This subresource integrity generator builds one integrity token from bytes you supply on the page. The token is the algorithm name, a hyphen, and standard base64 of the raw digest, with padding when the encoding needs it. SHA-384 is the default. SHA-256 and SHA-512 are the other choices. SHA-1 is not offered. The page does not print a hex digest. Base64 of the hex text would be the wrong attribute, so that spelling is not produced here.
Use a local file or the text box, not both. If both are filled, the page stops and does not pick one. A chosen file is hashed as its bytes. The file name is shown as text and is not mixed into the digest. A file of zero bytes is valid. Empty text with no file is an error, and it is not treated as that zero-byte file. The file is not uploaded, not stored, and not displayed.
Text is hashed as UTF-8. The text box turns CR and CRLF into LF before the digest, so a text digest will not match a file that still uses CRLF. The hint on the tool states that limit. A text box whose whole contents are one http or https URL is refused, because this page does not fetch. A longer text that merely contains a URL is ordinary text and can be hashed.
The output is the source label, the byte length of the exact bytes that were hashed, and the integrity token. Copy writes the token only. The page does not say a CDN matches, and it does not say the resource is safe. Hash Generator remains the hex digest of pasted text, including legacy SHA-1. The Base64 page encodes text. Neither of those pages is this token.
Hashing stays in the browser. The status line says the work happened on the page and that nothing was uploaded or stored.
A chosen file of zero bytes and SHA-384 produces sha384-OLBgp1GsljhM2TJ+sbHjaiH9txEUvgdDTAzHv2P24donTt6/529l+9Ua0vFImLlb and a byte length of 0. The text a and SHA-256 produces sha256-ypeBEsobvcr6wjGzmiPcTaeG7/gUfE5yuYB3ha/uSLs= and a byte length of 1. Those strings are base64 of the raw digest, not base64 of the hex spelling.
The text https://example.com alone is refused. The sentence see https://example.com in a note is hashed as text. A file together with any text is an error. A file larger than 1,048,576 bytes is an error, and no prefix of the file is hashed. Text longer than 200,000 characters is an error, and no prefix of the text is hashed.
The digest stays in the browser. A result is the integrity token for the bytes on this page. It is not a certificate, not a signature, and not a check of a remote file.
One integrity token from a local file or from the text box, not from both. SHA-384 is the default. SHA-256 and SHA-512 are the other choices. SHA-1 is not offered. The token is standard base64 of the raw digest, with padding when the encoding needs it. It is not base64 of the hex text, and this page does not print hex. A chosen file is hashed as its bytes, including a file of zero bytes. The file name is not part of the digest. Empty text with no file is an error, not the zero-byte digest. The text box turns CR and CRLF into LF before the digest, so text will not match a CRLF file. A text box that is only an http or https URL is refused. This page does not fetch. A longer text that merely contains a URL is hashed as text. The file stays on this page. It is not uploaded, stored, or shown. The token does not mean a server or CDN matches, and it does not mean the resource is safe.
An integrity attribute is standard base64 of the raw digest. Hex is a different spelling, and base64 of the hex text is the wrong token. The hash page remains the place for a hex digest.
No. A text box that contains only an http or https URL is refused. Choose the file, or paste the file text. Nothing is requested.
No. Empty text with no file is an error. A chosen file of zero bytes is hashed, and its SHA-384 token is the known zero-byte digest.
No. The token describes the bytes hashed on this page. It does not contact a CDN, and it does not say the resource is safe.