{"id":"hkdf-compute","version":"1.0.0","description":"Derive output key material with HKDF-Extract/Expand (RFC 5869), or HKDF-Expand alone from a caller-supplied PRK.","supported_operations":["derive a key with hkdf","hkdf-sha256 key derivation","expand a shared secret into subkeys","hkdf extract and expand","generate encryption key material from a master secret","גזור מפתח עם hkdf"],"unsupported_operations":["password-based key derivation (see pbkdf2-compute for an iterated, password-oriented KDF)","deriving more than 1024 bytes of output key material in one call"],"semantics":["algorithm selects the underlying hash function H for both steps; its output length HashLen is 20 (sha1), 32 (sha256), 48 (sha384) or 64 (sha512) bytes.","mode extract_and_expand (default): PRK = HMAC-Hash(salt, ikm). When salt is omitted, it defaults to a string of HashLen zero bytes per RFC 5869 section 2.2 (not the empty string, though HMAC's own zero-padding of short keys makes the two give the same PRK in practice). OKM = HKDF-Expand(PRK, info, length).","mode expand_only: ikm is used directly as the PRK (no extract step runs); ikm must be at least HashLen bytes in this mode, and salt must not be given (its presence is invalid_input, not silently ignored).","HKDF-Expand: T(0) is the empty string; for i = 1..ceil(length / HashLen), T(i) = HMAC-Hash(PRK, T(i-1) || info || byte(i)) where byte(i) is the 1-based block counter as a single byte. OKM is the first `length` bytes of T(1) || T(2) || ....","info defaults to the empty string when omitted. length is 1..1024 bytes (RFC 5869 itself allows up to 255*HashLen; this tool additionally caps at 1024 bytes to bound CPU and output size).","prk_hex is the PRK actually used for the expand step (HMAC-Hash(salt, ikm) in extract_and_expand mode, or ikm itself in expand_only mode). okm_hex is lowercase; okm_base64 is RFC 4648 section 4 padded."],"limits":{"max_ikm_bytes":4096,"max_salt_bytes":4096,"max_info_bytes":4096,"max_length":1024},"pricing":{"status":"unpriced","charge_usd":null},"input_schema":{"type":"object","additionalProperties":false,"required":["ikm","algorithm","length"],"properties":{"ikm":{"type":"string","maxLength":16384},"ikm_encoding":{"type":"string","enum":["utf8","hex","base64","base64url"],"default":"utf8"},"salt":{"type":"string","maxLength":16384},"salt_encoding":{"type":"string","enum":["utf8","hex","base64","base64url"],"default":"utf8"},"info":{"type":"string","maxLength":4096,"default":""},"info_encoding":{"type":"string","enum":["utf8","hex","base64","base64url"],"default":"utf8"},"algorithm":{"type":"string","enum":["sha1","sha256","sha384","sha512"]},"length":{"type":"integer","minimum":1,"maximum":1024},"mode":{"type":"string","enum":["extract_and_expand","expand_only"],"default":"extract_and_expand"}}},"output_schema":{"type":"object","additionalProperties":false,"required":["prk_hex","okm_hex","okm_base64","length"],"properties":{"prk_hex":{"type":"string","pattern":"^[0-9a-f]+$","minLength":2},"okm_hex":{"type":"string","pattern":"^[0-9a-f]*$"},"okm_base64":{"type":"string"},"length":{"type":"integer","minimum":1,"maximum":1024}}},"examples":[{"input":{"ikm":"0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b0b","ikm_encoding":"hex","salt":"000102030405060708090a0b0c","salt_encoding":"hex","info":"f0f1f2f3f4f5f6f7f8f9","info_encoding":"hex","algorithm":"sha256","length":42},"output":{"prk_hex":"077709362c2e32df0ddc3f0dc47bba6390b6c73bb50f9c3122ec844ad7c2b3e5","okm_hex":"3cb25f25faacd57a90434f64d0362f2a2d2d0a90cf1a5a4c5db02d56ecc4c5bf34007208d5b887185865","okm_base64":"PLJfJfqs1XqQQ09k0DYvKi0tCpDPGlpMXbAtVuzExb80AHII1biHGFhl","length":42}},{"input":{"ikm":"0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c0c","ikm_encoding":"hex","algorithm":"sha1","length":42},"output":{"prk_hex":"2adccada18779e7c2077ad2eb19d3f3e731385dd","okm_hex":"2c91117204d745f3500d636a62f64f0ab3bae548aa53d423b0d1f27ebba6f5e5673a081d70cce7acfc48","okm_base64":"LJERcgTXRfNQDWNqYvZPCrO65UiqU9QjsNHyfrum9eVnOggdcMznrPxI","length":42}}],"execute_url":"/v1/tools/hkdf-compute/versions/1.0.0/execute"}