Skip to main content
QUIETLYTIC
Cybersecurity

SRI Hash Generator

Paste a script or stylesheet, get its sha256/sha384/sha512 integrity attribute.

Local · nothing leaves this browser Waiting for content
Esc Clear
Integrity attributes

Paste content on the left.

How it works

Subresource Integrity lets a browser verify that a script or stylesheet fetched from a CDN or third-party host is exactly the bytes expected, not a tampered or compromised substitute. The browser hashes what it downloads and refuses to execute it if the digest does not match the integrity attribute.

This hashes whatever text is pasted here — it does not fetch a URL. The value is only correct if the pasted text is byte-for-byte the same file a <script>/<link> tag will actually load, which is why the tool cannot verify that for you; that check belongs to whoever controls the deployed file.

Which algorithm to pick

All three — sha256, sha384 and sha512 — are generated at once. sha384 is the most common in published examples and CDN documentation, but a browser accepts any of the three, so publishing all of them costs nothing and covers whatever a consuming tool expects.

Example

Pasting console.log("hello"); produces a ready-to-paste snippet: <script src="..." integrity="sha384-..." crossorigin="anonymous"></script> — the crossorigin attribute is required for a cross-origin resource, since without it the browser never exposes the response to the integrity check at all.

Frequently asked questions

Why do sha256, sha384 and sha512 all get generated?

A browser accepts any of the three, and sha384 is the most common in the wild, but publishing all three costs nothing and covers a tool on the consuming end that checks a specific algorithm.

Why does my generated hash not match what a CDN shows?

The bytes differ. A CDN sometimes serves a minified, gzip-negotiated, or otherwise transformed copy of a file that differs from whatever was pasted here — the hash is only ever correct for the exact bytes it was computed over.

Do I need crossorigin="anonymous" alongside integrity?

For a cross-origin resource, yes — without it the browser will not expose the response to the integrity check at all and the resource fails to load silently in most configurations. Same-origin resources do not need it, but adding it is harmless.

Related tools

From the intelligence desk