About the SHA-256 Hash
SHA-256 belongs to the SHA-2 family (FIPS 180-4) and produces a 256-bit digest: 64 hex characters or 44 Base64 characters. It has no known practical collision or preimage attacks and is the default choice for integrity checks, content addressing, digital signatures and Subresource Integrity. For example, sha256("abc") = ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad.
To verify a download, choose “Hash a file” and compare the result with the checksum published next to the file (the output of sha256sum or shasum -a 256). The file is read in your browser and hashed with native crypto.subtle.digest; nothing is uploaded.
The Base64 form is what HTML Subresource Integrity expects: integrity="sha256-<base64>", and what many APIs use for body digests. SHA-256 alone is not suitable for storing passwords because it is fast to brute-force; use bcrypt, scrypt or Argon2. For message authentication with a key, use HMAC-SHA256 rather than hashing key + message.
How to use it
- Type text or click “Hash a file”.
- Read the SHA-256 digest in the large box.
- Switch to Base64 for SRI or API headers.
- Copy and compare with the expected value.