Tooleux

ParallelHashXOF256

ParallelHash (4)

Compute a ParallelHashXOF256 (tree-based) hash of any input, at any output length.

Runs in your browser. Nothing leaves your device.
Calculate ParallelHashXOF256 (NIST SP 800-185) tree-based hash at any output length. Free, offline, runs client-side. Read more Show less

What is ParallelHashXOF256?

ParallelHashXOF256 is the extendable-output, 256-bit-security variant of ParallelHash (NIST SP 800-185). It hashes a message by splitting it into fixed-size blocks, hashing each block independently, then combining the block hashes with cSHAKE - at any output length the caller requests.

Because blocks are independent, they can be processed by multiple CPU cores - which is what makes ParallelHash useful for very large inputs. For small inputs the tree overhead makes it slightly slower than plain cSHAKE; use cSHAKE256 if you only need domain separation.

How to use

Type or paste the input. Choose the output length in bits. Optionally provide a customization string.

The tool uses the NIST default block size (136 bytes for the 256 variant), which matches the reference configuration and interops with pycryptodome and @noble/hashes.

ParallelHash256 vs ParallelHashXOF256

The two tools produce different outputs for the same input, because the SP 800-185 length encoding differs. Use ParallelHash256 for fixed-length digests. Use ParallelHashXOF256 when the digest length is decided at runtime, or when the output feeds a KDF.

FAQ

Is ParallelHashXOF256 deterministic?

Yes, provided the block size is the same. Same input, same block size, same customization string, same output length - same output.

ParallelHashXOF128 vs ParallelHashXOF256?

Same construction, different underlying cSHAKE width. The 128 variant gives 128-bit security; the 256 variant gives 256-bit. See ParallelHashXOF128.

Can I change the block size?

Not in this tool - it uses the NIST default. For custom block sizes, use a native library that exposes the parameter.

Is ParallelHashXOF256 a MAC?

No. It is unkeyed. For keyed authentication, use KMACXOF256.

Command line equivalent
# Node with @noble/hashes
npm i @noble/hashes
node --input-type=module -e '
import { parallelhash256xof } from "@noble/hashes/sha3-addons";
const out = parallelhash256xof(new TextEncoder().encode("abc"), { dkLen: 64 });
console.log(Buffer.from(out).toString("hex"));
'
Loads a test value into the form
Input
ParallelHashXOF256