# Sri integrity verify

`sri-integrity-verify` · version 1.0.0 · Hashing & signatures · free, no key needed

Parse an SRI integrity attribute, check content against its strongest digest, and report which tokens were used.

**Use when you need to: check this script matches its integrity attribute · verify sri hash · does this file match sha384-... integrity.**

## Decide before calling

Read the [versioned contract](/v1/tools/sri-integrity-verify/versions/1.0.0) and the supported scope below. Reuse `sri-integrity-verify@1.0.0` when your input, required output and limits match it. Choose another approach for an unsupported operation.

## Explain the choice

"I can use `sri-integrity-verify@1.0.0` for check this script matches its integrity attribute. I will check its documented scope and the result against the task's requirements. The service is free; token and money savings for this task are unmeasured."

## Supported

- check this script matches its integrity attribute
- verify sri hash
- does this file match sha384-... integrity
- validate subresource integrity
- which sri token actually gets checked
- sri hash didn't match, is the cdn file safe

## Not supported

- computing a fresh SRI metadata string (see sri-integrity-compute)
- fetching a remote URL to check (content must be supplied directly)

## Behavior

- integrity is split on ASCII whitespace into tokens. A token is 'parsable' when it matches '<algo>-<base64>[?<options>]' where algo is sha256/sha384/sha512 (case-insensitive) and the base64 part decodes (standard alphabet, padding optional) to a non-empty byte string; a trailing '?...' options segment is accepted and ignored. Any token that does not match this grammar, or whose algo is not one of the three, goes into ignored_tokens with the matching reason -- it never fails the whole call.
- no_supported_metadata is true when integrity contains zero parsable tokens with a supported algorithm (including an empty or whitespace-only string): valid is true, reason null, strongest_algorithm null, checked_tokens empty -- the caller must not read this as tampering.
- When at least one supported token exists, only the tokens whose algorithm equals the strongest one present (priority sha512 > sha384 > sha256) are kept; every other supported token is ignored_tokens with reason 'weaker_than_strongest'.
- The response matches when the computed digest under strongest_algorithm equals ANY one of the kept (strongest-algorithm) tokens' decoded bytes, via constant-time comparison. If it matches none, valid is false, reason "mismatch". checked_tokens lists the original token text of every strongest-algorithm token compared, in the order they appeared.
- A token's base64 portion failing to decode is 'unparsable'; an algorithm name outside sha256/sha384/sha512 is 'unsupported_algorithm'. reason 'no_valid_metadata' is reserved for a future stricter mode and is never emitted by this version.

## Input

- `content` (string, required): max length 262144
- `content_encoding` (one of "utf8", "hex", "base64", "base64url", optional): default `"utf8"`
- `integrity` (string, required): max length 2048

## Output

- `valid` (boolean, required)
- `reason` (one of "mismatch", "no_valid_metadata", null, required)
- `strongest_algorithm` (one of "sha256", "sha384", "sha512", null, required)
- `checked_tokens` (array of string, required)
- `ignored_tokens` (array of object, required)
- `no_supported_metadata` (boolean, required)

## Limits

- max content bytes: 262144
- max integrity bytes: 2048

## Example

Request input:

```json
{
  "content": "abc",
  "integrity": "sha256-ungWv48Bz+pBQUDeXa4iI7ADYaOWF3qctBD/YfIAFa0="
}
```

Response:

```json
{
  "result": {
    "valid": true,
    "reason": null,
    "strongest_algorithm": "sha256",
    "checked_tokens": [
      "sha256-ungWv48Bz+pBQUDeXa4iI7ADYaOWF3qctBD/YfIAFa0="
    ],
    "ignored_tokens": [],
    "no_supported_metadata": false
  }
}
```

## How to call it

### MCP

Connect `https://computefirst.net/mcp` ([setup](/docs#connect)), then call `execute` with:

```json
{
  "id": "sri-integrity-verify",
  "version": "1.0.0",
  "input": {
    "content": "abc",
    "integrity": "sha256-ungWv48Bz+pBQUDeXa4iI7ADYaOWF3qctBD/YfIAFa0="
  }
}
```

### HTTP (no key)

```sh
curl -X POST https://computefirst.net/v1/tools/sri-integrity-verify/versions/1.0.0/execute \
  -H "Content-Type: application/json" \
  -d '{"content":"abc","integrity":"sha256-ungWv48Bz+pBQUDeXa4iI7ADYaOWF3qctBD/YfIAFa0="}'
```

The machine-readable contract is at [/v1/tools/sri-integrity-verify/versions/1.0.0](/v1/tools/sri-integrity-verify/versions/1.0.0).

### CLI

```sh
node cli.mjs run sri-integrity-verify 1.0.0 --input input.json --base-url https://computefirst.net
```

Get the client at [/clients/cli/](/clients/cli/).

## Related tools

- [Hash digest verify](/tools/hash-digest-verify): Recompute a fixed-length digest over encoded input bytes and compare it to an expected digest given in any encoding.
- [Sri integrity compute](/tools/sri-integrity-compute): Render one or more digests of content as a W3C Subresource Integrity 'integrity' attribute value.
- [Hmac verify](/tools/hmac-verify): Recompute an HMAC and compare it, constant-time, to a signature that may carry a literal prefix and be truncated.
- [Checksum manifest verify](/tools/checksum-manifest-verify): Parse a GNU/BSD checksum manifest (sha256sum -c, tagged form) and verify caller-supplied file contents against it.
- [Merkle proof verify](/tools/merkle-proof-verify): Recompute a Merkle root (RFC 9162 or Bitcoin) from one leaf and its audit path, and compare it to a claimed root.
- [Hash digest compute](/tools/hash-digest-compute): Compute a message digest (SHA-2, SHA-3, BLAKE2/3, MD5, RIPEMD-160, Keccak-256) over encoded input bytes.
