Sri integrity verify
sri-integrity-verify · version 1.0.0 · Hashing & signatures · free, no key needed
Parse an SRI integrity attribute, check content against its strongest digest, and report which tokens were used.
Use when you need to: check this script matches its integrity attribute · verify sri hash · does this file match sha384-... integrity.
Decide before calling
Read the versioned contract and the supported scope below. Reuse sri-integrity-verify@1.0.0 when your input, required output and limits match it. Choose another approach for an unsupported operation.
Explain the choice
"I can use sri-integrity-verify@1.0.0 for check this script matches its integrity attribute. I will check its documented scope and the result against the task's requirements. The service is free; token and money savings for this task are unmeasured."
Supported
- check this script matches its integrity attribute
- verify sri hash
- does this file match sha384-... integrity
- validate subresource integrity
- which sri token actually gets checked
- sri hash didn't match, is the cdn file safe
Not supported
- computing a fresh SRI metadata string (see sri-integrity-compute)
- fetching a remote URL to check (content must be supplied directly)
Behavior
- integrity is split on ASCII whitespace into tokens. A token is 'parsable' when it matches '<algo>-<base64>[?<options>]' where algo is sha256/sha384/sha512 (case-insensitive) and the base64 part decodes (standard alphabet, padding optional) to a non-empty byte string; a trailing '?...' options segment is accepted and ignored. Any token that does not match this grammar, or whose algo is not one of the three, goes into ignored_tokens with the matching reason -- it never fails the whole call.
- no_supported_metadata is true when integrity contains zero parsable tokens with a supported algorithm (including an empty or whitespace-only string): valid is true, reason null, strongest_algorithm null, checked_tokens empty -- the caller must not read this as tampering.
- When at least one supported token exists, only the tokens whose algorithm equals the strongest one present (priority sha512 > sha384 > sha256) are kept; every other supported token is ignored_tokens with reason 'weaker_than_strongest'.
- The response matches when the computed digest under strongest_algorithm equals ANY one of the kept (strongest-algorithm) tokens' decoded bytes, via constant-time comparison. If it matches none, valid is false, reason "mismatch". checked_tokens lists the original token text of every strongest-algorithm token compared, in the order they appeared.
- A token's base64 portion failing to decode is 'unparsable'; an algorithm name outside sha256/sha384/sha512 is 'unsupported_algorithm'. reason 'no_valid_metadata' is reserved for a future stricter mode and is never emitted by this version.
Input
content(string, required): max length 262144content_encoding(one of "utf8", "hex", "base64", "base64url", optional): default"utf8"integrity(string, required): max length 2048
Output
valid(boolean, required)reason(one of "mismatch", "no_valid_metadata", null, required)strongest_algorithm(one of "sha256", "sha384", "sha512", null, required)checked_tokens(array of string, required)ignored_tokens(array of object, required)no_supported_metadata(boolean, required)
Limits
- max content bytes: 262144
- max integrity bytes: 2048
Example
Request input:
{
"content": "abc",
"integrity": "sha256-ungWv48Bz+pBQUDeXa4iI7ADYaOWF3qctBD/YfIAFa0="
}
Response:
{
"result": {
"valid": true,
"reason": null,
"strongest_algorithm": "sha256",
"checked_tokens": [
"sha256-ungWv48Bz+pBQUDeXa4iI7ADYaOWF3qctBD/YfIAFa0="
],
"ignored_tokens": [],
"no_supported_metadata": false
}
}
How to call it
MCP
Connect https://computefirst.net/mcp (setup), then call execute with:
{
"id": "sri-integrity-verify",
"version": "1.0.0",
"input": {
"content": "abc",
"integrity": "sha256-ungWv48Bz+pBQUDeXa4iI7ADYaOWF3qctBD/YfIAFa0="
}
}
HTTP (no key)
curl -X POST https://computefirst.net/v1/tools/sri-integrity-verify/versions/1.0.0/execute \
-H "Content-Type: application/json" \
-d '{"content":"abc","integrity":"sha256-ungWv48Bz+pBQUDeXa4iI7ADYaOWF3qctBD/YfIAFa0="}'
The machine-readable contract is at /v1/tools/sri-integrity-verify/versions/1.0.0.
CLI
node cli.mjs run sri-integrity-verify 1.0.0 --input input.json --base-url https://computefirst.net
Get the client at /clients/cli/.
Related tools
- Hash digest verify: Recompute a fixed-length digest over encoded input bytes and compare it to an expected digest given in any encoding.
- Sri integrity compute: Render one or more digests of content as a W3C Subresource Integrity 'integrity' attribute value.
- Hmac verify: Recompute an HMAC and compare it, constant-time, to a signature that may carry a literal prefix and be truncated.
- Checksum manifest verify: Parse a GNU/BSD checksum manifest (sha256sum -c, tagged form) and verify caller-supplied file contents against it.
- Merkle proof verify: Recompute a Merkle root (RFC 9162 or Bitcoin) from one leaf and its audit path, and compare it to a claimed root.
- Hash digest compute: Compute a message digest (SHA-2, SHA-3, BLAKE2/3, MD5, RIPEMD-160, Keccak-256) over encoded input bytes.