{"id":"sri-integrity-verify","version":"1.0.0","description":"Parse an SRI integrity attribute, check content against its strongest digest, and report which tokens were used.","supported_operations":["check this script matches its integrity attribute","verify sri hash","does this file match sha384-... integrity","validate subresource integrity","which sri token actually gets checked","sri hash didn't match, is the cdn file safe"],"unsupported_operations":["computing a fresh SRI metadata string (see sri-integrity-compute)","fetching a remote URL to check (content must be supplied directly)"],"semantics":["integrity is split on ASCII whitespace into tokens. A token is 'parsable' when it matches '<algo>-<base64>[?<options>]' where algo is sha256/sha384/sha512 (case-insensitive) and the base64 part decodes (standard alphabet, padding optional) to a non-empty byte string; a trailing '?...' options segment is accepted and ignored. Any token that does not match this grammar, or whose algo is not one of the three, goes into ignored_tokens with the matching reason -- it never fails the whole call.","no_supported_metadata is true when integrity contains zero parsable tokens with a supported algorithm (including an empty or whitespace-only string): valid is true, reason null, strongest_algorithm null, checked_tokens empty -- the caller must not read this as tampering.","When at least one supported token exists, only the tokens whose algorithm equals the strongest one present (priority sha512 > sha384 > sha256) are kept; every other supported token is ignored_tokens with reason 'weaker_than_strongest'.","The response matches when the computed digest under strongest_algorithm equals ANY one of the kept (strongest-algorithm) tokens' decoded bytes, via constant-time comparison. If it matches none, valid is false, reason \"mismatch\". checked_tokens lists the original token text of every strongest-algorithm token compared, in the order they appeared.","A token's base64 portion failing to decode is 'unparsable'; an algorithm name outside sha256/sha384/sha512 is 'unsupported_algorithm'. reason 'no_valid_metadata' is reserved for a future stricter mode and is never emitted by this version."],"limits":{"max_content_bytes":262144,"max_integrity_bytes":2048},"pricing":{"status":"unpriced","charge_usd":null},"input_schema":{"type":"object","additionalProperties":false,"required":["content","integrity"],"properties":{"content":{"type":"string","maxLength":262144},"content_encoding":{"type":"string","enum":["utf8","hex","base64","base64url"],"default":"utf8"},"integrity":{"type":"string","maxLength":2048}}},"output_schema":{"type":"object","additionalProperties":false,"required":["valid","reason","strongest_algorithm","checked_tokens","ignored_tokens","no_supported_metadata"],"properties":{"valid":{"type":"boolean"},"reason":{"type":["string","null"],"enum":["mismatch","no_valid_metadata",null]},"strongest_algorithm":{"type":["string","null"],"enum":["sha256","sha384","sha512",null]},"checked_tokens":{"type":"array","items":{"type":"string"}},"ignored_tokens":{"type":"array","items":{"type":"object","additionalProperties":false,"required":["token","reason"],"properties":{"token":{"type":"string"},"reason":{"type":"string","enum":["unsupported_algorithm","weaker_than_strongest","unparsable"]}}}},"no_supported_metadata":{"type":"boolean"}}},"examples":[{"input":{"content":"abc","integrity":"sha256-ungWv48Bz+pBQUDeXa4iI7ADYaOWF3qctBD/YfIAFa0="},"output":{"valid":true,"reason":null,"strongest_algorithm":"sha256","checked_tokens":["sha256-ungWv48Bz+pBQUDeXa4iI7ADYaOWF3qctBD/YfIAFa0="],"ignored_tokens":[],"no_supported_metadata":false}},{"input":{"content":"anything at all","integrity":""},"output":{"valid":true,"reason":null,"strongest_algorithm":null,"checked_tokens":[],"ignored_tokens":[],"no_supported_metadata":true}}],"execute_url":"/v1/tools/sri-integrity-verify/versions/1.0.0/execute"}