Neatbo.

File checksum manifests

Generate SHA256SUMS for a batch or verify selected files against a manifest, reporting missing, changed and unlisted files.

Browser-local processingInputFile / TextOutputChecksum manifest / reportUp to 30 MiB per file · File limit: 20
  1. 1Add input
  2. 2Adjust settings
  3. 3Get your result

Tool input and files are processed in this browser without being uploaded.

Your input

Inputs are kept temporarily in this tab when switching tools. Refreshing or closing clears them; large results may need to be regenerated.

⌘ / Ctrl + Enter to run

or drag and drop them here

Files stay on this device. Your originals stay unchanged.

Up to 30 MiB per file · File limit: 20

    Options

    Complete the required options first. You can keep the defaults for the rest.

    Preparing the tool…

    Before you start

    Generate a SHA256SUMS file for up to 20 selected local files, or compare selected files with a trusted SHA256SUMS manifest. The result identifies matching, changed, missing and unlisted names.

    How to use this tool

    1. Choose up to 20 local files and generate a downloadable SHA256SUMS manifest.
    2. To verify, select the received files, switch the task to Verify, then paste a trusted previous manifest. Choose complete-manifest or selected-files verification scope.
    3. Review matched, changed, missing and unlisted names separately; download the full JSON report if needed.

    Supported inputs and limits

    Select up to 20 files, 30 MiB each and 80 MiB total. Files are selected individually; folders and recursive scans are not supported. Exact filenames must be unique and cannot contain path separators.

    The manifest uses the GNU SHA256SUMS form: 64 hexadecimal digits, two spaces, then the exact filename. Verification accepts a space or * marker. A checksum detects changes but does not authenticate the manifest publisher. Verification accepts one safe leading ./ and matches the resulting exact basename; nested paths, parent traversal, drive prefixes, backslashes, NUL and duplicate normalized names are rejected.

    Original file bytes stay in the browser. A pasted verification manifest is limited to 1 MiB and 1,000 entries; outputs do not overwrite original files.

    Complete-manifest policy requires every entry present and matching. Selected-files policy permits absent entries while retaining their names and count; scopePassed applies only to that scope. verified always means the complete manifest matched, and never verifies unselected files.

    Worked example

    Example input

    Selected file: hello.txt (exact UTF-8 bytes: abc)
    Example options
    {"mode": "generate"}

    Example output

    ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad  hello.txt
    

    When something does not work

    Check exact filenames, the two-space SHA256SUMS format, and the 20-file limit. In Verify mode paste a trusted manifest before running.

    Frequently asked questions

    Can the tool find missing or changed files?

    Generate mode hashes the selected files. Verify mode compares them against a pasted manifest and separately lists matched, changed, missing and unlisted names.

    What should the example produce?

    A file named hello.txt containing exactly abc produces the shown SHA256SUMS line. Saving or changing even one byte changes the digest.

    Which cases are outside its scope?

    No folder or recursive scan. Choose at most 20 files. A matching digest does not prove who authored the manifest.

    Does a selected-files pass verify the complete manifest?

    No. The report separates selected-file matches, scope pass, complete-manifest verification and absent entries. Review the scope your recipient actually requires.

    Documentation & further reading

    Related tools