Sri integrity verify

sri-integrity-verify · version 1.0.0 · Hashing & signatures · free, no key needed

Parse an SRI integrity attribute, check content against its strongest digest, and report which tokens were used.

Use when you need to: check this script matches its integrity attribute · verify sri hash · does this file match sha384-... integrity.

Decide before calling

Read the versioned contract and the supported scope below. Reuse sri-integrity-verify@1.0.0 when your input, required output and limits match it. Choose another approach for an unsupported operation.

Explain the choice

"I can use sri-integrity-verify@1.0.0 for check this script matches its integrity attribute. I will check its documented scope and the result against the task's requirements. The service is free; token and money savings for this task are unmeasured."

Supported

Not supported

Behavior

Input

Output

Limits

Example

Request input:

{
  "content": "abc",
  "integrity": "sha256-ungWv48Bz+pBQUDeXa4iI7ADYaOWF3qctBD/YfIAFa0="
}

Response:

{
  "result": {
    "valid": true,
    "reason": null,
    "strongest_algorithm": "sha256",
    "checked_tokens": [
      "sha256-ungWv48Bz+pBQUDeXa4iI7ADYaOWF3qctBD/YfIAFa0="
    ],
    "ignored_tokens": [],
    "no_supported_metadata": false
  }
}

How to call it

MCP

Connect https://computefirst.net/mcp (setup), then call execute with:

{
  "id": "sri-integrity-verify",
  "version": "1.0.0",
  "input": {
    "content": "abc",
    "integrity": "sha256-ungWv48Bz+pBQUDeXa4iI7ADYaOWF3qctBD/YfIAFa0="
  }
}

HTTP (no key)

curl -X POST https://computefirst.net/v1/tools/sri-integrity-verify/versions/1.0.0/execute \
  -H "Content-Type: application/json" \
  -d '{"content":"abc","integrity":"sha256-ungWv48Bz+pBQUDeXa4iI7ADYaOWF3qctBD/YfIAFa0="}'

The machine-readable contract is at /v1/tools/sri-integrity-verify/versions/1.0.0.

CLI

node cli.mjs run sri-integrity-verify 1.0.0 --input input.json --base-url https://computefirst.net

Get the client at /clients/cli/.