Tooleux

ParallelHashXOF128

ParallelHash (4)

Compute a ParallelHashXOF128 (tree-based) hash of any input, at any output length.

Runs in your browser. Nothing leaves your device.
Calculate ParallelHashXOF128 (NIST SP 800-185) tree-based hash at any output length. Free, offline, runs client-side. Read more Show less

What is ParallelHashXOF128?

ParallelHashXOF128 is the extendable-output variant of ParallelHash128 (NIST SP 800-185). It hashes a message by splitting it into fixed-size blocks, hashing each block independently, then combining the block hashes with cSHAKE - at any output length the caller requests.

Because blocks are independent, they can be processed by multiple CPU cores. This is what makes ParallelHash interesting for very large inputs (terabytes). For small inputs the tree overhead makes it slightly slower than plain cSHAKE; use cSHAKE128 if you only need domain separation.

How to use

Type or paste the input. Choose the output length in bits. Optionally provide a customization string.

The tool uses the NIST default block size (168 bytes for the 128 variant), which matches the reference configuration and interops with pycryptodome and @noble/hashes.

ParallelHash128 vs ParallelHashXOF128

The two tools produce different outputs for the same input, because the SP 800-185 length encoding differs. Use ParallelHash128 for fixed-length digests. Use ParallelHashXOF128 when the digest length is decided at runtime, or when the output feeds a KDF.

FAQ

Is ParallelHashXOF128 deterministic?

Yes, provided the block size is the same. Same input, same block size, same customization string, same output length - same output.

ParallelHashXOF128 vs ParallelHashXOF256?

Same construction, different underlying cSHAKE width. The 128 variant gives 128-bit security; the 256 variant gives 256-bit. See ParallelHashXOF256.

Can I change the block size?

Not in this tool - it uses the NIST default to match the standard configuration. For custom block sizes, use a native library that exposes the parameter.

Is ParallelHashXOF128 a MAC?

No. It is unkeyed. For keyed authentication, use KMACXOF128.

Command line equivalent
# Node with @noble/hashes
npm i @noble/hashes
node --input-type=module -e '
import { parallelhash128xof } from "@noble/hashes/sha3-addons";
const out = parallelhash128xof(new TextEncoder().encode("abc"), { dkLen: 32 });
console.log(Buffer.from(out).toString("hex"));
'
Loads a test value into the form
Input
ParallelHashXOF128