X25519
The classical elliptic-curve component already used widely in TLS key exchange.
The classical elliptic-curve component already used widely in TLS key exchange.
The post-quantum key encapsulation component standardised by NIST as part of FIPS 203.
A combined session secret designed so the connection remains protected if either component stays secure.
Classical TLS protects data in transit today, but the key exchange methods used by ordinary TLS can be vulnerable to a future cryptographically relevant quantum computer. That creates harvest-now-decrypt-later risk for sensitive traffic recorded today.
X25519MLKEM768 addresses that risk at the TLS key exchange layer by adding a post-quantum component while keeping compatibility with modern web infrastructure.
Hybrid TLS key exchange is not a complete post-quantum migration. It does not replace all certificate signatures, software signatures, identity tokens, encrypted databases, backups, internal services or supplier cryptography.
It is still a valuable early move because it protects a highly exposed layer of the stack: public and API traffic that adversaries can record from networks today.
Run the free scanner to see whether your public website negotiates post-quantum key exchange or only classical TLS.
A PQC guide is more useful when it is attached to current evidence. Create a free account, add a public domain now or later, and keep a repeatable baseline for TLS, security headers and visible post-quantum readiness.
Prefer to scan first? Open the free quantum security scanner.