hkdf
HMAC-based Extract-and-Expand Key Derivation Function (HKDF)
Decision gist · record as of 2026-08-14
No. The package is dormant (last release 2015-06-16, classifiers list only Python 2.6–3.4, all end-of-life), has high install friction (source-only), and offers no runtime dependencies to ease integration. Install only if you are maintaining legacy Python 2 code that already depends on it.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- No runtime dependencies, but package is source-only and classifiers list only Python 2.6–3.4, all end-of-life versions.
- Compatibility with modern Python versions is unverified.
- High install friction due to source-only distribution (hkdf-0.0.3.tar.gz).
License · maintenance · safety
UNKNOWN (permissive) — Licensed under BSD (permissive), which permits commercial and private use with minimal restrictions. No notable licensing constraints for most use cases.
last release 2015-06-16 (4077 days) · last repo commit 2024-01-17 · 22 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 101,992 downloads/mo, #12,900 on PyPI
Alternatives
Verify before relying
from hkdf import hkdf_extract, hkdf_expand
from binascii import unhexlify
prk = hkdf_extract(unhexlify(b"8e94ef805b93e683ff18"), b"asecretpassword")
key = hkdf_expand(prk, b"context1", 16)- Whether the package actually works on Python 3.5 or later despite classifiers listing only 2.6–3.4.
- Whether any security review or audit has been performed on the HKDF implementation since 2015.
- Current maintenance status and whether the author is accepting pull requests or bug reports.
What it is and what it does
HKDF is a cryptographic key derivation function that implements the HMAC-based Extract-and-Expand Key Derivation Function as specified in the draft RFC. It takes input key material (typically a password or shared secret) and derives one or more cryptographically strong keys suitable for use in encryption, authentication, or other cryptographic operations. The package provides both a functional interface (separate `hkdf_extract()` and `hkdf_expand()` functions) and a wrapper class (`Hkdf`) for convenience.
The functional interface defaults to SHA-512 for hashing, while the wrapper class defaults to SHA-256. Both allow you to specify a custom hash function. The extract phase produces a pseudorandom key (PRK) from input material and an optional salt; the expand phase then generates output key material of a specified length, optionally parameterized by context information. This is useful when you need to derive multiple independent keys from a single source or when you need to convert weak input into strong cryptographic material.
Use it for
- Derive encryption keys from a user password in a password-based key derivation workflow.
- Generate multiple independent session keys from a single shared secret in a protocol handshake.
- Expand a master key into subkeys for different purposes (e.g., encryption, authentication, integrity).
- Implement cryptographic protocols that require HKDF-based key material generation.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
No.
The package is dormant (last release 2015-06-16, classifiers list only Python 2.6–3.4, all end-of-life), has high install friction (source-only), and offers no runtime dependencies to ease integration. Install only if you are maintaining legacy Python 2 code that already depends on it.
Install
hkdf on PyPI
Before you install
High install friction due to source-only distribution (hkdf-0.0.3.tar.gz). Maintenance is dormant—last release was 2015-06-16 and last commit 2024-01-17, with no recent activity. Classifiers indicate support only for Python 2.6, 2.7, 3.3, 3.4, all of which are end-of-life.
No runtime dependencies, but package is source-only and classifiers list only Python 2.6–3.4, all end-of-life versions. Compatibility with modern Python versions is unverified.
License in practice
Licensed under BSD (permissive), which permits commercial and private use with minimal restrictions. No notable licensing constraints for most use cases.
Quickstart
from hkdf import hkdf_extract, hkdf_expand
from binascii import unhexlify
prk = hkdf_extract(unhexlify(b"8e94ef805b93e683ff18"), b"asecretpassword")
key = hkdf_expand(prk, b"context1", 16)
Verify before relying
- Whether the package actually works on Python 3.5 or later despite classifiers listing only 2.6–3.4.
- Whether any security review or audit has been performed on the HKDF implementation since 2015.
- Current maintenance status and whether the author is accepting pull requests or bug reports.
Package facts
| License | UNKNOWN permissive |
| Python support | Not specified |
| Install friction | High. Source build required |
| Runtime dependencies | None |
| Maintenance | Dormant 4,077 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 101,992 / month, #12,900 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Intended Audience :: DevelopersLicense :: OSI Approved :: BSD LicenseProgramming Language :: Python :: 2.6Programming Language :: Python :: 2.7Programming Language :: Python :: 3.3Programming Language :: Python :: 3.4 |
Evidence: hkdf-0.0.3.tar.gz
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “key derivation function”
- hkdfImplements HMAC-based Key Derivation Function (HKDF) with…
- blake3Python bindings for the BLAKE3 cryptographic hash function, exposing…
- pyscryptA pure-Python implementation of the scrypt password-based key…
Give your agent the search over MCP, or paste the wish link into any chat.
More Cryptography packages
Certifi provides Mozilla's curated collection of root SSL certificates for Python applications to validate TLS hosts and verify certificate trustworthiness.
cryptography provides cryptographic recipes and low-level primitives for symmetric encryption, message digests, key derivation, and other common cryptographic algorithms in Python.
Pure-Python RSA encryption, decryption, signing, and key generation following PKCS#1 v1.5, with command-line and library interfaces.
pyOpenSSL wraps OpenSSL's SSL/TLS functionality for Python, providing high-level connection objects and certificate handling through a Python-friendly interface around OpenSSL's cryptographic operations.
Provides Microsoft Entra ID token-based authentication for Azure SDK clients through a set of TokenCredential implementations that handle OAuth flows and managed identity support.
PyNaCl provides Python bindings to libsodium for digital signatures, secret-key and public-key encryption, hashing, message authentication, and password-based key derivation.
See also pyscrypt · aws-cryptographic-material-providers · eth-keyfile · diffiehellmanlib · keyrings.cryptfile · altcha · scrypt · spake2 · bip32 · bcrypt