Tooleux

Compute cSHAKE256 at any output length, with optional function name and customization.

Runs in your browser. Nothing leaves your device.
Calculate cSHAKE256 (NIST SP 800-185) hashes at any output length. Customizable with function name and domain separation. Free, offline, runs client-side. Read more Show less

What is cSHAKE256?

cSHAKE256 is the customizable version of SHAKE256, defined in NIST SP 800-185. It extends SHAKE with two optional parameters: a function name (N) and a customization string (S). Both affect the output, letting you derive distinct hash functions from the same primitive.

cSHAKE is the foundation of the KMAC, TupleHash, and ParallelHash constructions. It is used in modern protocols that need domain separation, where the same algorithm must produce different outputs for different purposes.

How to use

Type or paste your input. Choose the output length in bits. Optionally provide a function name and customization string.

If both the function name and customization are empty, cSHAKE256 is identical to SHAKE256. That is a useful sanity check - the tool's default output should match the SHAKE256 tool byte-for-byte.

For example, cSHAKE256 with empty parameters over the UTF-8 string abc at 512 bits produces:

483366601360a8771c6863080cc4114d8db44530f8f1e1ee4f94ea37e78b5739d5a15bef186a5386c75744c0527e1faa9f8726e462a12a4feb06bd8801e751e4

The two parameters

Function name (N) - identifies the higher-level function that is using cSHAKE. Standardized values exist for KMAC (KMAC), TupleHash (TupleHash), and ParallelHash (ParallelHash). For custom applications, use a unique string that names your use case.

Customization string (S) - an application-specific domain separator. Two different customization strings produce completely unrelated outputs from the same input. This is what lets you reuse cSHAKE for multiple purposes without cross-protocol attacks.

Both parameters are optional. If both are empty, cSHAKE reduces to SHAKE.

Output length is arbitrary

Like all extendable-output functions (XOFs), cSHAKE can produce any number of bits. The tool lets you choose any multiple of 8 between 8 and 4096 bits. There is no "canonical" length - you pick based on your use case.

FAQ

cSHAKE vs SHAKE

cSHAKE is SHAKE plus two domain-separation parameters. With empty N and S, they are the same function. With non-empty parameters, cSHAKE is a different function entirely - SHAKE does not have these knobs.

Is cSHAKE a MAC?

No. cSHAKE is unkeyed. For a keyed MAC built on cSHAKE, use KMAC.

What should I put in the function name?

Either a standardized string (KMAC, TupleHash, ParallelHash) if you are implementing one of those constructions, or a unique application-specific name. Never leave it empty unless you want SHAKE behavior - the point of cSHAKE is the domain separation.

What is the customization string for?

Long-lived domain separation. Use it to distinguish multiple uses of the same function name: for example, "user-signing" vs "server-signing". Two cSHAKE instances with different customization strings produce statistically independent outputs.

Is cSHAKE secure?

Yes. It is built on the same Keccak sponge as SHA-3 and inherits its security properties. The 128-bit variant provides 128-bit security, the 256-bit variant 256-bit.

Command line equivalent
# Python with pycryptodome
pip install pycryptodome
python3 -c '
from Crypto.Hash import cSHAKE256
h = cSHAKE256.new(data=b"abc", custom=b"")
print(h.read(64).hex())
'

# OpenSSL 3.x - no cSHAKE command-line tool; use a scripting language

# Node with hash-wasm
npm i hash-wasm
node --input-type=module -e '
import { cshake256 } from "hash-wasm";
const hash = await cshake256(new TextEncoder().encode("abc"), 512, "", "");
console.log(hash);
'
Loads a test value into the form
Input
cSHAKE256