This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Radar · Go · Archive · Week 47 · Nov 17 – 23, 2025

crypto/hpke: new package

Nice to knowstdlib

What changed
A new crypto/hpke package has been added, providing the base mode of the HPKE IETF standard.
Production impact
The source does not say.
Try it
Import crypto/hpke and call NewSender to create an HPKE sender.
Source
github.com/golang/go/issues/75300

Understand it, then run it

A new crypto/hpke package has been added to the Go standard library. It implements the base mode of the HPKE IETF standard, which is a hybrid encryption scheme that combines a public‑key key‑encapsulation mechanism (KEM) with a symmetric key‑derivation function (KDF) and an authenticated encryption algorithm (AEAD). Before this change Go had no built‑in support for HPKE; developers had to use third‑party libraries or roll their own. With the new package you can now create a sender and a recipient, encrypt data with Seal, and decrypt it with Open, all using the same ciphersuite.

Run it now

Todaygo
// This program demonstrates the new crypto/hpke package in Go 1.27.1.
// It generates a DHKEM key pair, encrypts a message, then decrypts it.
package main

import (
	"crypto/ecdh"
	"crypto/hpke"
	"fmt"
)

func main() {
	// Choose the X25519 curve for the KEM.
	kem := hpke.DHKEM(ecdh.X25519())

	// Generate a key pair.
	priv, err := kem.GenerateKey()
	if err != nil {
		panic(err)
	}
	pub := priv.PublicKey()

	// Define the ciphersuite: use the same KEM, HKDF-SHA256, and AES-128-GCM.
	kdf := hpke.HKDFSHA256()
	aead := hpke.AES128GCM()

	// Sender side: create a context and seal a message.
	enc, sender, err := hpke.NewSender(pub, kdf, aead, []byte("info"))
	if err != nil {
		panic(err)
	}
	plaintext := []byte("Hello, HPKE!")
	ciphertext, err := sender.Seal(nil, plaintext)
	if err != nil {
		panic(err)
	}
	fmt.Printf("Ciphertext: %x\n", ciphertext)

	// Recipient side: create a context and open the ciphertext.
	recipient, err := hpke.NewRecipient(enc, priv, kdf, aead, []byte("info"))
	if err != nil {
		panic(err)
	}
	decrypted, err := recipient.Open(nil, ciphertext)
	if err != nil {
		panic(err)
	}
	fmt.Printf("Decrypted: %s\n", decrypted)
}

What it printed when we ran it on Go 1.27.1

Ciphertext: ba604d358860c4cc33ef72b25e46b34ef4d7b178bd2d3d1ca2e44faa
Decrypted: Hello, HPKE!

After the change ships

go · the proposal's code; it does not compile until the change ships

// This code uses the new crypto/hpke package.  It will not compile until
// the package is available in the Go release.

package main

import (
	"crypto/hpke"
	"crypto/ecdh"
	"fmt"
)

func main() {
	kem := hpke.DHKEM(ecdh.X25519)
	priv, _ := kem.GenerateKey()
	pub := priv.PublicKey()

	info := []byte("example context")
	enc, sender, _ := hpke.NewSender(pub, hpke.HKDFSHA256(), hpke.AES128GCM(), info)

	plaintext := []byte("Hello, HPKE!")
	ciphertext, _ := sender.Seal(nil, plaintext)

	recipient, _ := hpke.NewRecipient(enc, priv, hpke.HKDFSHA256(), hpke.AES128GCM(), info)
	decrypted, _ := recipient.Open(nil, ciphertext)

	fmt.Printf("Decrypted: %s\n", decrypted)
}

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed