Shake-256 Hash Generator
Generate variable-length SHAKE256 (SHA-3 XOF) hashes.
SHAKE256
Result will appear here...
SHAKE256 Hash Generator
Generate a SHAKE256 hash of any output length from text or a file. SHAKE256 is the higher-security extendable-output function (XOF) of the SHA-3 standard: pick the number of bits and the tool squeezes exactly that much output from the Keccak sponge, entirely in your browser.
About SHAKE256
SHAKE256 is specified in NIST FIPS 202 next to SHA-3 and SHAKE128. It offers 256-bit security and produces output of any requested length, making it a flexible building block for key derivation, deterministic randomness, and padding. Because it uses a smaller sponge rate than SHAKE128, it trades a little speed for a stronger security margin.
For example, SHAKE256("abc", 64 bits) = 483366601360a877.
Features
- Custom output length from 8 to 8192 bits, in 8-bit steps
- Text or file input, hashed locally up to 200 MB
- Hex, uppercase, or Base64 output
- Compare with a known hash
Where SHAKE256 is used
SHAKE256 underpins several post-quantum cryptography standards, including SLH-DSA (SPHINCS+) and ML-DSA (Dilithium), and it powers Ed448 signatures. For a fixed-length digest use the SHA3-512 Hash Generator; for the faster 128-bit-security XOF see the SHAKE128 Hash Generator.
Frequently Asked Questions
How is SHAKE256 different from SHAKE128?
SHAKE256 targets 256-bit security instead of 128-bit. It uses a smaller sponge rate, so it is slightly slower, but it is the right choice when you need a stronger security margin, especially for long outputs.
Does the output length change the security?
SHAKE256 provides up to 256-bit security. Requesting a longer output does not add security beyond that ceiling, and requesting a very short output limits it to roughly half the output length against collisions.
What uses SHAKE256?
SHAKE256 appears in post-quantum signature schemes such as SLH-DSA (SPHINCS+) and ML-DSA, in EdDSA variants like Ed448, and anywhere a high-security variable-length hash or key-derivation stream is required.
Can SHAKE256 replace SHA3-512?
For a fixed 512-bit digest, SHA3-512 is the standard choice. SHAKE256 set to 512 bits is a XOF with different padding, so it will not match a SHA3-512 value even at the same length.