KMACXOF256
Compute a KMACXOF256 tag over a message with a secret key, at any output length.
Calculate KMACXOF256 (NIST SP 800-185) message authentication codes at any output length. Free, offline, runs client-side. Read more Show less
What is KMACXOF256?
KMACXOF256 is the extendable-output (XOF) variant of KMAC256, defined in NIST SP 800-185. It produces a 256-bit-security keyed message authentication code from a secret key and a message, at any output length the caller requests.
KMAC256 bakes a fixed output length into the encoding. KMACXOF256 uses the XOF form, which encodes the output length as zero and lets the caller truncate or extend the result freely without breaking the security proof. Same primitive, different length handling.
How to use
Enter the message, enter the key, choose the output length in bits, and press Hash. The output is the KMACXOF256 tag.
The key can be any length. NIST recommends at least 256 bits of entropy for the 256-bit variant. Generate a random key with the Random Bytes tool if you do not have one.
To verify a tag, compute the KMACXOF256 on the same message with the same key and compare. As with KMAC, there is no separate verify operation.
Customization
KMACXOF256 accepts an optional customization string (S). Like the function name in cSHAKE, this provides domain separation. Two KMACXOF256 instances with different customization strings produce unrelated tags even with the same key and message.
KMAC256 vs KMACXOF256
The two tools produce different outputs for the same inputs, because the length encoding differs. Choose based on use:
KMAC256 is the correct choice for authentication tags with a known, fixed length - for example, a 512-bit MAC that a peer protocol expects to find at a fixed offset. Interoperates with the widest range of libraries.
KMACXOF256 is the correct choice when the output length is decided at runtime, or when the output is being used as a key derivation output rather than a fixed-size tag. It is also the right mode when you may want to truncate the output later.
The underlying cryptographic strength is identical.
FAQ
Is KMACXOF256 secure?
Yes. KMACXOF256 provides 256-bit security, the same as KMAC256. No practical attacks are known against the full construction.
Is KMACXOF256 deterministic?
Yes. Same key, same message, same customization string, same output length - same output. It is not randomized.
Why does the output not match KMAC256 at the same length?
Because the SP 800-185 encoding differs. KMAC256 encodes the output length L; KMACXOF256 encodes zero. This changes the sponge input and therefore the output, even for the same key and message. Both are correct; they are intentionally distinct modes.
KMACXOF128 vs KMACXOF256?
Same construction, different underlying cSHAKE width and different security level. KMACXOF128 provides 128-bit security; KMACXOF256 provides 256-bit. Use the 256 variant when 128-bit security is not enough - for example, for long-lived keys or high-value authentication. See KMACXOF128.
What output length should I choose?
Match your downstream consumer. 512 bits (64 bytes) is a common default for the 256 variant. Longer output is not stronger - the security level is fixed by the variant, not by output length.
Can I use KMACXOF256 for password hashing?
No. It is fast. For password hashing, use Argon2id, scrypt, or bcrypt.
Command line equivalent
# Node with @noble/hashes (same library this tool uses)
npm i @noble/hashes
node --input-type=module -e '
import { kmac256xof } from "@noble/hashes/sha3-addons";
import { utf8ToBytes, bytesToHex } from "@noble/hashes/utils";
const key = utf8ToBytes("key");
const msg = utf8ToBytes("message");
const tag = kmac256xof(key, msg, { personalization: "", dkLen: 64 });
console.log(bytesToHex(tag));
'