Algorithms

SHA-224

SHA-256 with its own start values and the last four bytes cut off. With HMAC and 112-bit security
IDsha22404 / 38SHA · 224-bit
Hash / Cryptographic

SHA-224

SHA-256 with other start values, cut to 28 bytes.

Digest
224-bit · 28 bytes
HMAC
takes a key
Security
112-bit collision resistance
Family
12 in SHA
4 options, 0 required

Sample

hex
2f05477fc24bb4faefd86517156dafdecec45b8ad3cf2522a563582b
base64
LwVHf8JLtPrv2GUXFW2v3s7EW4rTzyUipWNYKw==

Options

encodingstring
default hex
Output encoding: hex, base64, base64url, binary
keystring
optional
HMAC key; enables HMAC mode
roundsnumber
default 1
How many times to hash, each round hashing the previous digest
chainstring
default bytes
What each round after the first hashes: bytes of the digest, or its lowercase hex

Access

Createcreate("sha224")
CLIhashes sha224 'hello world'
Tryplayground with the sample above
Kinsha256, sha384, sha512, sha512-224 +7

SHA-256 on a diet. Same rounds, same constants, other initial values, and the digest stops at 28 bytes. NIST added it in 2004 to match 112-bit security, the level of P-224 and three-key Triple DES.

ts
create("sha224").hash("abc").digest;
// "23097d223405d8228642a477bda255b32aadbce4bda0b3f7e36c9da7"

So is it the first 28 bytes of SHA-256? No. SHA-256 of abc starts with ba7816bf, this one with 23097d22. The start values change every byte.

It costs exactly as much as SHA-256 and gives you less. That's fine when a spec asks for it, and odd anywhere else. Want 28 bytes on a 64-bit machine? SHA-512/224 gets there faster.