Hash & Checksum Verifier

Check downloads against their published checksum — and verify the checksum file’s own OpenPGP or minisign signature, so you know who published it.

Runs entirely in your browser. Your browser blocks this page from opening connections or loading anything from other sites. Nothing you enter is uploaded or saved.

requests since opened: 0
How to verify this yourself
  1. Open your browser’s developer tools (F12, or ⌥⌘I on Mac) → Network tab, then use the tool. No new requests appear.
  2. Or disconnect from the internet after the page loads — the tool keeps working, because it never needed the network.
  3. See the rule itself: in the Network tab, select this page’s document → Response Headers → content-security-policy contains connect-src 'none' and no 'unsafe-inline' for scripts.
  4. Press Test the lock: the page tries a harmless request and the browser blocks it (the Console shows the refusal).
How to use
  1. Single file: drop it and paste the published checksum.
  2. Signed release: add the publisher’s key, the checksum list and its signature, then your downloads.
  3. Compare the key fingerprint shown with the one on the publisher’s website.

Drop a file here, or

Read in 4 MB pieces straight from your disk. Files over 1 GB work with MD5, SHA-1 and SHA-256.

Checks every algorithm against the published FIPS 180 / RFC 1321 answers, including 1,000,000 × “a”.

Common questions

How do I verify a file’s SHA-256 checksum?

Drop the file and paste the checksum from the download page. The algorithm is detected from its length, and you get a clear match or mismatch. Large files are read in pieces, so multi-gigabyte ISOs work.

Is a matching checksum enough?

It proves the file matches the list, not that the list is genuine — an attacker who changes the download can change the checksum too. Verifying the list’s signature with the publisher’s key closes that gap.

Is my file uploaded?

No. Your browser reads the file from your disk, and the page cannot open any connection to send it.

Known limitations

  • Keys are never fetched: you supply the publisher’s public key, and must check its fingerprint against an official source.
  • OpenPGP: v4 signatures with RSA or Ed25519 keys (what Linux distributions and most vendors use). Key expiry and revocation are not checked.
  • MD5 and SHA-1 catch accidental corruption but not deliberate tampering. SHA-384/512 are limited to files up to 1 GB.
  • Large files are read in pieces to stay light on memory, so files over 256 MB hash more slowly than native tools.
  • Browser extensions with access to this site can read the page. For sensitive data, use a private window with extensions off. How the lock works

tools v0.9.0 · build 7317bbb · 2026-10-07