Subresource Integrity Generator

Make an integrity attribute from a local file or from text. SHA-384 is the default. A URL is not fetched.

Last updated: October 6, 2026

Tool

This tool will load here.

What this tool does

This subresource integrity generator builds one integrity token from bytes you supply on the page. The token is the algorithm name, a hyphen, and standard base64 of the raw digest, with padding when the encoding needs it. SHA-384 is the default. SHA-256 and SHA-512 are the other choices. SHA-1 is not offered. The page does not print a hex digest. Base64 of the hex text would be the wrong attribute, so that spelling is not produced here.

Use a local file or the text box, not both. If both are filled, the page stops and does not pick one. A chosen file is hashed as its bytes. The file name is shown as text and is not mixed into the digest. A file of zero bytes is valid. Empty text with no file is an error, and it is not treated as that zero-byte file. The file is not uploaded, not stored, and not displayed.

Text is hashed as UTF-8. The text box turns CR and CRLF into LF before the digest, so a text digest will not match a file that still uses CRLF. The hint on the tool states that limit. A text box whose whole contents are one http or https URL is refused, because this page does not fetch. A longer text that merely contains a URL is ordinary text and can be hashed.

The output is the source label, the byte length of the exact bytes that were hashed, and the integrity token. Copy writes the token only. The page does not say a CDN matches, and it does not say the resource is safe. Hash Generator remains the hex digest of pasted text, including legacy SHA-1. The Base64 page encodes text. Neither of those pages is this token.

How to use

  1. Choose a file, or paste text. Leave the other input empty.
  2. Leave SHA-384 selected, or choose SHA-256 or SHA-512.
  3. Choose Hash, or press Enter in the algorithm list. Copy writes the token. Clear empties the text and the file choice and leaves the algorithm selected.

Hashing stays in the browser. The status line says the work happened on the page and that nothing was uploaded or stored.

Example

A chosen file of zero bytes and SHA-384 produces sha384-OLBgp1GsljhM2TJ+sbHjaiH9txEUvgdDTAzHv2P24donTt6/529l+9Ua0vFImLlb and a byte length of 0. The text a and SHA-256 produces sha256-ypeBEsobvcr6wjGzmiPcTaeG7/gUfE5yuYB3ha/uSLs= and a byte length of 1. Those strings are base64 of the raw digest, not base64 of the hex spelling.

The text https://example.com alone is refused. The sentence see https://example.com in a note is hashed as text. A file together with any text is an error. A file larger than 1,048,576 bytes is an error, and no prefix of the file is hashed. Text longer than 200,000 characters is an error, and no prefix of the text is hashed.

Limits

  • One source: a file up to 1,048,576 bytes, or text up to 200,000 characters.
  • SHA-256, SHA-384, or SHA-512. Standard base64 of the raw digest. No hex and no SHA-1.
  • No fetch, no upload, and no claim that a server matches the token.

The digest stays in the browser. A result is the integrity token for the bytes on this page. It is not a certificate, not a signature, and not a check of a remote file.

On this page

Related Articles

Related guides

Related solutions

Related Tools

Need another tool ?

Open the free tools — no signup.

FAQs

newsletter signup

Lorem ipsum dolor sit amet, consectetur adipiscing elit.
Innovative Solutions For Modern Needs
Copyright © 2026 Yallasolve. all rights reserved.