API Reference › Crypto › Crypto.ct_equal
method

Crypto.ct_equal

Crypto.ct_equal(a, b) -> bool

Compares two strings for equality without short-circuiting: every character is examined even once a difference is found, so the time taken does not reveal where — or whether — the strings first diverged. Reach for it whenever you compare a secret, token, or MAC that an attacker might be probing. For the common case of checking a message tag, Crypto.verify_hmac already does this for you; use ct_equal directly when you hold both values yourself. Strings of different length return false at once (length is not secret). For ordinary, non-secret text just use == — the constant-time guarantee is not free.

Parameters

aone string
bthe other string

Example

program CompareToken {
  entry {
    if Crypto.ct_equal("abc", "abc") { print(1) } else { print(0) }   # 1
    if Crypto.ct_equal("abc", "abd") { print(1) } else { print(0) }   # 0
  }
}
← All symbols