SRI hash generator
Calculate SHA-256, SHA-384 or SHA-512 SRI from local file bytes or UTF-8 text, then copy an integrity value or HTML tag.
- 1Choose source
- 2Calculate hash
- 3Use integrity
Tool input and files are processed in this browser without being uploaded.
Before you start
Generate a Subresource Integrity value from the exact bytes of a local JavaScript or CSS file. You can also paste UTF-8 text. Add a resource URL to build a script or stylesheet tag; this tool does not fetch the URL.
How to use this tool
- Choose a local file or switch to pasted text. For a deployed asset, use the exact built file.
- Choose SHA-256, SHA-384 or SHA-512. Optionally enter an HTTPS URL or site path and select script or stylesheet.
- Calculate, check the hashed byte count, then copy the integrity value or HTML tag. Recalculate after changes.
Supported inputs and limits
Hash one local file (up to 10 MB) or pasted UTF-8 text (up to 1 MB) in your browser. Text input uses LF line endings. The optional URL is used only in the generated tag.
SRI works only when the deployed resource bytes match the hashed input. Cross-origin resources require CORS and the crossorigin attribute.
Worked example
Example input
hello
Example options
{"algorithm":"SHA-384"}Example output
sha384-WeF0h3dEjGnea4ANejO7+5/xtGPkQ1TDVTvNucZm+pASWjx5+QOXvfX2oT3oKGhP
When something does not work
If the value fails in the browser, hash the final deployed bytes again and check the browser console for an integrity or CORS error.
Frequently asked questions
Can I hash a CDN URL directly?
No. This tool hashes your local file or pasted UTF-8 text. An optional URL only appears in the HTML tag; it is never fetched. Use a copy of the exact deployed bytes.
Why does the browser reject my integrity value?
The resource bytes may differ because of a build, minification, encoding or line-ending change. Text input uses LF line endings, so hash the final deployed file. For a cross-origin resource, the server must allow CORS.
Is my input sent to a server?
No. File and text input are hashed in your browser. Temporary workspace state remains in this tab; save the output you need.
Documentation & further reading
Related tools
Base64 encode / decode
Encode or decode a snippet in a click.
URL encode / decode
Make those encoded characters readable again.
HTML entities
Convert between HTML entities and readable characters.
Unicode escape
Convert Unicode escapes into readable text and back.