# js-crypto-hkdf

> Universal Module for HKDF (Hash-based Key Derivation Function) in JavaScript

Latest version **1.0.7** (published 2023-09-27) · MIT license · 0 weekly downloads

## Install

```sh
npm install js-crypto-hkdf
pnpm add js-crypto-hkdf
yarn add js-crypto-hkdf
bun add js-crypto-hkdf
```

## Health

**Score 25/100 (F)** — status: abandoned.

Positive: has types; no vulnerabilities; high quality score.

Warnings: low downloads; no esm support.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 1.0.7 |
| Published | 2023-09-27 |
| First published | 2018-09-26 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | bundled |
| Module format | CommonJS |
| Dependencies | 5 |
| Unpacked size | 102.3 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| Author | Jun Kurihara |
| Maintainers | kurihara |
| Keywords | crypto, hkdf, rfc5869, webcrypto |

## Links

- npm: https://www.npmjs.com/package/js-crypto-hkdf
- Repository: https://github.com/junkurihara/jscu
- Homepage: https://github.com/junkurihara/jscu/tree/master/packages/js-crypto-hkdf#readme
- Issues: https://github.com/junkurihara/jscu/issues
- npm.io page: https://npm.io/package/js-crypto-hkdf

## Dependencies (5)

- [js-crypto-env](https://npm.io/package/js-crypto-env.md) ^1.0.5
- [js-crypto-hash](https://npm.io/package/js-crypto-hash.md) ^1.0.7
- [js-crypto-hmac](https://npm.io/package/js-crypto-hmac.md) ^1.0.7
- [js-crypto-random](https://npm.io/package/js-crypto-random.md) ^1.0.5
- [js-encoding-utils](https://npm.io/package/js-encoding-utils.md) 0.7.3

## Alternatives

- [@gemini-wallet/core](https://npm.io/package/@gemini-wallet/core.md) — 515.6K weekly downloads
- [utility](https://npm.io/package/utility.md) — 416.6K weekly downloads
- [@primno/dpapi](https://npm.io/package/@primno/dpapi.md) — 7.2K weekly downloads
- [pi-readseek](https://npm.io/package/pi-readseek.md) — 3.7K weekly downloads
- [@emilia-protocol/verify](https://npm.io/package/@emilia-protocol/verify.md) — 1.1K weekly downloads

## Recent versions

- 1.0.7 (latest) — 2023-09-27
- 1.0.6 — 2023-09-02
- 1.0.5 — 2023-08-25
- 1.0.4 — 2022-02-04
- 1.0.3 — 2021-11-22
- 1.0.2 — 2021-03-13
- 1.0.1 — 2021-03-13
- 1.0.0 — 2020-09-30
- 0.7.3 — 2020-01-14
- 0.7.2 — 2019-12-08
- 0.7.1 — 2019-11-19
- 0.7.0 — 2019-11-19
- 0.6.4 — 2019-09-05
- 0.6.3 — 2019-08-14
- 0.6.2 — 2019-07-19
- … 26 more at https://npm.io/package/js-crypto-hkdf/versions

## README

Universal Module for RFC5869 HKDF (Hash-based Key Derivation Function) in JavaScript
--
[![npm version](https://badge.fury.io/js/js-crypto-hkdf.svg)](https://badge.fury.io/js/js-crypto-hkdf)
[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](https://opensource.org/licenses/MIT)

> **WARNING**: At this time this solution should be considered suitable for research and experimentation, further code and security review is needed before utilization in a production application.

# Introduction and Overview
This library is designed to 'universally' provide an HKDF (Hash-based Key Derivation Function), i.e., it works both on most modern browsers and on Node.js just by importing from NPM/source code. The original specification is given in RFC5869 (https://tools.ietf.org/html/rfc5869). Note that in the design principle, the library fully utilizes native APIs like WebCrypto API to accelerate its operation if available.

# Installation

At your project directory, do either one of the following.

- From npm/yarn:
  ```shell
  $ npm install --save js-crypto-hkdf // npm
  $ yarn add js-crypto-hkdf // yarn
  ```
- From GitHub:
  ```shell
  $ git clone https://github.com/junkurihara/jscu.git
  $ cd js-crypto-utils/packages/js-crypto-hkdf
  & yarn build
  ```

Then you should import the package as follows.

```shell
import hkdf from 'js-crypto-hkdf'; // for npm
import hkdf from 'path/to/js-crypto-hkdf/dist/index.js'; // for github
```

The bundled file is also given as `js-crypto-hkdf/dist/jschkdf.bundle.js` for a use case where the module is imported as a `window.jschkdf` object via `script` tags.


# Usage

## Derive key from a master secret without salt (salt is randomly generated inside the function)

```javascript
const masterSecret = ...; // Uint8Array of arbitrary length
const hash = 'SHA-256';
const length = 32; // derived key length
const info = ''; // information specified in rfc5869
hkdf.compute(masterSecret, hash, length, info).then( (derivedKey) => {
  // now you get a automatically-generated salt and a key derived from the masterSecret.
});
```

## Derive key from a master secret with salt

```javascript
const masterSecret = ...; // Uint8Array of arbitrary length
const hash = 'SHA-256';
const length = 32; // derived key length
const info = ''; // information specified in rfc5869
const salt = ...; // Uint8Array of arbitrary length
hkdf.compute(masterSecret, hash, length, info, salt).then( (derivedKey) => {
  // now you get a key derived from the masterSecret
});
```

# License

Licensed under the MIT license, see `LICENSE` file.

---
_Source: https://npm.io/package/js-crypto-hkdf · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
