security · Browser tool
Base64 & Hash Toolkit
Encode or decode Base64 and Base64URL, and hash the same input with the SHA-2 family. Text and files are handled the same way, as bytes.
Source
The file is read with FileReader and never sent anywhere. Large files are hashed in full; the Base64 view is trimmed for display only.
Encode to Base64
Decode from Base64
Hashes of the source
Check against an expected checksum
The comparison walks the full length of both strings and folds every character into one accumulator, so a wrong answer takes the same work as a right one.
What this does
Base64 turns arbitrary bytes into 64 printable characters, three bytes at a time becoming four characters. That is where the one-third size increase comes from, and why the output length is always a multiple of four once padding is applied. Base64URL uses the same table with - and _ in place of + and / so the result survives a URL or a filename untouched, and it usually drops the = padding. This page accepts either on input, padded or not, and works out the rest.
Text is encoded as UTF-8 first
A common bug in Base64 code is calling btoa straight on a string. That function only accepts characters in the Latin-1 range, so an emoji or a Greek letter throws an exception. Bytes are what Base64 actually operates on, so the text here goes through TextEncoder to become UTF-8 bytes before anything else happens. Try the ü in the sample text: it encodes to two bytes, not one.
Why there is no MD5
The Web Crypto API deliberately does not implement MD5, and neither does this page. Writing MD5 by hand in JavaScript is easy enough, but a hash function you cannot verify is a hash function you should not rely on, and MD5 has had practical collisions since 2004 — two different files can be made to share a digest. If you have an MD5 checksum from a vendor, treat it as a download-corruption check, not evidence that the file is the one they published. The four algorithms offered here all come from the browser's own audited implementation.
Hex and Base64 digests are the same number
A SHA-256 digest is 32 bytes. Written as hex that is 64 characters; written as Base64 it is 44. Checksum files use hex almost always, while Subresource Integrity attributes and many package manifests use Base64. If a published checksum does not match what you see, check the encoding before assuming the file is bad.