.SHA1

SHA1 File

SHA-1 Checksum File
Ask a question
QUICK ANSWER

A .sha1 file is a small plain-text file containing a 40-character SHA-1 fingerprint of another file (an ISO, installer, or archive). You use it to confirm your download arrived without corruption: compute the SHA-1 hash of your file and compare it to the value inside. On Windows run certutil -hashfile yourfile.iso SHA1; on macOS run shasum yourfile.iso; on Linux run sha1sum -c file.sha1. Note: SHA-1 is cryptographically broken since 2017 and cannot prove a file wasn't maliciously replaced.

Developer: Convention (no single author); SHA-1 algorithm by NSA / NIST, FIPS 180-1, 1995 Category: Misc Files Open standard MIME: text/plain
OPENS ON Windows macOS Linux
Related: .TORRENT · .MSO · .MD5 · .SHS

On this page

19k+ extensions indexed
Last reviewed Sep 9, 2026

Not sure what your file is?

Drop any file into our identifier - we read just the first bytes to name the format.

Identify a file

What is the SHA1 file format?

.SHA1 is a plain-text checksum sidecar file that stores one or more SHA-1 cryptographic digests alongside their corresponding filenames. Its format follows the GNU sha1sum convention: each line contains a 40-character lowercase hexadecimal digest (representing 160 bits / 20 bytes), a two-space separator (or * for binary mode), and the filename.

SHA-1 was published by NIST in April 1995 (FIPS 180-1) and became a standard integrity-verification tool for software distribution throughout the late 1990s and 2000s. A .sha1 sidecar allows a user to verify a downloaded file has not been corrupted - by running sha1sum -c file.sha1 on Linux/macOS or certutil -hashfile / Get-FileHash -Algorithm SHA1 on Windows.

Important: SHA-1 is cryptographically broken. Google and CWI Amsterdam demonstrated a practical collision attack (*SHAttered*) in February 2017, proving two different files can produce the same digest. NIST had already deprecated SHA-1 for security use in 2011. .sha1 files remain useful for detecting accidental corruption (bit-rot), but must not be relied upon to verify authenticity or detect deliberate tampering. For security purposes, .sha256 or .sha512 are strongly preferred.

SHA-1 remains in widespread use in Git for object hashing; newer Git repository formats are actively migrating to SHA-256.

Security & safety

RISK: LOW

The .sha1 file itself is harmless plain text. The security concern is what SHA-1 guarantees: it reliably detects accidental corruption (bit-flip, truncated download) but is cryptographically broken since the 2017 SHAttered collision attack. A matching SHA-1 does NOT prove a file was not deliberately replaced. For security-sensitive downloads (OS images, signed software), verify a SHA-256 or SHA-512 checksum AND the publisher's PGP/GPG signature. Ensure the published hash comes from a trusted HTTPS source, not the same server as the file.

Format details

in a nutshell
FULL NAMESHA-1 Checksum Fileaka SHA1 hash sidecar, SHA-1 digest file
DEVELOPERConvention (no single author); SHA-1 algorithm by NSA / NIST, FIPS 180-1, 1995since SHA-1 published April 1995 (FIPS 180-1); .sha1 sidecar convention in common use since late 1990s
CATEGORYMisc Files
MIME TYPEtext/plain
TYPEplain-text checksum sidecar (one or more SHA-1 digests with filenames)
STANDARDOpen · royalty-free

Programs that open SHA1 files

Windows5 apps
Windows Notepad Built-in Opens the .sha1 as text to read the expected hash value - does NOT compute or verify anything.
Notepad Open-source Opens the .sha1 as plain text; readable and editable.
certutil (built-in) Built-in Run 'certutil -hashfile yourfile.iso SHA1' in Command Prompt, then compare the 40-char output to the value in the .sha1 file.
PowerShell Get-FileHash Built-in Run 'Get-FileHash yourfile.iso -Algorithm SHA1' and compare the Hash column to the .sha1 value.
HashCheck Shell Extension Open-source Right-click any file → Properties → Checksums tab; shows SHA-1, MD5, CRC32 for comparison against .sha1 contents.
macOS2 apps
TextEdit Built-in Opens .sha1 as plain text for reading the hash value.
shasum (Terminal, built-in) Built-in Run 'shasum yourfile.iso' (defaults to SHA-1) or 'shasum -c file.sha1' to auto-verify. Compare output to the .sha1 value.
Linux2 apps
gedit Open-source Opens .sha1 as plain text for reading.
sha1sum (coreutils, built-in) Open-source Run 'sha1sum -c file.sha1' in the directory containing the file - outputs OK or FAILED per entry. Or 'sha1sum yourfile' to compute and compare manually.

