cryptoAuth Compute a tag for the provided message and key.
See: crypto_auth()
:: a typeCtrl KGHC 9.10.3 · lts/ghc-9.10.x · c74966e · 2026-09-27
Modulelibsodium-bindings-0.0.1.1Haskell2010
Compute an authentication tag for a message and a secret key, and verify that a given tag is valid for a given message and a key.
The function computing the tag is deterministic: the same (message, key) tuple will always produce the same output. However, even if the message is public, knowing the key is required in order to be able to compute a valid tag. Therefore, the key should remain confidential. The tag, however, can be public.
The operations of this module are backed by the HMAC-SHA512-256 algorithm.
A typical use case is:
A prepares a message, adds an authentication tag, sends it to B
A doesn't store the message
Later on, B sends the message and the authentication tag to A
A uses the authentication tag to verify that it created this message.
This operation does not encrypt the message. It only computes and verifies an authentication tag.
cryptoAuth Compute a tag for the provided message and key.
See: crypto_auth()
cryptoAuthVerify Verify that the tag is valid for the provided message and secret key.
See: crypto_auth_verify()
cryptoAuthKeygen :: Ptr CUCharBuffer that holds the secret key of size cryptoAuthKeyBytes
-> IO ()Create a random secret key of size cryptoAuthKeyBytes
It is equivalent to calling randombytesBuf but improves code clarity and can prevent misuse by ensuring that the provided key length is always be correct.
See: crypto_auth_keygen()
Size of the secret key
See: crypto_auth_KEYBYTES
Size of the tag
See: crypto_auth_BYTES