SRI Hash Generator
Paste a script or stylesheet, get its sha256/sha384/sha512 integrity attribute.
Paste content on the left.
How it works
Subresource Integrity lets a browser verify that a script or stylesheet fetched from a CDN or third-party host is
exactly the bytes expected, not a tampered or compromised substitute. The browser hashes what it downloads and
refuses to execute it if the digest does not match the integrity attribute.
This hashes whatever text is pasted here — it does not fetch a URL. The value is only correct if the pasted text
is byte-for-byte the same file a <script>/<link> tag will actually load,
which is why the tool cannot verify that for you; that check belongs to whoever controls the deployed file.
Which algorithm to pick
All three — sha256, sha384 and sha512 — are generated at once. sha384 is the most common in published examples and CDN documentation, but a browser accepts any of the three, so publishing all of them costs nothing and covers whatever a consuming tool expects.
Example
Pasting console.log("hello"); produces a ready-to-paste snippet:
<script src="..." integrity="sha384-..." crossorigin="anonymous"></script> — the
crossorigin attribute is required for a cross-origin resource, since without it the browser never
exposes the response to the integrity check at all.
Frequently asked questions
Why do sha256, sha384 and sha512 all get generated?
A browser accepts any of the three, and sha384 is the most common in the wild, but publishing all three costs nothing and covers a tool on the consuming end that checks a specific algorithm.
Why does my generated hash not match what a CDN shows?
The bytes differ. A CDN sometimes serves a minified, gzip-negotiated, or otherwise transformed copy of a file that differs from whatever was pasted here — the hash is only ever correct for the exact bytes it was computed over.
Do I need crossorigin="anonymous" alongside integrity?
For a cross-origin resource, yes — without it the browser will not expose the response to the integrity check at all and the resource fails to load silently in most configurations. Same-origin resources do not need it, but adding it is harmless.
Related tools
CSP Generator
Build a Content-Security-Policy header directive by directive, not by editing a string.
LocalSecurity Headers Analyzer
Review a set of pasted HTTP response headers against current guidance.
LocalHash Identifier
Narrow an unlabelled hash down to the algorithms that could have produced it.
LocalPermissions-Policy Builder
Turn on, off or origin-scope a browser feature per directive, then copy the header.
LocalX.509 Certificate Decoder
Paste a PEM certificate to read its subject, issuer, validity, key and extensions.
LocalCSR Decoder
Paste a PKCS#10 CSR to read its requested subject, key and Subject Alternative Names.
Local