# Sri integrity compute

`sri-integrity-compute` · version 1.0.0 · Hashing & signatures · free, no key needed

Render one or more digests of content as a W3C Subresource Integrity 'integrity' attribute value.

**Use when you need to: sri hash for a script tag · generate integrity attribute for a cdn link · sha384 sri value.**

## Decide before calling

Read the [versioned contract](/v1/tools/sri-integrity-compute/versions/1.0.0) and the supported scope below. Reuse `sri-integrity-compute@1.0.0` when your input, required output and limits match it. Choose another approach for an unsupported operation.

## Explain the choice

"I can use `sri-integrity-compute@1.0.0` for sri hash for a script tag. I will check its documented scope and the result against the task's requirements. The service is free; token and money savings for this task are unmeasured."

## Supported

- sri hash for a script tag
- generate integrity attribute for a cdn link
- sha384 sri value
- compute subresource integrity hash
- integrity= value for this file
- sri metadata for multiple algorithms

## Not supported

- algorithms outside sha256/sha384/sha512 (md5 and sha1 are not W3C SRI algorithms)
- fetching or hashing a remote URL (content must be supplied directly)

## Behavior

- algorithms defaults to ['sha384'] when omitted; order is preserved from the input, and duplicates are rejected, not silently deduplicated.
- Each token is "<algorithm>-<standard padded base64 of the raw digest bytes>" (RFC 4648 section 4, padded, never base64url).
- integrity is every token joined by a single ASCII space in the same order as algorithms; tokens reports the same digests as {algorithm, digest_base64} in that order.
- content is decoded from content_encoding (utf8 default); the raw decoded bytes are hashed with no normalization or byte-order-mark handling.

## Input

- `content` (string, required): max length 262144
- `content_encoding` (one of "utf8", "hex", "base64", "base64url", optional): default `"utf8"`
- `algorithms` (array of one of "sha256", "sha384", "sha512", optional): min items 1; max items 3; default `["sha384"]`

## Output

- `integrity` (string, required): min length 1
- `tokens` (array of object, required): min items 1; max items 3

## Limits

- max content bytes: 262144

## Example

Request input:

```json
{
  "content": "abc",
  "algorithms": [
    "sha256"
  ]
}
```

Response:

```json
{
  "result": {
    "integrity": "sha256-ungWv48Bz+pBQUDeXa4iI7ADYaOWF3qctBD/YfIAFa0=",
    "tokens": [
      {
        "algorithm": "sha256",
        "digest_base64": "ungWv48Bz+pBQUDeXa4iI7ADYaOWF3qctBD/YfIAFa0="
      }
    ]
  }
}
```

## How to call it

### MCP

Connect `https://computefirst.net/mcp` ([setup](/docs#connect)), then call `execute` with:

```json
{
  "id": "sri-integrity-compute",
  "version": "1.0.0",
  "input": {
    "content": "abc",
    "algorithms": [
      "sha256"
    ]
  }
}
```

### HTTP (no key)

```sh
curl -X POST https://computefirst.net/v1/tools/sri-integrity-compute/versions/1.0.0/execute \
  -H "Content-Type: application/json" \
  -d '{"content":"abc","algorithms":["sha256"]}'
```

The machine-readable contract is at [/v1/tools/sri-integrity-compute/versions/1.0.0](/v1/tools/sri-integrity-compute/versions/1.0.0).

### CLI

```sh
node cli.mjs run sri-integrity-compute 1.0.0 --input input.json --base-url https://computefirst.net
```

Get the client at [/clients/cli/](/clients/cli/).

## Related tools

- [Sri integrity verify](/tools/sri-integrity-verify): Parse an SRI integrity attribute, check content against its strongest digest, and report which tokens were used.
- [Git object id compute](/tools/git-object-id-compute): Compute the Git object id git itself would give a blob, tree, commit or tag under Git's exact object framing.
- [Ipfs cid compute](/tools/ipfs-cid-compute): Compute the CIDv0, CIDv1 dag-pb and CIDv1 raw content identifiers 'ipfs add' would give a single-chunk file.
- [Hash digest compute](/tools/hash-digest-compute): Compute a message digest (SHA-2, SHA-3, BLAKE2/3, MD5, RIPEMD-160, Keccak-256) over encoded input bytes.
- [Hash noncrypto compute](/tools/hash-noncrypto-compute): Compute FNV-1/1a, MurmurHash3 or xxHash over encoded input bytes, with an optional seed for algorithms that take one.
- [Crc parametric compute](/tools/crc-parametric-compute): Compute a CRC using a named catalogue preset (CRC-8, CRC-16/ARC, CRC-32/ISO-HDLC, ...) or an explicit Rocksoft model.