Technical details

deep spec
Digest algorithmSHA-1 (Secure Hash Algorithm 1), FIPS 180-1 / FIPS 180-4
Digest length160 bits (20 bytes), represented as 40 lowercase hexadecimal characters per hash
File encodingPlain ASCII text (UTF-8 for filenames containing non-ASCII characters)
Line format<40-char hex> <filename> (two-space separator, text mode); <40-char hex> *<filename> (binary mode)
Command-line compatibilityGNU sha1sum -c (Linux/macOS); certutil -hashfile (Windows); Get-FileHash -Algorithm SHA1 (PowerShell)
ContainerNone - plain text file, no binary wrapper
Typical file sizeUnder 1 KB (single-file sidecar); a few KB for multi-file manifests
Security statusCryptographically broken - SHAttered collision demonstrated February 2017 (Google / CWI Amsterdam)
NIST deprecationDeprecated for security use since 2011; SHA-1 TLS certificates distrusted by major browsers since 2017
Remaining valid useAccidental corruption detection (bit-rot) in non-adversarial contexts; Git object hashing (legacy SHA-1 mode)
Preferred replacementSHA-256 (.sha256) or SHA-512 (.sha512) per NIST SP 800-131A
ReleasedSHA-1 published April 1995 (FIPS 180-1); .sha1 sidecar convention in common use since late 1990s
Latest versionFIPS 180-4 (2015) - no versioned file format; format is a convention
Open standardYes · royalty-free
Specificationcsrc.nist.gov

SHA1 conversions

Community Q&A

asked by users
Ask a quick question
Get help from people who work with SHA1 files. Be specific - include your system and software version.
No account needed · answers usually within a day

No questions yet - be the first to ask about SHA1 files.

Frequently asked questions

How do I verify a file against a .sha1 checksum?
Windows: 'certutil -hashfile yourfile SHA1' then compare to the .sha1 contents. macOS: 'shasum -c file.sha1'. Linux: 'sha1sum -c file.sha1'.
Is SHA-1 still safe to use?
For detecting accidental corruption - yes. For security verification - no. SHA-1 collisions are practical since 2017. Use SHA-256 or SHA-512 for any security-critical purpose.
What is the difference between .sha1 and .sha256?
.sha1 holds a 40-character SHA-1 digest (160-bit, broken); .sha256 holds a 64-character SHA-256 digest (256-bit, currently secure). The file format is identical - plain text.
Can I convert a SHA-1 hash to SHA-256?
No. Hashing is a one-way process. You must hash the original file again with SHA-256 - you cannot derive a SHA-256 from an existing SHA-1.
The SHA-1 values don't match - what should I do?
Re-download the file. A mismatch usually means a corrupted or incomplete download. In rare cases it could indicate tampering; when in doubt, get the file from the official source.
Does Git use SHA-1?
Historically yes - Git uses SHA-1 for object IDs. Since Git 2.29 (2020) SHA-256 is an option; transition to SHA-256 as the default is ongoing but not yet complete.

References

1GNU coreutils - sha1sumwww.gnu.org
2Microsoft - certutil command referencelearn.microsoft.com

Keep exploring

across the database

Top extensions this week

1.AQQAQQ Instant Messenger File
2.CRDOWNLOADChrome Partial Download File
3.BINCD/DVD Disc Image (BIN/CUE)
4.DATProgram Data File (generic)
5.PARTPartial Download File
6.EXEWindows Executable (Portable Executable)
7.NOMEDIAAndroid No-Media Marker File
8.RPMSGRestricted Permission Message
9.TMPTemporary File
10.TXTPlain Text File

Related extensions

.TORRENTBitTorrent Metainfo File
.MSOMicrosoft Office HTML/OLE Data Stream (oledata.mso)
.MD5MD5 Checksum File
.SHSShell Scrap Object File
.DDDAdobe Acrobat Distiller file
.DWLDrawing Lock File (CAD)

Free file tools

An in-browser file identifier and image converter - everything runs on your device.

Open the toolbox

Browse file extensions A-Z