This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Radar · Go · Archive · Week 48 · Nov 24 – 30, 2025

crypto/hpke: new package

Nice to knowstdlib

What changed
A new crypto/hpke package is added to provide the base mode of the HPKE IETF standard.
Production impact
The source does not say.
Try it
Import crypto/hpke and create a sender/recipient pair.
Source
github.com/golang/go/issues/75300

Understand it, then run it

Run it now

Todaygo
// This program demonstrates the new crypto/hpke package that was added in Go 1.27.1.
// It generates a DHKEM key pair, encrypts a message with the public key,
// and then decrypts it with the private key. The output shows the original
// plaintext and the decrypted plaintext to confirm that the round‑trip
// succeeded.

package main

import (
	"crypto/hpke"
	"crypto/ecdh"
	"fmt"
)

func main() {
	// Create a DHKEM instance for the X25519 curve.
	kem := hpke.DHKEM(ecdh.X25519())

	// Generate a new key pair.
	priv, err := kem.GenerateKey()
	if err != nil {
		panic(err)
	}
	pub := priv.PublicKey()

	// Choose a KDF and AEAD. Here we use HKDF‑SHA256 and AES‑128‑GCM.
	kdf := hpke.HKDFSHA256()
	aead := hpke.AES128GCM()

	// The sender creates a context with the recipient's public key.
	enc, sender, err := hpke.NewSender(pub, kdf, aead, []byte("info"))
	if err != nil {
		panic(err)
	}

	// Encrypt a message.
	plaintext := []byte("Hello, HPKE!")
	ciphertext, err := sender.Seal(nil, plaintext)
	if err != nil {
		panic(err)
	}

	// The recipient creates a context with the encapsulated key and its private key.
	recipient, err := hpke.NewRecipient(enc, priv, kdf, aead, []byte("info"))
	if err != nil {
		panic(err)
	}

	// Decrypt the message.
	decrypted, err := recipient.Open(nil, ciphertext)
	if err != nil {
		panic(err)
	}

	fmt.Printf("original: %s\n", plaintext)
	fmt.Printf("decrypted: %s\n", decrypted)
}

What it printed when we ran it on Go 1.27.1

original: Hello, HPKE!
decrypted: Hello, HPKE!

Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.

Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed