How to Add a SHA-256 Hash to an Archived Webpage PDF
Calculate a SHA-256 checksum for a finished webpage PDF, save it beside the file, and verify later that the PDF has not changed.
To add a SHA-256 hash to an archived webpage PDF, first finish and save the PDF, then calculate SHA-256 over its exact bytes and record the hexadecimal digest in a separate checksum file or archive manifest. Keep the PDF filename and useful capture context with the digest. If you edit, OCR, optimize, sign, or otherwise rewrite the PDF afterward, calculate a new digest.
A detached checksum is usually the clearest choice because writing the hash into the PDF changes the file whose hash you are trying to record. The commands below work on the saved PDF bytes; no PDF-specific hashing feature is needed.
1. Finalize the PDF before hashing
- Save the webpage as a PDF in its final location.
- Complete any intended edits, OCR, metadata changes, optimization, or signature operations.
- Choose the exact final file to preserve, and avoid modifying it after calculating its checksum.
A PDF is a useful page-oriented copy, but it may not retain links, interactive behavior, referenced resources, or related pages. If your goal is to preserve a fuller website record, see the NARA guidance on managing web records, which discusses component parts, original links, functionality, internally referenced URLs, and web-archive formats such as WARC and WACZ. Those formats are not mandatory for every archive; they address a broader preservation need than a PDF plus checksum.
2. Calculate the SHA-256 digest
macOS and other Unix-like systems
shasum -a 256 "archived-page.pdf"
The output includes a 64-character hexadecimal digest and usually the filename. The -a 256 flag selects SHA-256.
Linux with coreutils
sha256sum "archived-page.pdf"
Windows PowerShell
Get-FileHash "archived-page.pdf" -Algorithm SHA256
PowerShell displays the digest and the algorithm. These commands read the file; they do not alter it. Adobe documents the shasum -a 256, sha256sum, and PowerShell Get-FileHash command forms for calculating a file fingerprint. See Adobe’s checksum instructions.
3. Save a detached checksum record
Save the complete digest outside the PDF, for example in archived-page.pdf.sha256.txt or in the archive’s manifest. Identify the exact PDF and include capture context you know, such as its source URL and capture date. Example:
File: archived-page.pdf
Algorithm: SHA-256
SHA-256: 4b6f...replace-with-the-complete-64-character-digest...
Source URL: https://example.com/page
Capture date: 2026-10-04
The abbreviated value above is only a format example. Store the complete digest produced by your command, not an ellipsis. Keep the manifest or sidecar with the archived file and preserve the reference record so it remains available for later comparison.
4. Verify the PDF later
Run the same command on the same PDF and compare the newly calculated digest with the saved reference value, character for character. A match means the checked file has the same SHA-256 digest as the reference. If they differ, first confirm that you have the intended file and version and used SHA-256 in both calculations. A mismatch means the bytes do not match the reference digest; it does not by itself explain why.
Quick verification commands
# macOS or other Unix-like systems
shasum -a 256 "archived-page.pdf"
# Linux with coreutils
sha256sum "archived-page.pdf"
# Windows PowerShell
Get-FileHash "archived-page.pdf" -Algorithm SHA256
On Unix-like systems, you can also put the reference in a standard checksum file and ask the checksum tool to check it. For example, if archived-page.pdf.sha256 contains the digest, two spaces, and the filename:
sha256sum --check archived-page.pdf.sha256
For a portable check across systems, compare the hexadecimal strings directly and ensure the algorithm is SHA-256 on both sides.
Why the checksum should usually stay outside the PDF
A SHA-256 digest is a fingerprint of a particular byte sequence. If you insert the digest into the PDF, the PDF bytes change, so the digest you calculated before insertion no longer describes the resulting file. You could calculate a new digest after editing, but printing that new value into the same PDF repeats the problem. A sidecar or manifest avoids that loop and lets the PDF remain unchanged.
Keep the record unambiguous: include the exact filename, algorithm, full digest, and enough provenance to distinguish this capture from another. For archives with many files, use a manifest with one entry per file rather than a loose list of unlabeled hashes.
What a matching SHA-256 hash proves—and what it does not
A match supports the conclusion that the checked file has the same digest as the file represented by the trusted reference value. It does not independently prove who created the PDF, when the page was captured, whether the webpage was complete, or whether the saved reference digest is trustworthy. Preserve provenance and capture context alongside the file. NARA describes web-record integrity in terms of completeness and lack of alteration, and also emphasizes reliability, authenticity, usability, context, and structural relationships. See NARA’s web-record guidance.
A SHA-256 checksum is also distinct from a PDF digital signature. A detached checksum is an external value for comparison. A digital signature is a cryptographic signing operation associated with a signer identity and certificate. Adobe’s technical guide to digital signatures in PDF describes computing a digest over PDF byte ranges while excluding the signature value bytes, then signing and embedding it. That is a different process from printing or storing a standalone checksum.
