Subresource Integrity Generator

Hash exact local script or stylesheet bytes and generate an escaped HTML tag with an SRI attribute.

Files stay on your device No sign-up Free to use
How this works

The tool runs in this browser. Your file or text is not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

Privacy details

Process files controls

Drop your file here

or choose one from your device

One file up to 10 MiB. Its exact bytes are hashed without text decoding.

    Used in the tag only; never fetched. Ensure the deployed file has identical bytes.

    How to use Subresource Integrity Generator

    1. Select the local script or stylesheet with the exact bytes you will deploy.
    2. Choose the hash and tag kind, then supply its deployment path or URL.
    3. Copy the tag draft and verify the deployed response has those same bytes.

    Example: Subresource Integrity Generator

    Build a digest for a precisely empty script.

    You add
    Choose a zero-byte file named empty.js. Hash algorithm: SHA-256; HTML tag: Script; deployed path: /assets/empty.js.
    You get
    The integrity value is sha256-47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=. The HTML draft refers to /assets/empty.js without fetching it.

    Options

    Hash algorithm
    The digest algorithm must be one of the supported SHA variants. The chosen name becomes part of the integrity attribute.
    HTML tag
    Select a script tag or a stylesheet link tag. This changes the HTML draft, not the file content that was hashed.

    Supported inputs and limits

    One local asset up to 10 MiB. SHA-256, SHA-384 or SHA-512 requires Web Crypto on a secure supported page. The supplied URL is a tag label and is never fetched. Deployed bytes must match exactly; cross-origin SRI also requires CORS permission. A digest does not validate file safety.

    Where your input is processed

    This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.

    Even a small byte change changes the digest

    Line-ending conversion, minification or an added comment produces different bytes and therefore a different integrity value. Hash the final artifact rather than an earlier source file. A digest checks agreement with those bytes, not whether the JavaScript or stylesheet is safe.

    Cross-origin use has another requirement

    For an external asset, integrity checking also depends on the asset response permitting the required CORS access. This generator does not query that server, test the URL or publish the tag. Check the actual delivered resource in the consuming browser after deployment.

    Questions about Subresource Integrity Generator

    Does the URL field download the asset?

    No. Only the selected local file is hashed.

    Will changing line endings affect the hash?

    Yes. Hashing uses exact bytes, including a byte-order mark and line endings.

    Why can an accurate cross-origin hash still fail?

    The asset server also needs to permit the CORS request.

    Project manager: Tony Hines · Content updated 3 October 2026 · Report a problem