Tooleux

Compute a KMACXOF128 tag over a message with a secret key, at any output length.

Runs in your browser. Nothing leaves your device.
Calculate KMACXOF128 (NIST SP 800-185) message authentication codes at any output length. Free, offline, runs client-side. Read more Show less

What is KMACXOF128?

KMACXOF128 is the extendable-output (XOF) variant of KMAC128, defined in NIST SP 800-185. It produces a keyed message authentication code from a secret key and a message, at any output length the caller requests.

KMAC128 bakes a fixed output length into the encoding. KMACXOF128 uses the XOF form, which encodes the output length as zero and lets the caller truncate or extend the result freely without breaking the security proof. Same primitive, different length handling.

How to use

Enter the message, enter the key, choose the output length in bits, and press Hash. The output is the KMACXOF128 tag.

The key can be any length. NIST recommends at least 128 bits of entropy for the 128-bit variant. Generate a random key with the Random Bytes tool if you do not have one.

To verify a tag, compute the KMACXOF128 on the same message with the same key and compare. As with KMAC, there is no separate verify operation.

Customization

KMACXOF128 accepts an optional customization string (S). Like the function name in cSHAKE, this provides domain separation. Two KMACXOF128 instances with different customization strings produce unrelated tags even with the same key and message.

KMAC128 vs KMACXOF128

The two tools produce different outputs for the same inputs, because the length encoding differs. Choose based on use:

KMAC128 is the correct choice for authentication tags with a known, fixed length - for example, a 256-bit MAC that a peer protocol expects to find at a fixed offset. Interoperates with the widest range of libraries.

KMACXOF128 is the correct choice when the output length is decided at runtime, or when the output is being used as a key derivation output (stream cipher key, expansion seed) rather than a fixed-size tag. It is also the right mode when you may want to truncate the output later - for example, compute 512 bits now and slice 256 bits off for a shorter application.

The underlying cryptographic strength is identical.

FAQ

Is KMACXOF128 secure?

Yes. KMACXOF128 provides 128-bit security, the same as KMAC128. No practical attacks are known against the full construction.

Is KMACXOF128 deterministic?

Yes. Same key, same message, same customization string, same output length - same output. It is not randomized.

Why does the output not match KMAC128 at the same length?

Because the SP 800-185 encoding differs. KMAC128 encodes the output length L; KMACXOF128 encodes zero. This changes the sponge input and therefore the output, even for the same key and message. Both are correct; they are intentionally distinct modes.

What output length should I choose?

Match your downstream consumer. 256 bits (32 bytes) is a common default. If the tag feeds a key derivation, 256 or 512 bits is fine. Longer output is not stronger - the security level is fixed by the 128-bit variant, not by output length.

Can I use KMACXOF128 for password hashing?

No. It is fast. For password hashing, use Argon2id, scrypt, or bcrypt.

When should I use the 256-bit variant?

When you need 256-bit security instead of 128-bit. Otherwise the API and behavior are identical. See KMACXOF256.

Command line equivalent
# Node with @noble/hashes (same library this tool uses)
npm i @noble/hashes
node --input-type=module -e '
import { kmac128xof } from "@noble/hashes/sha3-addons";
import { utf8ToBytes, bytesToHex } from "@noble/hashes/utils";
const key = utf8ToBytes("key");
const msg = utf8ToBytes("message");
const tag = kmac128xof(key, msg, { personalization: "", dkLen: 32 });
console.log(bytesToHex(tag));
'

# Python with pycryptodome (uses the non-XOF KMAC128; not XOF-compatible)
# There is no widely-available CLI for KMACXOF128.
Loads a test value into the form
Message
KMACXOF128 output