PDF/A, checksums, signatures, and web archives are different tools
| Item | What it is for | Does it replace a detached SHA-256 record? |
|---|---|---|
| A page-oriented document copy of the captured webpage. | No. Hash the final PDF if you need a checksum for that file. | |
| PDF/A | A constrained PDF format family intended to support long-term preservation of page-oriented documents. | No. It concerns document format characteristics, not a separately maintained checksum. See the Library of Congress PDF/A description. |
| Detached SHA-256 checksum | A digest stored outside the file for later comparison against a reference. | This is the checksum record. |
| PDF digital signature | A signing operation tied to a signer identity and certificate, with signature data embedded in the PDF. | No. It serves a different purpose and follows a different signing process. |
| WARC or WACZ web archive | A broader package for preserving web content and capture information. | No. A PDF checksum can still be useful for checking the PDF component. |
Optional: create the webpage PDF with ScreenshotNeo
If you still need to create the webpage PDF, ScreenshotNeo is a website screenshot API and MCP server for developers. Its API supports PDF capture; the API documentation is at ScreenshotNeo docs. Hash the finished PDF after you have saved it, using the commands above.
curl -G "https://api.screenshotneo.com/v1/shot" \
-d access_key=YOUR_API_KEY \
--data-urlencode url=https://stripe.com \
-d format=pdf \
-o archived-page.pdf
ScreenshotNeo accepts cookie and consent banners like a visitor and removes more than 60 known consent platforms, newsletter popups, and chat widgets before capture; each step can be turned off. Bot checks or CAPTCHAs, blank pages, timeouts, failed loads, and cache hits cost nothing, and each response says which outcome occurred in the X-Page-Verdict and X-Billed headers. It also provides an MCP server for AI agents, with take_screenshot, get_page_info, and capture_pdf tools.
There are 1,000 screenshots a month on the free plan with no card required. Paid plans start at $5 for 3,000 screenshots; all features are on every plan. Sign up for free and get 1,000 screenshots a month with no card.
Troubleshooting
The digest differs from the saved value
- Confirm that both calculations use SHA-256, not another algorithm.
- Check that you selected the same PDF version and filename. Re-exporting, editing metadata, running OCR, optimizing, or signing can change bytes.
- Recalculate from the final archived file and update the reference only if you have confirmed that this is the intended new version. Keep prior manifests when version history matters.
The command says the file cannot be found
- Check the current folder with
pwdon Unix-like systems orGet-Locationin PowerShell, then use the full file path if needed. - Quote paths containing spaces, for example
shasum -a 256 "/archives/2026/archived page.pdf". - Confirm the extension and spelling. A downloaded file may have a suffix such as
(1).
The output is truncated or copied incorrectly
- Copy the complete hexadecimal digest, not the filename or surrounding labels.
- Preserve all characters exactly. Hexadecimal letters are case-insensitive for comparison, but the number and sequence of characters must match.
- Re-run the command and compare against the output directly if the saved value looks incomplete.
The PDF changed after the checksum was recorded
- Any byte-level change produces a different digest. Calculate a fresh checksum for the final file and replace or version the manifest entry.
- Do not try to keep a digest printed inside the PDF synchronized with the PDF itself; store it in a sidecar or manifest.
Performance, reliability, and cost
SHA-256 calculation reads the PDF bytes and produces a short digest. It requires no paid product for this workflow; the commands shown use available system utilities. For large files or batches, process files from their final storage location and keep a manifest that maps each filename to its complete digest. If a copy is transferred between storage systems, calculate the digest after transfer and compare it with the trusted saved value.
Reliability depends on preserving both the file and its reference digest. A checksum alone cannot restore a damaged PDF, establish provenance, or prove that the source webpage was faithfully captured. Maintain independent copies and capture records according to your archive’s needs, and use a broader web-archive package when a PDF does not preserve enough of the record.
FAQ
How do I calculate a SHA-256 checksum for a PDF?
Use shasum -a 256 file.pdf, sha256sum file.pdf, or PowerShell’s Get-FileHash file.pdf -Algorithm SHA256, depending on your system.
Can I put the hash in the PDF itself?
You can add text, but doing so changes the PDF bytes. Store the digest externally if it needs to describe the unchanged final PDF.
Does a matching hash prove that the webpage was authentic or complete?
No. It compares a file with a reference digest. Preserve source, capture date, and other provenance separately, and consider a broader web archive if page resources and relationships matter.
Is PDF/A a checksum format?
No. PDF/A is a constrained PDF format family for preservation-oriented documents. It does not replace a detached SHA-256 checksum.


