Hashing & KDF
@webbuf/hkdf-sha256
Synchronous HKDF-SHA-256 extract, expand and key derivation for browsers and JavaScript runtimes.
Install
npm install @webbuf/hkdf-sha256Usage
import { WebBuf } from "@webbuf/webbuf";
import {
hkdfSha256,
hkdfSha256Extract,
hkdfSha256Expand,
} from "@webbuf/hkdf-sha256";
const salt = WebBuf.fromHex("000102030405060708090a0b0c");
const ikm = WebBuf.fromHex("0b".repeat(22));
const info = WebBuf.fromHex("f0f1f2f3f4f5f6f7f8f9");
const key = hkdfSha256(salt, ikm, info, 42);
const prk = hkdfSha256Extract(salt, ikm);
const expanded = hkdfSha256Expand(prk.buf, info, 42);
const keyHex = key.toHex();
const expandedHex = expanded.toHex();
console.log(keyHex);
console.log(expandedHex);
prk.wipe();
key.wipe();
expanded.wipe();API reference (3 exports)
Functions
hkdfSha256
functionCombined HKDF-SHA-256 extract then expand, with salt-first ordering. Undefined salt uses 32 zero bytes; info and keyLen are explicit. Returns FixedBuf<keyLen> in fresh storage for integer lengths 0..8160. Invalid lengths throw RangeError before derivation; invalid byte kinds throw TypeError. Inputs are not modified. The internal extracted key is wiped best-effort, including on failure; JS/WASM copies cannot be guaranteed erased.
hkdfSha256<N extends number>(salt: WebBuf | undefined, ikm: WebBuf, info: WebBuf, keyLen: N): FixedBuf<N>hkdfSha256Expand
functionRFC 5869 HKDF-SHA-256 expansion of a PRK of at least 32 bytes. Info is explicit (use an empty WebBuf for no context). keyLen is an integer byte count from 0 through 8160; invalid length or short PRK throws RangeError, including for zero output. Invalid byte argument kinds throw TypeError. Returns fresh independent storage with literal size inference. Input ranges are respected and never wiped. Owned temporary blocks are wiped best-effort; this promises neither complete runtime zeroization nor constant-time behavior.
hkdfSha256Expand<N extends number>(prk: WebBuf, info: WebBuf, keyLen: N): FixedBuf<N>hkdfSha256Extract
functionRFC 5869 HKDF-SHA-256 extraction. Undefined salt means 32 zero bytes; explicit salt and IKM may be any length, including empty. Returns a fresh 32-byte pseudorandom key without mutating either input. This is not a password-hardening function. Invalid byte argument kinds throw TypeError.
hkdfSha256Extract(salt: WebBuf | undefined, ikm: WebBuf): FixedBuf<32>