๐ก๏ธ SRI Hash Generator (integrity attribute)
The hash is calculated directly from the text pasted into the box (file upload is not supported).
Enter content
Generate the integrity attribute value used by Subresource Integrity (SRI) โ a browser feature that detects tampering in externally-loaded resources via <script> or <link> tags โ from a piece of text content. Everything runs entirely in your browser.
How to use
- Paste the content (JS or CSS source code) you want to hash.
- Choose a hash algorithm (SHA-256, SHA-384, or SHA-512).
- Copy the generated integrity attribute value into your <script> or <link> tag.
How the calculation works
Subresource Integrity (SRI), a W3C specification, lets the browser check that JavaScript or CSS loaded from an external server such as a CDN has not been tampered with. You put a hash of the file's contents in the integrity attribute of the <script> or <link> tag. When the browser receives the file, it hashes it the same way and refuses to run or apply it if the hashes do not match. This tool encodes the input as UTF-8, hashes it with SHA-256, SHA-384 or SHA-512, and shows the Base64 result in the form "sha384-โฆ". SHA-384 is the most common choice for SRI.
Worked example
Input: console.log("Hello, Heron Tools!"); Algorithm: SHA-384 Result: sha384-kRDt+sRLDsibNoT2KJ7aLhaapiAtYSpQ8rboCvuX1O3cpwXZ1yPp+IBTEamvLXlV In HTML <script src="https://cdn.example.com/app.js" integrity="sha384-kRDt+sRLDsibโฆ" crossorigin="anonymous"></script> The crossorigin attribute is required when loading from another origin.
Things to be aware of
- The hash will not match if the delivered file differs by even one byte. Watch out for line endings (LF vs CRLF) and trailing newlines. To hash a file directly, you can also run "openssl dgst -sha384 -binary app.js | openssl base64 -A".
- Recompute the hash whenever you update the library version.
- The integrity attribute can list several hashes separated by spaces.
FAQ
What is Subresource Integrity (SRI)?
A mechanism that lets the browser verify that a JS/CSS file loaded from a CDN or other external source hasn't been tampered with. If the integrity attribute's hash doesn't match the actual fetched file's hash, the browser refuses to load the resource.
Is the generated value specific to that exact file?
Yes โ the hash depends on the file's exact content, so even a single-byte change produces a completely different value. Always regenerate the integrity attribute whenever you update the file.
Which algorithm should I choose?
The SRI spec allows SHA-256, SHA-384, or SHA-512. SHA-384 is the most commonly used, though you can also list multiple algorithms space-separated.