How to use Checksum Manifest Verifier
- Paste a trusted supported SHA-256 or SHA-512 manifest.
- Choose the local files, avoiding duplicate basenames, and run verification.
- Inspect match, mismatch, missing and extra rows before deciding what to keep.
Example: Checksum Manifest Verifier
Verify three known file bytes against a SHA-256 record.
Supported inputs and limits
Where your input is processed
This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.
A match depends on trusting the manifest
The verifier proves that selected bytes agree with the supplied digest. An attacker who replaces both a file and its checksum can still produce a match. This tool does not validate a signature or the publisher’s identity. Obtain a checksum through the appropriate trusted channel for your workflow.
Basenames do not distinguish duplicate directory copies
Relative manifest paths are mapped to selected basenames. Two chosen files with the same basename are ambiguous and refused instead of guessed. Absolute and parent-traversal paths are not accepted. Missing entries and extra selections are reported separately; extra files are listed rather than silently included in hash verification.
Questions about Checksum Manifest Verifier
Does a matching hash prove the source is safe?
No. It proves bytes match the supplied checksum. Obtain that checksum from a trusted source.
Are files downloaded automatically?
No. Select the files on your device.
How are names matched?
By safe basenames. Ambiguous duplicate names are refused.