Shake-128 Hash Generator
Generate variable-length SHAKE128 (SHA-3 XOF) hashes.
SHAKE128
Result will appear here...
SHAKE128 Hash Generator
Generate a SHAKE128 hash of any length from text or a file. SHAKE128 is an extendable-output function (XOF) from the SHA-3 standard: set the output length in bits and the tool squeezes exactly that many bits out of the Keccak sponge, all in your browser.
About SHAKE128
SHAKE128 is defined alongside SHA-3 in NIST FIPS 202. The name combines Secure Hash Algorithm and Keccak. Unlike a fixed-length hash, a XOF can produce output of any size, which makes it ideal wherever you need a pseudo-random stream derived from some input. SHAKE128 offers 128-bit security and uses a larger sponge rate than SHAKE256, so it runs faster when the extra margin is not needed.
For example, SHAKE128("", 256 bits) = 7f9c2ba4e88f827d616045507605853ed73b8093f6efbc88eb1a6eacfa66ef26.
Features
- Custom output length from 8 to 8192 bits, in 8-bit steps
- Text or file input, hashed locally
- Hex, uppercase, or Base64 output
- Compare with a known hash for verification
Where SHAKE128 is used
SHAKE functions are central to modern cryptography: they generate masks in RSA padding, derive keys, and power the post-quantum standards ML-KEM (Kyber) and ML-DSA (Dilithium). For a fixed-length SHA-3 digest instead, use the SHA3-256 Hash Generator; for a wider security margin see the SHAKE256 Hash Generator.
Frequently Asked Questions
What is an extendable-output function (XOF)?
A XOF is a hash whose output length you choose. Instead of a fixed digest, SHAKE128 can squeeze out as many bytes as you ask for — 16, 32, 64, or thousands — all from the same internal state.
What does the 128 in SHAKE128 mean?
It is the security strength, not the output length. SHAKE128 targets 128-bit security against collisions and preimages regardless of how long an output you request, though very short outputs naturally limit the effective security.
When would I use SHAKE128?
When you need a hash of a specific, non-standard length: key derivation, mask generation in RSA-PSS/OAEP, deterministic random bytes, or post-quantum schemes such as ML-KEM and ML-DSA that rely on SHAKE internally.
Is SHAKE128 the same as SHA3-256?
They share the Keccak permutation but use different padding and rate. SHAKE128 has a larger rate (faster) and variable output, while SHA3-256 has a fixed 256-bit output. Their results are not interchangeable.