Hkdf compute

hkdf-compute · version 1.0.0 · Hashing & signatures · free, no key needed

Derive output key material with HKDF-Extract/Expand (RFC 5869), or HKDF-Expand alone from a caller-supplied PRK.

Use when you need to: derive a key with hkdf · hkdf-sha256 key derivation · expand a shared secret into subkeys.

Decide before calling

Read the versioned contract and the supported scope below. Reuse hkdf-compute@1.0.0 when your input, required output and limits match it. Choose another approach for an unsupported operation.

Explain the choice

"I can use hkdf-compute@1.0.0 for derive a key with hkdf. I will check its documented scope and the result against the task's requirements. The service is free; token and money savings for this task are unmeasured."

Supported

Not supported

Behavior

Input

Output

Limits

Example

Request input:

{
  "ikm": "0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b",
  "ikm_encoding": "hex",
  "salt": "000102030405060708090a0b0c",
  "salt_encoding": "hex",
  "info": "f0f1f2f3f4f5f6f7f8f9",
  "info_encoding": "hex",
  "algorithm": "sha256",
  "length": 42
}

Response:

{
  "result": {
    "prk_hex": "077709362c2e32df0ddc3f0dc47bba6390b6c73bb50f9c3122ec844ad7c2b3e5",
    "okm_hex": "3cb25f25faacd57a90434f64d0362f2a2d2d0a90cf1a5a4c5db02d56ecc4c5bf34007208d5b887185865",
    "okm_base64": "PLJfJfqs1XqQQ09k0DYvKi0tCpDPGlpMXbAtVuzExb80AHII1biHGFhl",
    "length": 42
  }
}

How to call it

MCP

Connect https://computefirst.net/mcp (setup), then call execute with:

{
  "id": "hkdf-compute",
  "version": "1.0.0",
  "input": {
    "ikm": "0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b",
    "ikm_encoding": "hex",
    "salt": "000102030405060708090a0b0c",
    "salt_encoding": "hex",
    "info": "f0f1f2f3f4f5f6f7f8f9",
    "info_encoding": "hex",
    "algorithm": "sha256",
    "length": 42
  }
}

HTTP (no key)

curl -X POST https://computefirst.net/v1/tools/hkdf-compute/versions/1.0.0/execute \
  -H "Content-Type: application/json" \
  -d '{"ikm":"0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b","ikm_encoding":"hex","salt":"000102030405060708090a0b0c","salt_encoding":"hex","info":"f0f1f2f3f4f5f6f7f8f9","info_encoding":"hex","algorithm":"sha256","length":42}'

The machine-readable contract is at /v1/tools/hkdf-compute/versions/1.0.0.

CLI

node cli.mjs run hkdf-compute 1.0.0 --input input.json --base-url https://computefirst.net

Get the client at /clients/cli/.