Skip to content

Checksum Verifier — Java source

Drag and drop a file to compute its MD5, SHA-1, SHA-256, and SHA-512 checksums. Paste an expected hash to verify integrity - detect tampered or corrupted downloads instantly. Runs entirely in your browser.

This is the Java implementation — the same logic the interactive tool runs, in a shareable, citable form.

// Checksum Verifier — MD5 / SHA-1 / SHA-256 / SHA-512 digests + verification.
//
// Language: Java (17+, standard library only)
// Ported from src/lib/checksum-verifier.ts
// display source — part of CosmoDev's polyglot tool pages.
//
// The TS reference implements MD5 from scratch because the Web Crypto API
// dropped MD5; the JDK's java.security.MessageDigest still ships it, so all
// four algorithms use the platform digest here. The verification helpers
// (length-based algorithm detection, normalization, comparison) are ported
// as-is.

import java.security.MessageDigest;
import java.util.Locale;
import java.util.Map;

public final class ChecksumVerifier {

    /** The four checksums of one buffer, as lowercase hex. */
    public record ChecksumResult(String md5, String sha1, String sha256, String sha512) {
    }

    public enum HashAlgorithm { MD5, SHA1, SHA256, SHA512 }

    private static final Map<Integer, HashAlgorithm> LENGTH_TO_ALGO = Map.of(
            32, HashAlgorithm.MD5,
            40, HashAlgorithm.SHA1,
            64, HashAlgorithm.SHA256,
            128, HashAlgorithm.SHA512);

    private ChecksumVerifier() {
    }

    private static String toHex(byte[] bytes) {
        StringBuilder sb = new StringBuilder(bytes.length * 2);
        for (byte b : bytes) {
            sb.append(Character.forDigit((b >> 4) & 0xf, 16));
            sb.append(Character.forDigit(b & 0xf, 16));
        }
        return sb.toString();
    }

    /** Digest a buffer and return lowercase hex. */
    public static String hex(HashAlgorithm algorithm, byte[] data) throws Exception {
        String name = switch (algorithm) {
            case MD5 -> "MD5";
            case SHA1 -> "SHA-1";
            case SHA256 -> "SHA-256";
            case SHA512 -> "SHA-512";
        };
        return toHex(MessageDigest.getInstance(name).digest(data));
    }

    /** Compute all four checksums of a buffer. */
    public static ChecksumResult computeChecksums(byte[] data) throws Exception {
        return new ChecksumResult(
                hex(HashAlgorithm.MD5, data),
                hex(HashAlgorithm.SHA1, data),
                hex(HashAlgorithm.SHA256, data),
                hex(HashAlgorithm.SHA512, data));
    }

    // --- Verification helpers ---------------------------------------------------

    /** Normalize a pasted hash: drop whitespace and `:` grouping, lowercase. */
    private static String normalizeHash(String hash) {
        return hash.trim().replaceAll("[\\s:]", "").toLowerCase(Locale.ROOT);
    }

    /** Detect the algorithm from the hex length: 32=MD5, 40=SHA-1, 64=SHA-256, 128=SHA-512. */
    public static HashAlgorithm detectHashAlgorithm(String hash) {
        String h = normalizeHash(hash);
        if (!h.matches("[0-9a-f]+")) {
            return null;
        }
        return LENGTH_TO_ALGO.get(h.length());
    }

    /** The verdict of comparing an expected hash against a computed result. */
    public record Verification(HashAlgorithm algorithm, boolean match) {
    }

    /**
     * Compare an expected hash against a computed result. Returns null when the
     * expected string is not a recognizable hex hash of a supported length.
     */
    public static Verification verifyChecksum(String expected, ChecksumResult result) {
        HashAlgorithm algorithm = detectHashAlgorithm(expected);
        if (algorithm == null) {
            return null;
        }
        String actual = switch (algorithm) {
            case MD5 -> result.md5();
            case SHA1 -> result.sha1();
            case SHA256 -> result.sha256();
            case SHA512 -> result.sha512();
        };
        return new Verification(algorithm, normalizeHash(expected).equals(actual));
    }
}

Also available in 8 other languages

Every CosmoDev tool ships its pure logic in TypeScript (web) and Go (CLI), with authored implementations in a dozen-plus languages — the same contract, ported. Compare all languages side by side →