the source is safe?

    No. It proves bytes match the supplied checksum. Obtain that checksum from a trusted source.

    Are files downloaded automatically?

    No. Select the files on your device.

    How are names matched?

    By safe basenames. Ambiguous duplicate names are refused.

    Project manager: Tony Hines · Content updated 3 October 2026 · Report a problem