# Hex bytes xor

`hex-bytes-xor` · version 1.0.0 · Encoding & checksums · free, no key needed

Byte-wise XOR of two equal-length lowercase hex byte strings. Transformation only; no cryptographic security claim.

**Use when you need to: hex bytes xor · xor hex byte strings · byte-wise xor of hex.**

## Supported

- hex bytes xor
- xor hex byte strings
- byte-wise xor of hex

## Not supported

- unequal-length xor
- uppercase hex
- 0x prefix
- byte separators
- stream cipher key expansion
- encryption
- decode hex to text

## Behavior

- a and b are lowercase hex byte strings: 0-9 and a-f only, two hex digits per byte, no 0x prefix, no separators, no whitespace, no uppercase.
- a and b are each bounded to 128000 bytes (256000 hex characters).
- a and b must decode to the same number of bytes; unequal lengths are rejected rather than truncated, padded, or wrapped.
- Result hex is the byte-wise XOR of a and b, encoded as lowercase hex with the same byte length as the inputs.
- Empty a and empty b produce an empty result.
- This is a reversible byte transform, not encryption, a MAC, or any other security guarantee.

## Input

- `a` (string, required): max length 256000
- `b` (string, required): max length 256000

## Output

- `hex` (string, required)

## Limits

- max input bytes: 128000

## Example

Request input:

```json
{
  "a": "ff00",
  "b": "0f0f"
}
```

Response:

```json
{
  "result": {
    "hex": "f00f"
  }
}
```

## How to call it

### MCP

Connect `https://computefirst.net/mcp` ([setup](/docs#connect)), then call `execute` with:

```json
{
  "id": "hex-bytes-xor",
  "version": "1.0.0",
  "input": {
    "a": "ff00",
    "b": "0f0f"
  }
}
```

### HTTP (no key)

```sh
curl -X POST https://computefirst.net/v1/tools/hex-bytes-xor/versions/1.0.0/execute \
  -H "Content-Type: application/json" \
  -d '{"a":"ff00","b":"0f0f"}'
```

The machine-readable contract is at [/v1/tools/hex-bytes-xor/versions/1.0.0](/v1/tools/hex-bytes-xor/versions/1.0.0).

### CLI

```sh
node cli.mjs run hex-bytes-xor 1.0.0 --input input.json --base-url https://computefirst.net
```

Get the client at [/clients/cli/](/clients/cli/).

## Related tools

- [Hex bytes concat](/tools/hex-bytes-concat): Concatenate a bounded ordered list of lowercase hex byte strings into one hex string.
- [Hex bytes slice](/tools/hex-bytes-slice): Slice a lowercase hex byte string by explicit byte-index bounds, half-open like Array.slice.
- [UTF-8 hex](/tools/utf8-hex): Encode a Unicode string as lowercase hex of its UTF-8 bytes. Transformation only; no security claim.
- [Adler-32](/tools/adler32): Adler-32 of UTF-8 bytes (RFC 1950). Integrity check only; no security claim.
- [Base64 UTF-8](/tools/base64-utf8): Decode standard Base64 to UTF-8 text. Transformation only; no security claim.
- [CRC-32](/tools/crc32): CRC-32 of UTF-8 bytes (ISO 3309 / ZIP / PNG polynomial). Integrity check only; no security claim.
