How to use Subresource Integrity Generator
- Select the local script or stylesheet with the exact bytes you will deploy.
- Choose the hash and tag kind, then supply its deployment path or URL.
- Copy the tag draft and verify the deployed response has those same bytes.
Example: Subresource Integrity Generator
Build a digest for a precisely empty script.
Options
- Hash algorithm
- The digest algorithm must be one of the supported SHA variants. The chosen name becomes part of the integrity attribute.
- HTML tag
- Select a script tag or a stylesheet link tag. This changes the HTML draft, not the file content that was hashed.
Supported inputs and limits
Where your input is processed
This tool processes your input in this browser. Your text and files are not uploaded to UseFreeTools. Check this tool's limits for anything it may save on your device.
Even a small byte change changes the digest
Line-ending conversion, minification or an added comment produces different bytes and therefore a different integrity value. Hash the final artifact rather than an earlier source file. A digest checks agreement with those bytes, not whether the JavaScript or stylesheet is safe.
Cross-origin use has another requirement
For an external asset, integrity checking also depends on the asset response permitting the required CORS access. This generator does not query that server, test the URL or publish the tag. Check the actual delivered resource in the consuming browser after deployment.
Questions about Subresource Integrity Generator
Does the URL field download the asset?
No. Only the selected local file is hashed.
Will changing line endings affect the hash?
Yes. Hashing uses exact bytes, including a byte-order mark and line endings.
Why can an accurate cross-origin hash still fail?
The asset server also needs to permit the CORS request.