Browser-based HPKE demo — RFC 9180 hybrid public key encryption. KEM + KDF + AEAD composed into one scheme, every stage inspectable. Base, PSK, Auth, AuthPSK modes. Edit the info string or AAD and watch real AEAD reject. The composition underlying TLS ECH, Oblivious HTTP, and MLS. No backends. No simulated math.
MITTypeScriptaeadcrypto-labcryptographyhkdfhpkehybrid-encryptionkdfkem
systemslibrarian.github.io/crypto-lab-hpke-envelope