# `SSL.Crypto.HKDF`
[🔗](https://github.com/gsmlg-dev/http_fetch/blob/v0.16.7/apps/ex_ssl/lib/ssl/crypto/hkdf.ex#L1)

HKDF and TLS 1.3 labeled key derivation.

Only the SHA-256 and SHA-384 cipher-suite hashes are supported.

# `error`

```elixir
@type error() ::
  {:error, :unsupported_hash}
  | {:error, {:length_out_of_range, pos_integer()}}
  | {:error, {:label_length_out_of_range, {1, 249}}}
  | {:error, {:context_length_out_of_range, 255}}
  | {:error, {:invalid_transcript_hash_length, pos_integer()}}
```

# `hash`

```elixir
@type hash() :: :sha256 | :sha384
```

# `derive_secret`

```elixir
@spec derive_secret(atom(), binary(), binary(), binary()) :: binary() | error()
```

# `expand`

```elixir
@spec expand(atom(), binary(), binary(), integer()) :: binary() | error()
```

# `expand_label`

```elixir
@spec expand_label(atom(), binary(), binary(), binary(), integer()) ::
  binary() | error()
```

# `extract`

```elixir
@spec extract(atom(), binary(), binary()) :: binary() | error()
```

---

*Consult [api-reference.md](api-reference.md) for complete listing*
