CSP Builder
Build and risk-score Content-Security-Policy headers visually.
OpenCompute SHA-256 / SHA-1 / MD5 checksums for local files. - runs entirely in your browser. Free, fast and private.
Load your input in the editor or upload area on the tool page.
Tune any options shown for File Checksum to match your task.
File Checksum processes everything in your browser with no upload.
Copy, download, or share the output from the results panel.
A mirror site published SHA-256 next to the download. File Checksum hashes the file you already have on disk so you can compare digests without installing a checksum utility for a one-off verify.
Use it after downloading installers, firmware, datasets, or release archives. Prefer SHA-256 for new checks. SHA-1 and MD5 remain available when a vendor still only publishes those older digests. Matching digests means the bytes you hashed match what the publisher intended to publish; they do not prove the publisher is trustworthy.
Common miss: hashing a partial download or a renamed copy that still has a .crdownload sibling. Wait for the transfer to finish, then hash the final path.
Practical note: for short strings rather than files, Hash Generator is faster. For signed webhook bodies, use HMAC or Webhook HMAC instead of a plain file digest.
The file is read with the browser File API and digested via Web Crypto in this page. Nothing is uploaded to compute the checksum.
Related: Hash Generator
Processes data instantly with no server round-trips.
Your data never leaves your browser. Nothing is uploaded.
Works in any modern browser. Nothing to download or install.
No limits, no sign-up, no credit card required.
Works on desktop, tablet and mobile devices.
Beautiful in both themes. Your preference is saved.
Keyboard shortcut
Match a published SHA-256 against the archive you downloaded.
Spot-check that a copied ISO or dump still matches the source digest.
Produce digests you can paste into Compare Hashes next.
Answers for this tool. For site-wide help, open the FAQ hub.
Generators and hashers run locally. Still, never paste production secrets into any site if your security policy forbids it.
Results live in page memory until you leave or clear. Favourites/history do not save password fields unless you explicitly store them in Vault.
When applicable, tools rely on Web Crypto or well-known libraries. Read on-page notes for exact algorithms (SHA-256, bcrypt-style notes, etc.).
After load, crypto helpers typically work offline. Confirm network independence for your threat model.
Browser CSPRNG (crypto.getRandomValues) powers secure generators when the tool states so.
Treat generated secrets like passwords - share only through approved password managers, never chat apps.
OneDevToolkit aids technical workflows; it is not a certification product. See Compliance for processing model language.
Always check you are on your real OneDevToolkit domain before entering sensitive material.
Contact us via Contact with responsible-disclosure details - do not include live production secrets.