# crypto.constant-time-equal
`constantTimeEqual(expectedTag, givenTag)` is true when the two byte strings
are identical. Use it wherever one side is secret and the other comes from
outside: an HMAC tag, a JWT signature, a password hash, an API key digest.
An ordinary `==` on lists or strings stops at the first byte that differs.
Timed over many requests, that tells an attacker how many leading bytes of a
forged value were right, and lets them find a valid tag a byte at a time.
This looks at every byte whatever it finds, OR-ing the differences together
and deciding once at the end, which is how Node's `timingSafeEqual` and
Python's `hmac.compare_digest` (which the Python implementation uses) work.
Lengths are compared first and different lengths answer false straight away.
That reveals the length, which is not a secret for a MAC or hash (its length
is fixed by the algorithm). Compare fixed-length digests, not raw secrets of
varying length; hash both sides first if you must.
Constant time is a property of the code as written; a JIT or an optimising
compiler may still find shortcuts, which is why the libraries above exist.
This is the same loop they use and is as good as pure code can do, and the
vectors pin its answers, not its timing.
Bytes are lists of integers 0 to 255, as everywhere in the registry (see
`encoding.hex`), and a value outside that range is an error rather than
"not equal", because it means the caller passed the wrong thing.