Hashes, MAC, KDF (RFC + FIPS / SP NIST). Four families:
- SHA-2 (FIPS 180-4) —
sha224,sha256,sha384,sha512,sha512_224,sha512_256. - SHA-3 / SHAKE (FIPS 202) —
sha3(1 module exposing all 6 variants). - MAC + KDF (FIPS 198-1, SP 800-56C, SP 800-132) —
hmac,hkdf,pbkdf2. - Non-NIST (RFC interop) —
blake2b(RFC 7693),poly1305(RFC 8439),argon2(RFC 9106),adf(KeePass interop).
| Module | Returns | Deps | Description |
|---|---|---|---|
| sha224 | {fn, hash} |
sha256 |
SHA-224 (FIPS 180-4 §6.3) — sha256 wrapper |
| sha256 | {fn, hash, _internal} |
bitArray, utf8 |
SHA-256 (FIPS 180-4 §6.2) |
| sha384 | {fn, hash} |
sha512 |
SHA-384 (FIPS 180-4 §6.5) — sha512 wrapper |
| sha512 | {fn, hash, _internal} |
bitArray, utf8 |
SHA-512 (FIPS 180-4 §6.4) + parametric builder |
| sha512_224 | {fn, hash} |
sha512 |
SHA-512/224 (FIPS 180-4 §5.3.6.1) |
| sha512_256 | {fn, hash} |
sha512 |
SHA-512/256 (FIPS 180-4 §5.3.6.2) |
| sha3 | {sha3_*, shake*, sha3_*_hash} |
bitArray, utf8 |
SHA-3 + SHAKE (FIPS 202) one-shot + streaming |
| hmac | {fn, verify} |
bitArray, utf8, sha256 |
Polymorphic HMAC (RFC 2104 / FIPS 198-1) over any hash |
| hkdf | {extract, expand, derive} |
bitArray, utf8, hmac |
HKDF (RFC 5869 / SP 800-56C Rev. 2) |
| pbkdf2 | callable + .derive, .MIN_RECOMMENDED_COUNT |
bitArray, utf8, hmac |
PBKDF2 (RFC 2898 / SP 800-132), default 600,000 iter |
| blake2b | {hash, fn} |
none | BLAKE2b (RFC 7693); salt/person; keyed mode |
| poly1305 | {mac, verify} |
none | Poly1305 (RFC 8439 §2.5) — 128-bit one-shot MAC |
| argon2 | {hash, hashD, hashI, _internal} |
blake2b |
Argon2id (RFC 9106); Argon2d/i explicit reject |
| adf | {transform} |
aes, sha256 |
KeePass AES-DF (KDBX 3.x) — legacy interop |
Common pattern (one-shot)
const sha256 = fw.runtime.resolve('sha256');
const digestBa = sha256.hash('hello'); // bitArray (8 words × 32 bits)
const hex = fw.runtime.resolve('hex');
console.log(hex.fromBytes(bitArray.ba_to_ui8(digestBa)));
Streaming pattern
const sha512 = fw.runtime.resolve('sha512');
const h = new sha512.fn();
h.update(chunk1).update(chunk2);
const digestBa = h.finalize();
See also
- Mode — AEAD / encryption modes
- PKC — hash-based signatures
NIST_CONFORMANCE.md