How to use Hash and Checksum Generator
- Choose Text typed or pasted here, or A file from this device.
- Set Algorithm. SHA-256 is the default.
- Enter the text or select the file, and paste an expected value if you have one.
- The digest updates as you change the input. Read the Digest row.
Example: Hash and Checksum Generator
Hash one short text with SHA-256.
Options
- Algorithm
- SHA-256, SHA-384 and SHA-512 use the browser crypto interface. SHA-1 and CRC32 are computed in the page and labeled legacy, because they are not safe for security work.
- Expected value to compare
- Optional. Spaces and colons are stripped and letter case is ignored, so a digest copied from a download page can be pasted as it appears. The page compares two strings only; it cannot check where your expected value came from.
- CRC32 (corruption check)
- Use it to catch accidental changes during a transfer. Two different inputs can share one CRC32 value, so it is not proof of authenticity.
- Legacy MD5
- MD5 is available for matching old checksums. It is unsuitable for passwords, signatures or security verification. Use SHA-256 for file integrity checks.
Supported inputs and limits
Where your input is processed
This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.
What a matching checksum proves
A checksum turns bytes into a fixed-length value, and any change produces a different one. When the expected value comes from the publisher over HTTPS and both sides used the same algorithm, a match is strong evidence that your bytes match theirs. It is not a safety check: a digest cannot tell you whether a program contains malware.
Why one changed byte changes everything
A secure hash spreads a small input change across the whole output, so abc and abd share no visible structure. That is what catches a truncated download or a converted line ending.
Questions about Hash and Checksum Generator
When should I choose MD5?
Only when matching an existing legacy checksum that requires MD5. It is unsuitable for passwords, signatures or security verification. A match does not prove a file is safe.
A file matches its checksum but will not open. Why?
The bytes match what the publisher hashed. That says nothing about whether the file is valid or safe.
Do spaces or colons in a pasted value break the comparison?
No. They are removed before the comparison, and letter case is ignored.
Can I hash a file larger than 64 MB?
Not here. Use sha256sum on Linux, certutil -hashfile on Windows, or shasum on macOS.