KMAC256
Compute a KMAC256 tag over a message with a secret key.
Calculate KMAC256 (NIST SP 800-185) message authentication codes. Arbitrary output length, optional domain separation. Free, offline, runs client-side. Read more Show less
What is KMAC256?
KMAC256 is a keyed message authentication code built on cSHAKE256, defined in NIST SP 800-185. It takes a secret key and a message and produces a tag that proves the message was produced by someone who holds the key, and that it has not been modified in transit.
KMAC is the NIST-recommended replacement for HMAC when you want the flexibility of a SHA-3-based construction, or when you need output longer than the underlying hash function can produce. It is used in modern protocols including some post-quantum signature schemes and hardware security modules.
How to use
Enter the message, enter the key, choose the output length in bits, and press Hash. The output is the KMAC tag.
The key can be any length. NIST recommends at least 128 bits of entropy for KMAC128 and 256 bits for KMAC256. Generate a random key with the Random Bytes tool if you do not have one.
To verify a tag, compute the KMAC on the same message with the same key and compare the results. KMAC has no separate verify operation.
Customization
KMAC accepts an optional customization string (S). Like the function name in cSHAKE, this provides domain separation. Use it to distinguish multiple uses of the same key - for example, "session-token" vs "api-signature". Two KMAC instances with different customization strings produce unrelated tags even with the same key and message.
KMAC vs HMAC
HMAC is built on a Merkle-Damgard hash (SHA-1, SHA-2) and works by hashing the key twice. KMAC is built on cSHAKE, which is a sponge construction, and uses the key as part of the sponge input. Both are secure. KMAC has two practical advantages:
Arbitrary output length. HMAC-SHA-256 always produces 256 bits. KMAC can produce 128, 256, 512, or any other multiple of 8.
Domain separation built in. HMAC has no equivalent to the customization string. KMAC makes it trivial to reuse a key safely across multiple contexts.
FAQ
Is KMAC secure?
Yes. KMAC128 provides 128-bit security and KMAC256 provides 256-bit, provided the key has sufficient entropy. No practical attacks are known against the full construction.
KMAC vs KMACXOF
The non-XOF version produces a fixed-length tag and is the right choice for authentication. KMACXOF can produce any length and is used when you need output longer than a typical MAC, or when the tag is used as a KDF output. This tool implements the fixed-length version.
Can I use KMAC for password hashing?
No. KMAC is fast. For password hashing, use Argon2id, scrypt, or bcrypt.
What key size should I use?
At least 128 bits (16 bytes) for KMAC128 and 256 bits (32 bytes) for KMAC256. Larger keys do not add security beyond this point but do not hurt.
Why does the output not match HMAC-SHA-256?
KMAC and HMAC are different algorithms. They use different underlying primitives (cSHAKE vs SHA-2) and different constructions. The output is intentionally different.
Can I use the same key for KMAC128 and KMAC256?
Not recommended. Use independent keys for each variant. If you must share, use different customization strings.
Command line equivalent
# Python with pycryptodome
pip install pycryptodome
python3 -c '
from Crypto.Hash import KMAC256
h = KMAC256.new(key=b"key", data=b"message", mac_len=32, custom=b"")
print(h.hexdigest())
'
# Node with hash-wasm
npm i hash-wasm
node --input-type=module -e '
import { kmac256 } from "hash-wasm";
const tag = await kmac256(new TextEncoder().encode("key"), new TextEncoder().encode("message"), 256, "");
console.log(tag);
'