Batch File Hash & Manifest Verifier

Pick or drop many files at once and this page computes the MD5, SHA-1, SHA-256, SHA-384 or SHA-512 digest of every one of them, entirely inside your browser. Then either copy the results out as sha256sum-compatible lines for your own release notes, or paste a checksum manifest (SHA256SUMS, .sha256, .sfv, BSD openssl dgst output) and let the page tell you which files verified, which mismatched and which are missing. Nothing is uploaded anywhere. For a single file with more algorithms, see the Hash Generator.
Drop files here, or click to choose them
Up to 50 files, 200 MB each. The files stay on this machine.
No files selected.
— hex output; pick at least one.
Click any digest cell to copy it. Names and sizes are always listed, so the table doubles as a batch file-size view.
The digest table appears here once you pick files and press Compute.
Paste a manifest in GNU (hash  name), BSD (SHA256 (name) = hash), SFV (name crc32) or plain (sha256=hash) style, or upload the .sha256 / SHA256SUMS / .sfv file itself. Lines starting with ; are treated as comments.
Privacy: every digest is computed with the browser's own JavaScript and WebCrypto engine — the files never leave this tab. Tip: after verifying a download it is safe to close this page; nothing was stored.

What is batch file hashing?

A checksum is a short fingerprint of a file: feed the file's bytes through a hash function and you get a digest that changes almost certainly when even one byte of the file changes. Software distributors publish those digests next to their downloads so you can prove that the file you received is the file they sent — the download did not get truncated or corrupted, and nobody swapped in different content.

Doing it one file at a time is fine for one download. The moment you have a folder of files, or a release archive with a SHA256SUMS manifest inside it, you want the batch version: hash every file once, then check each line of the manifest against the matching file. That is exactly the loop this page automates.

The manifest formats this page reads

StyleExample lineWhere you meet it
GNU900150983c...  hello.txtsha256sum / md5sum output, SHA256SUMS files in Linux releases
BSDSHA256 (hello.txt) = 900150983c...openssl dgst -sha256 on macOS/BSD
SFVhello.txt 1A2B3C4DSimple File Verification files, old binary newsgroups
plainsha256=ba7816bf...Download pages, release notes, Docker checksums

The hash length itself identifies the algorithm: 32 hex characters mean MD5, 40 mean SHA-1, 64 mean SHA-256, 96 SHA-384 and 128 SHA-512 — so GNU-format lines do not need to say which program produced them.

How it works, briefly

Each file is read once with the browser's FileReader and handed to crypto.subtle.digest (the SHA family) and a local MD5 implementation. The digests are hex-encoded and lined up next to the manifest entries; a file verifies only when the computed digest equals the expected one character for character. SFV lines carry a CRC-32 instead of a cryptographic hash — the page flags them as unsupported rather than pretending a CRC equals a digest.

Common mistakes

“All my files say mismatch.” — the usual cause is a manifest made for a different version of the download. Check the file names first: the matcher compares base names, so dist/app-1.2.bin matches a manifest line for app-1.2.bin. “SHA-1 verified, so the file is safe?” — no. Verification proves the bytes match what the publisher released; whether the publisher is trustworthy is a different question. And SHA-1 is collision-broken since 2017, so prefer SHA-256 manifests when you have the choice.

FAQ

Is hashing a big file slow? — roughly a second per 200 MB on a normal machine; a progress line shows how far along the batch is.
Can I verify a CRC-32 SFV manifest? — SFV lines are parsed and listed, but a CRC-32 is not computed by this page; use the CRC tool on the crypto hub for single files.
Why hex only? — manifests in the wild are hex; base64 digests are an feature.
What happens to my files? — nothing: no server, no storage, no analytics; close the tab and every byte of input is gone.