PQC Today is an educational and demonstration platform, not a production system. Nothing it produces — keys, certificates, configurations, reports, or test results — is fit to protect real data, and none of it may be deployed or relied upon in production.

PKCS#11 HSM Playground

What this means for you

Executive / Business Leader
A banner at the top says this is a hands-on engineering workbench and points you to Command Center, Compliance landscape and Migration framework; for your role the engine stays Rust and the test suites are not shown.
GRC / Risk & Compliance
The same engineering-workbench banner appears for your role; if you stay, Inspect › Log lists every call with Function, Arguments and Return Value, and "Beginner" adds a "Plain English" column.
Developer / Engineer
Build › Standard is a pipeline builder with Builder and Code views, Run (⌘/Ctrl+Enter) and "Export .py"; Build also carries Validation and Conformance suites, and the Engine switch offers C++, Rust or Dual Parity.
Security Architect
Operate walks "1. Initialize HSM", "2. Create Token", "3. Open Session & Login", then a Primitives rail — KEM, Symmetric Encrypt, Key Wrap / Unwrap, Hashing, Sign & Verify, Key Agreement, KDF; Inspect › Keys lists what the token holds.
Researcher / Academic
Build › Validation is the "Cryptographic Validation Workbench": NIST ACVP-Server reference samples, standard KATs, oracle and functional tests, each row tagged with its evidence tier; Build › Conformance is a "PKCS#11 v3.2 Conformance Runner"; the WIP badge opens the methodology.
Certification & Validation Engineer
Build › Validation is the "Cryptographic Validation Workbench" — NIST ACVP-Server reference samples, standard KATs, oracle and functional tests, each row tagged with its evidence tier; Build › Conformance replays PKCS#11 v3.2 profile cases.
IT Ops / DevOps
The Learn lessons "The Cryptoki model — slots, tokens, sessions, login" and "Mechanism discovery" cover token setup; Inspect › Mechanisms' "Query Slot" enumerates what the token supports, and the Log filters by origin.
Curious Explorer
Open the Learn tab, pick a lesson and press "Run all" to watch each step run; the "New to PKCS#11?" strip explains the terms on hover, and the engine is preset to Rust.
New to PKCS#11?Hover a term:CKA_EXTRACTABLECKA_SENSITIVEC_WrapKeyCKM_AES_KWC_EncapsulateKey
Core

The Cryptoki model — slots, tokens, sessions, login

Every PKCS#11 call happens through a session, opened against a token, that lives in a slot. This walkthrough boots the real engine and shows what each layer actually is — then deliberately breaks one to show what an honest failure looks like.

PKCS#11 (Cryptoki) separates "what device" (slot → token) from "how you talk to it" (session → login). Get this model straight and every later operation — key generation, signing, wrapping — is just "which session, which handle."

Steps

  1. C_Initialize / C_InitToken / C_OpenSession

    1. Boot the library, format a token, and open an authenticated session

  2. C_GetTokenInfo

    2. Read back the token's identity

  3. C_GetSessionInfo

    3. Read back this session's own state

  4. C_GetSessionInfo (unopened handle)

    4. Try the same call on a session handle nobody ever opened

No HSM keys generated yet.

Use the KEM or Sign tabs to generate key pairs.

Next step

Learn HSMs and PQC

The module behind this lab: how hardware security modules take on post-quantum keys.