Hpke.Private_keySourceA validated private key tagged with its KEM. Values are abstract but cannot be reliably zeroized by the OCaml garbage collector.
Parse and validate an exact-length key. X25519 input is clamped.
Serialize the key. X25519 output is clamped as required by RFC 9180.