Subresource Integrity Generator

Generate SRI hashes, verify resource content, and create ready-to-use script and stylesheet integrity attributes.

Browser onlySHA-256 / 384 / 512Scripts & CSS

Subresource Integrity generator

Generate browser-compatible integrity hashes for scripts and stylesheets.

Resource content

Integrity result

Generate an integrity hash

The SRI attribute, Base64 digest, and ready-to-use HTML tag will appear here.

Verify integrity value

Supply-chain security

Protect externally hosted resources with Subresource Integrity

Subresource Integrity (SRI) allows browsers to verify that a downloaded JavaScript or CSS resource exactly matches the expected cryptographic hash before executing or applying it.

Generate hashes from deployed files

Always calculate the integrity value from the exact resource served by your CDN or web server. Even a single-byte change, minification, or line-ending difference produces a completely different hash.

Update hashes with every release

Whenever a script or stylesheet changes, generate a new integrity attribute and deploy it together with the updated resource. Old hashes will cause browsers to reject modified files.

Guide

About Subresource Integrity Generator

Subresource Integrity allows browsers to verify that an externally loaded resource matches an expected cryptographic digest.

This tool generates and verifies SRI values for pasted content or local files and can produce ready-to-use markup.

The hash must be generated from the exact bytes served to users.

Supported SRI algorithms

Modern browsers support SHA-256, SHA-384, and SHA-512 integrity metadata.

Hash deployed bytes

Minification, encoding, line endings, or any content change produces a different digest.

Cross-origin resources

Cross-origin SRI requires compatible CORS behavior and commonly uses crossorigin="anonymous".

Update with releases

Whenever the resource changes, deploy a new integrity value with the updated URL or asset.

FAQ

Frequently asked questions

What is Subresource Integrity?

SRI lets a browser verify a resource against an expected cryptographic hash.

Which algorithm should I use?

SHA-384 is a common choice, while SHA-256 and SHA-512 are also supported.

Why does a small file change break SRI?

The digest covers the exact bytes, so any change produces a new value.

What does crossorigin="anonymous" do?

It requests a cross-origin resource without user credentials and enables compatible SRI checks.

Can I hash a remote URL directly?

Browser CORS rules often prevent fetching arbitrary remote resources.

Are files uploaded?

Hashing is intended to occur locally in your browser.

Continue exploring

Useful tools for the next step in the same workflow.