Neatbo.

SRI hash generator

Calculate SHA-256, SHA-384 or SHA-512 SRI from local file bytes or UTF-8 text, then copy an integrity value or HTML tag.

Browser-local processingInputFile bytes / UTF-8 textOutputIntegrity value / HTML tagUp to 10 MiB per file · File limit: 1
  1. 1Choose source
  2. 2Calculate hash
  3. 3Use integrity

Tool input and files are processed in this browser without being uploaded.

Your input

Inputs are kept temporarily in this tab when switching tools. Refreshing or closing clears them; large results may need to be regenerated.

⌘ / Ctrl + Enter to run

Choose the exact resource bytes. A local file is safest: pasted text is encoded as UTF-8 and its line endings are normalized to LF. The optional URL only builds an HTML tag and is never fetched.

Resource source

HTTPS URL or /site-path. Used only to build a tag; never fetched.

Choose one file (up to 10 MB).

or drag and drop it here

Files stay on this device. Your originals stay unchanged.

Up to 10 MiB per file · File limit: 1

    Preparing the tool…

    Before you start

    Generate a Subresource Integrity value from the exact bytes of a local JavaScript or CSS file. You can also paste UTF-8 text. Add a resource URL to build a script or stylesheet tag; this tool does not fetch the URL.

    How to use this tool

    1. Choose a local file or switch to pasted text. For a deployed asset, use the exact built file.
    2. Choose SHA-256, SHA-384 or SHA-512. Optionally enter an HTTPS URL or site path and select script or stylesheet.
    3. Calculate, check the hashed byte count, then copy the integrity value or HTML tag. Recalculate after changes.

    Supported inputs and limits

    Hash one local file (up to 10 MB) or pasted UTF-8 text (up to 1 MB) in your browser. Text input uses LF line endings. The optional URL is used only in the generated tag.

    SRI works only when the deployed resource bytes match the hashed input. Cross-origin resources require CORS and the crossorigin attribute.

    Worked example

    Example input

    hello
    Example options
    {"algorithm":"SHA-384"}

    Example output

    sha384-WeF0h3dEjGnea4ANejO7+5/xtGPkQ1TDVTvNucZm+pASWjx5+QOXvfX2oT3oKGhP

    When something does not work

    If the value fails in the browser, hash the final deployed bytes again and check the browser console for an integrity or CORS error.

    Frequently asked questions

    Can I hash a CDN URL directly?

    No. This tool hashes your local file or pasted UTF-8 text. An optional URL only appears in the HTML tag; it is never fetched. Use a copy of the exact deployed bytes.

    Why does the browser reject my integrity value?

    The resource bytes may differ because of a build, minification, encoding or line-ending change. Text input uses LF line endings, so hash the final deployed file. For a cross-origin resource, the server must allow CORS.

    Is my input sent to a server?

    No. File and text input are hashed in your browser. Temporary workspace state remains in this tab; save the output you need.

    Documentation & further reading

    Related tools