HKDF Key Derivation
RFC 5869 extract-then-expand key derivation with explicit salt and info.
The secret you are stretching: never a URL, never persisted.
Empty means the RFC 5869 default: hash-length zero bytes.
Context/purpose binding, e.g. the key id the output is for.
1-64 bytes. This page refuses KDF-as-fountain usage.
HKDF (RFC 5869, extract-then-expand) over your inputs: WebCrypto deriveBits in this tab.
Nothing in yet
Paste, drop, or type to begin. Everything stays on this device.