How to get the SHA-256 checksum of an image on a Mac
You can do this with B64 in one click, for the file you encoded or the bytes you decoded. Here is where it is and what to do with it.
A checksum is a short fingerprint of a file's bytes. Change one bit anywhere in the file and the fingerprint changes completely, which makes it the only clean answer to questions like is this the same file? and did it arrive intact?
This guide covers reading one in B64.
Read the checksum
Load the file
In Encode (⌘1) for a source file, or in Decode (⌘2) for a payload you have just decoded.
Open the Inspector
Press ⌥⌘I, or click the info button in the toolbar.
Compute it
The SHA-256 row computes with one click. Select the value to copy it — every value in the Inspector is selectable text.
Which checksum you are looking at
| Workspace | The checksum is of |
|---|---|
| Encode | The source file you loaded, before encoding |
| Decode | The decoded bytes, after decoding |
| Batch | The selected item, plus the manifest for the whole run |
That pairing is the useful part. The checksum of a source in Encode and the checksum of the decoded bytes in Decode are the two ends of a round trip, and they should be identical.
Prove a round trip is lossless
Encode the file and note its checksum
Load it in Encode, open the Inspector, compute the SHA-256.
Decode the result
Copy the Base64 and paste it into Decode — which is free.
Compare
Compute the SHA-256 of the decoded bytes. It matches. Not approximately: exactly, every character.
It converts a claim into an observation. Base64 is lossless — but seeing two identical sixty-four-character values is a different kind of confidence from reading that it is.
What a checksum settles, and what it does not
It settles: whether two files are byte-identical; whether a file changed since you last looked; which one file out of a thousand is the broken one; whether a download or a copy completed.
It does not settle: who made the file. A checksum proves integrity, not authenticity — anyone who can change a file can also change the checksum written next to it. For integrity it is exactly the right tool; for authenticity it is not the tool at all.
Checksums for a whole folder
Switch on the manifest in B64 ▸ Settings… ▸ General and every batch export writes a checksums.txt alongside the results — one line per file. See how to create a checksum manifest.
Troubleshooting
The checksum does not match the one I was given
The files differ. On a transfer, that is usually a truncated or interrupted copy. Check the file sizes first — if those differ too, the copy is incomplete.
Two files I think are identical give different checksums
They are not identical. Metadata is part of a file's bytes, so two exports of the same picture with different timestamps or different EXIF are different files.
The value is too long to read
Select it and copy it rather than reading it. Comparing sixty-four hexadecimal characters by eye is error-prone.
Frequently asked questions
What is a SHA-256 checksum for?
Proving that two files are byte-identical. Change one bit and the value changes completely, so matching checksums mean the same file.
Does Base64 change a file's checksum?
No. Encode a file and decode the result, and the decoded bytes have the same SHA-256 as the source — which you can verify in the Inspector in about a minute.
Does a checksum prove where a file came from?
No. It proves integrity, not authenticity. Anyone who can change a file can change the checksum written beside it.
Can I get checksums for a whole folder?
Yes — switch on the manifest in Settings and every batch export writes a checksums.txt with one line per file.