How to create a checksum manifest for a batch on a Mac
You can do this with B64 by switching one setting on. Here is what the manifest contains and what it is actually for.
You have converted a thousand files and handed the folder to someone. Six months later a question arrives: is this the same as what you sent? Without a record there is no way to answer it. With a manifest the answer is yes or no.
Switch it on
Open Settings
B64 ▸ Settings…, or ⌘,.
Go to General
Find include a checksum manifest in batch exports and switch it on. It stays on until you turn it off.
Run your batch
Convert as usual and save the results. A
checksums.txtis written into the same folder, alongside everything else.
What the manifest contains
One line per file: its SHA-256 and its name. A checksum is a fixed-length fingerprint of a file's bytes — change one bit anywhere and the checksum changes completely, so two files with the same SHA-256 are the same file.
9f2c4a71e0b83d5619ca7e04f8b2d3a6c18e7b45d90a2f6e3c4b8175d0e2a9f36 logo@2x.txt
4b7e1d0c93a25f8e6117cb4d2a90e5f38c7b16a4de052193f8c6a7b204e91d5c sprite-sheet.txt
e3a97c5410d8b62fa7e5013b94c8d2f60a71e5934bc80d217fa6b3e59c04d187 favicon-512.txtIt is plain text. You can read it, search it, keep it in version control, or attach it to the hand-off.
What it is actually for
- Proving a hand-off arrived intact. The recipient compares their copies against the manifest you sent.
- Finding the one file that went wrong. On a thousand-file run, a manifest turns something is broken into this file is broken.
- Detecting silent corruption. Files on a drive or a network share can rot. A manifest from the day they were written is the only way to know.
- Keeping a record for later. A run you might need to account for in a year.
It proves that a file is unchanged. It does not prove who produced it — anyone who can alter the files can alter the manifest that sits next to them. For integrity it is exactly the right tool; for authenticity it is not the tool at all.
Checking a single file later
Load the file into B64 and read its SHA-256 in the Inspector (⌥⌘I). If it matches the line in the manifest, the file is unchanged, byte for byte. See how to get the SHA-256 checksum of an image.
The same trick verifies a round trip. Encode a file, decode the result, and compare the checksum of the decoded bytes against the checksum of the source. They match, because Base64 is lossless — and now you have shown it rather than assumed it.
Troubleshooting
There is no checksums.txt in my export
The setting was off when the run was saved. Switch it on in Settings and export again.
A checksum does not match
The file has changed since the manifest was written. On a transferred folder that usually means a truncated or interrupted copy; re-transfer that one file and check again.
Two different files have the same checksum
They are not different files — they are two copies of the same bytes under different names. That is useful when you are auditing a folder for duplicates.
Frequently asked questions
What is in the manifest?
One line per file: a SHA-256 checksum and the file name, in plain text you can read, search or keep in version control.
What is a checksum for?
Proving a file is unchanged. Change one bit and the checksum changes completely, so matching checksums mean identical bytes.
Does it prove who made the files?
No. A checksum proves integrity, not authenticity — anyone who can alter the files can alter the manifest beside them.
How do I check one file against the manifest later?
Load it into B64 and read its SHA-256 in the Inspector, then compare it with the line in the manifest.