Neatbo.

SHA256SUMS and JWT signatures: what verification can prove

Separate file hashes, JWT signatures and identity trust. Reconcile missing and extra files in SHA256SUMS and understand the limits of local HAR, robots and CSP checks.

Example: receive files and an access token

A release package contains a PDF, a data export and a short configuration note. The sender wants the recipient to know that the files arrived unchanged. A SHA256 manifest can answer that byte-level question. It cannot, by itself, establish who sent the package or whether the content is safe or correct. That distinction determines how the expected manifest should be obtained and stored.

Separate matching bytes from trusted sources

Generate the manifest from the final bytes, then preserve it through a trusted channel. During verification, inspect all three result classes: mismatched files, missing filenames and files not listed in the manifest. Renaming a file may leave its digest unchanged while breaking the name-based lookup. A green result for one file is not an acceptance check for the entire package.

Check files, signatures and configuration separately

Apply the same separation of claims to authentication and web configuration. Decoding a JWT only reveals its structure. Signature verification additionally needs a trusted key and a pinned algorithm, while issuer, audience and time checks answer different questions. Similarly, an offline CSP inspection or robots rule test can reveal a local configuration issue without proving what a deployed browser or crawler actually receives.

A small, checkable example
SHA-256 of an empty file starts e3b0c442; a filename change does not change its bytes, but a manifest lookup still requires the exact name.

Record conditions and unresolved checks

Before sharing a diagnostic report, inspect the report itself. A HAR summary omits query values, headers, cookies and bodies, but its URL path can still identify a customer or internal project. Keep credentials out of examples and compare full fingerprints through an independent source. Local execution reduces upload exposure; it does not remove the need to control what you copy, download or send to another person.

Common assumptions and better checks
Do not rely only onAlso check
Matching hashesEstablish a trusted source for the expected manifest
A valid JWT signatureCheck time, issuer, audience and application authorization
Local rules passCheck actual deployed responses and configuration
  • Record mismatched, missing and unlisted files separately.
  • Do not confuse decoded claims with a verified signature.
  • Review URL paths before sharing a HAR summary.

References

Tools used in this article

Base64 encode / decode →Encode or decode a snippet in a click.URL encode / decode →Make those encoded characters readable again.HTML entities →Convert between HTML entities and readable characters.Unicode escape →Convert Unicode escapes into readable text and back.SHA-256 checksum →Calculate a SHA-256 checksum for text or a file.Inspect and verify JWT →Inspect complete JWT header and claims, or verify HS256 / RS256 with a separately supplied trusted key.QR code maker →Turn a link or a little text into a QR code.UTM link builder →Add your campaign details without the guesswork.Meta tags generator →Fill in page details and copy the resulting meta tags.robots.txt generator →Build a robots.txt file from the crawl rules you choose.Sitemap generator →Turn a list of page URLs into a sitemap XML file.Open Graph preview →Check Open Graph tags in pasted HTML and preview a share card.URL parser →Inspect URL paths, ordered query parameters and key=value fragments without opening the link.HMAC-SHA256 generator →Calculate a SHA-256 HMAC and compare it with a supplied signature in Hex, Base64 or Base64URL.IPv4 subnet and netmask calculator →Calculate IPv4 subnet boundaries and usable endpoints, or convert a netmask and prefix.IP range to CIDR →Turn an inclusive IPv4 address range into the smallest exact list of CIDR blocks.Aggregate CIDR blocks →Reduce an IPv4 CIDR list without changing its address coverage.IPv4 number converter →Convert one IPv4 address between dotted decimal, unsigned integer and 32-bit binary.IPv6 expand and compress →Convert one IPv6 address to canonical, expanded and colon-free 32-digit forms.IPv6 subnet calculator →Find the exact start, end and size of one IPv6 prefix.MAC address normalizer →Convert MAC addresses between colon, hyphen, Cisco dotted and plain formats, including short and Python hex octets.IP address validator →Validate one IPv4 or IPv6 address per line and export the valid entries.IP in CIDR checker →Check a list of IP addresses against one IPv4 or IPv6 CIDR and export matching values.Base32 encoder / decoder →Encode text or any file as RFC 4648 Base32, or decode Base32 to the original bytes.Hex and text converter →Encode text or file bytes as hex and Base64 of the same bytes, or decode plain hex to exact bytes.Binary and text converter →Encode UTF-8 text or file bytes as eight-bit groups or a MATLAB numeric row vector assignment; decode bit text to exact bytes.Quoted-printable converter →Encode a MIME body as quoted-printable or decode one to exact bytes and readable text.SAML response inspector →Decode a SAML 2.0 response locally and inspect SSO status, audience, recipient, NameID and attributes.Password generator →Generate random passwords that fit a site’s length and character rules.Passphrase generator →Create a six-word or longer EFF passphrase for a password manager, disk encryption, or an account that accepts long passwords.SRI hash generator →Calculate SHA-256, SHA-384 or SHA-512 SRI from local file bytes or UTF-8 text, then copy an integrity value or HTML tag.HAR request analysis →Analyze a local HAR export, list every failed request and summarize status classes and slow requests without contacting recorded URLs.robots.txt rule tester →Test pasted or imported robots.txt rules for one URL and crawler token, with an allow decision, selected group, winning rule and line number.Sitemap XML audit →Audit a pasted or imported Sitemap XML file for namespace, schemaLocation pairs, URL structure, duplicates, host consistency and common optional fields.Nginx exact redirect rules generator →Convert a source,target CSV into exact-path Nginx location and return rules, checking duplicate sources and same-site loops.CSP policy inspection →Inspect a pasted CSP policy for malformed source expressions, duplicate directives, broad allowances and missing restrictions.SSH public-key fingerprint →Calculate a SHA256 fingerprint from an OpenSSH RSA or Ed25519 public-key blob and validate its wire structure.File checksum manifests →Generate SHA256SUMS for a batch or verify selected files against a manifest, reporting missing, changed and unlisted files.