Batch File Hash — checksums for many files at once, verified against a manifest
Batch File Hash & Manifest Verifier
Pick or drop many files at once and this page computes the MD5, SHA-1, SHA-256,
SHA-384 or SHA-512 digest of every one of them, entirely inside your browser. Then either
copy the results out as sha256sum-compatible lines for your own release notes,
or paste a checksum manifest (SHA256SUMS, .sha256, .sfv,
BSD openssl dgst output) and let the page tell you which files verified, which
mismatched and which are missing. Nothing is uploaded anywhere.
For a single file with more algorithms, see the
Hash Generator.
1. Pick files
Drop files here, or click to choose them
Up to 50 files, 200 MB each. The files stay on this machine.
No files selected.
2. Algorithms
— hex output; pick at least one.
3. Results
Click any digest cell to copy it. Names and sizes are always listed, so the table doubles as a batch file-size view.
The digest table appears here once you pick files and press Compute.
4. Verify against a manifest (optional)
Paste a manifest in GNU (hash name), BSD (SHA256 (name) = hash),
SFV (name crc32) or plain (sha256=hash) style, or upload the
.sha256 / SHA256SUMS / .sfv file itself. Lines starting with
; are treated as comments.
Privacy: every digest is computed with the browser's own JavaScript and
WebCrypto engine — the files never leave this tab. Tip: after verifying a
download it is safe to close this page; nothing was stored.
What is batch file hashing?
A checksum is a short fingerprint of a file: feed the file's bytes through a hash
function and you get a digest that changes almost certainly when even one byte of the file
changes. Software distributors publish those digests next to their downloads so you can
prove that the file you received is the file they sent — the download did not get
truncated or corrupted, and nobody swapped in different content.
Doing it one file at a time is fine for one download. The moment you have a folder of
files, or a release archive with a SHA256SUMS manifest inside it, you want the
batch version: hash every file once, then check each line of the manifest against the
matching file. That is exactly the loop this page automates.
The manifest formats this page reads
Style
Example line
Where you meet it
GNU
900150983c... hello.txt
sha256sum / md5sum output, SHA256SUMS files in Linux releases
BSD
SHA256 (hello.txt) = 900150983c...
openssl dgst -sha256 on macOS/BSD
SFV
hello.txt 1A2B3C4D
Simple File Verification files, old binary newsgroups
plain
sha256=ba7816bf...
Download pages, release notes, Docker checksums
The hash length itself identifies the algorithm: 32 hex characters mean MD5, 40 mean SHA-1,
64 mean SHA-256, 96 SHA-384 and 128 SHA-512 — so GNU-format lines do not need to say
which program produced them.
How it works, briefly
Each file is read once with the browser's FileReader and handed to
crypto.subtle.digest (the SHA family) and a local MD5 implementation. The
digests are hex-encoded and lined up next to the manifest entries; a file verifies
only when the computed digest equals the expected one character for character. SFV lines
carry a CRC-32 instead of a cryptographic hash — the page flags them as unsupported
rather than pretending a CRC equals a digest.
Common mistakes
“All my files say mismatch.” — the usual cause is a manifest made for a
different version of the download. Check the file names first: the matcher compares base
names, so dist/app-1.2.bin matches a manifest line for app-1.2.bin.
“SHA-1 verified, so the file is safe?” — no. Verification proves the
bytes match what the publisher released; whether the publisher is trustworthy is a different
question. And SHA-1 is collision-broken since 2017, so prefer SHA-256 manifests when you
have the choice.
FAQ
Is hashing a big file slow? — roughly a second per 200 MB on a normal
machine; a progress line shows how far along the batch is. Can I verify a CRC-32 SFV manifest? — SFV lines are parsed and listed, but a
CRC-32 is not computed by this page; use the CRC tool on the
crypto hub for single files. Why hex only? — manifests in the wild are hex; base64 digests are an
feature. What happens to my files? — nothing: no server, no storage, no analytics;
close the tab and every byte of input is gone.