cSHAKE128
Compute cSHAKE128 at any output length, with optional function name and customization.
Calculate cSHAKE128 (NIST SP 800-185) hashes at any output length. Customizable with function name and domain separation. Free, offline, runs client-side. Read more Show less
What is cSHAKE128?
cSHAKE128 is the customizable version of SHAKE128, defined in NIST SP 800-185. It extends SHAKE with two optional parameters: a function name (N) and a customization string (S). Both affect the output, letting you derive distinct hash functions from the same primitive.
cSHAKE is the foundation of the KMAC, TupleHash, and ParallelHash constructions. It is used in modern protocols that need domain separation, where the same algorithm must produce different outputs for different purposes.
How to use
Type or paste your input. Choose the output length in bits. Optionally provide a function name and customization string.
If both the function name and customization are empty, cSHAKE128 is identical to SHAKE128. That is a useful sanity check - the tool's default output should match the SHAKE128 tool byte-for-byte.
For example, cSHAKE128 with empty parameters over the UTF-8 string abc at 256 bits produces:
5881092dd818bf5cf8a3ddb793fbcba74097d5c526a6d35f97b83351940f2cc8
The two parameters
Function name (N) - identifies the higher-level function that is using cSHAKE. Standardized values exist for KMAC (KMAC), TupleHash (TupleHash), and ParallelHash (ParallelHash). For custom applications, use a unique string that names your use case.
Customization string (S) - an application-specific domain separator. Two different customization strings produce completely unrelated outputs from the same input. This is what lets you reuse cSHAKE for multiple purposes without cross-protocol attacks.
Both parameters are optional. If both are empty, cSHAKE reduces to SHAKE.
Output length is arbitrary
Like all extendable-output functions (XOFs), cSHAKE can produce any number of bits. The tool lets you choose any multiple of 8 between 8 and 4096 bits. There is no "canonical" length - you pick based on your use case.
FAQ
cSHAKE vs SHAKE
cSHAKE is SHAKE plus two domain-separation parameters. With empty N and S, they are the same function. With non-empty parameters, cSHAKE is a different function entirely - SHAKE does not have these knobs.
Is cSHAKE a MAC?
No. cSHAKE is unkeyed. For a keyed MAC built on cSHAKE, use KMAC.
What should I put in the function name?
Either a standardized string (KMAC, TupleHash, ParallelHash) if you are implementing one of those constructions, or a unique application-specific name. Never leave it empty unless you want SHAKE behavior - the point of cSHAKE is the domain separation.
What is the customization string for?
Long-lived domain separation. Use it to distinguish multiple uses of the same function name: for example, "user-signing" vs "server-signing". Two cSHAKE instances with different customization strings produce statistically independent outputs.
Is cSHAKE secure?
Yes. It is built on the same Keccak sponge as SHA-3 and inherits its security properties. The 128-bit variant provides 128-bit security, the 256-bit variant 256-bit.
Command line equivalent
# Python with pycryptodome
pip install pycryptodome
python3 -c '
from Crypto.Hash import cSHAKE128
h = cSHAKE128.new(data=b"abc", custom=b"")
print(h.read(32).hex())
'
# OpenSSL 3.x - no cSHAKE command-line tool; use a scripting language
# Node with hash-wasm
npm i hash-wasm
node --input-type=module -e '
import { cshake128 } from "hash-wasm";
const hash = await cshake128(new TextEncoder().encode("abc"), 256, "", "");
console.log(hash);
'