An interactive command-line interface for cryptographic operations, supporting both legacy OpenPGP and modern post-quantum algorithms.
Getting started
The Crypto Service ecosystem
Package reference
Operational
pnpm add @sebastienrousseau/crypto-cli
# or
npm install @sebastienrousseau/crypto-cli
# or
yarn add @sebastienrousseau/crypto-cli
^22.0.0 or >=24.0.0 (active and maintenance LTS releases)pnpm >=9 (recommended) or npm >=10>=5.0 (when compiling with TypeScript)Launch the interactive menu:
cryptocli
You will be presented with a selection prompt:
? Select a function to execute.
Generate -- Generate a new OpenPGP key pair
Encrypt -- Encrypt a message (OpenPGP)
Decrypt -- Decrypt a message (OpenPGP)
Modern Keygen -- Generate keys (Ed25519, ML-DSA, ML-KEM, etc.)
Modern Hash -- Hash data (SHA-2, SHA-3, BLAKE2b, BLAKE3)
Modern Encrypt -- Encrypt (XChaCha20, AES-GCM, AES-GCM-SIV)
Modern Sign -- Sign/verify (Ed25519, ECDSA, Schnorr, ML-DSA)
Password Hash -- Hash/verify passwords (Argon2id/i/d)
Help -- Get help on a command
Use arrow keys to navigate, then press Enter to select a command.
Crypto Service provides a complete cryptography stack across 14 specialized packages:
| Package | Role | Description |
|---|---|---|
@sebastienrousseau/crypto-api |
API Schemas | Shared TypeScript types and utilities for the Crypto Service Suite, defining the canonical API surface. |
@sebastienrousseau/crypto-cli (this package) |
Terminal CLI | An interactive command-line interface for cryptographic operations, supporting both legacy OpenPGP and modern post-quantum algorithms. |
@sebastienrousseau/crypto-edge |
Edge Runtime | Edge-runtime cryptographic operations using the Web Crypto API, optimized for Cloudflare Workers, Vercel Edge, and Deno. |
@sebastienrousseau/crypto-kms |
Cloud KMS | Unified Key Management Service interface for AWS KMS, GCP Cloud KMS, Azure Key Vault, and HashiCorp Vault. |
@sebastienrousseau/crypto-lib |
Core Library | A modern cryptographic library for TypeScript, with post-quantum support, zero unsafe dependencies, and 100% test coverage. |
@sebastienrousseau/crypto-middleware |
Middleware | Framework-agnostic cryptographic middleware for Express, Fastify, and Koa applications. |
@sebastienrousseau/crypto-prisma |
ORM Adapter | Transparent field-level encryption extension for Prisma Client, powered by AES-256-GCM. |
@sebastienrousseau/crypto-react |
React Hooks | React hooks and context provider for client-side cryptographic operations with zero boilerplate. |
@sebastienrousseau/crypto-sdk |
Client SDK | A zero-dependency, typed HTTP client for the Crypto Service REST API, with full post-quantum support. |
@sebastienrousseau/crypto-server |
HTTP API | A hardened Fastify REST API for cryptographic operations, with rate limiting, OpenAPI schemas, and post-quantum endpoints. |
@sebastienrousseau/crypto-testing |
Test Support | Deterministic keys, fast mocks, and test fixtures for crypto-lib |
@sebastienrousseau/crypto-typeorm |
ORM Adapter | TypeORM column-level encryption with a single decorator, powered by crypto-lib. |
@sebastienrousseau/crypto-vue |
Vue Composables | Vue 3 composables for client-side cryptography |
@sebastienrousseau/crypto-wasm |
Acceleration | WebAssembly performance accelerator for crypto-lib |
crypto-cli is the command-line interface for the Crypto Service
Suite. It offers both legacy OpenPGP commands (key generation,
encryption, decryption, signing, verification, revocation) and
modern v2 commands using @noble/* primitives with post-quantum
algorithm support. All operations run interactively via a guided
prompt menu.
| Command | Description |
|---|---|
Generate |
Generate a new OpenPGP key pair (RSA or ECC) |
Encrypt |
Encrypt a message using public keys, passwords, or both |
Decrypt |
Decrypt a message with a private key, session key, or password |
Sign |
Sign a message with an OpenPGP private key |
Verify |
Verify signatures of a cleartext signed message |
Revoke |
Revoke an OpenPGP key with a reason |
Reformat |
Reformat signature packets and rewrap a key object |
Session |
Generate a new session key object from public key preferences |
| Command | Description |
|---|---|
Modern Keygen |
Generate key pairs for 12 algorithms including post-quantum |
Modern Hash |
Hash data with 7 algorithms (SHA-2, SHA-3, BLAKE) |
Modern Encrypt |
Encrypt/decrypt with 5 AEAD ciphers |
Modern Sign |
Sign and verify with 8 algorithms including ML-DSA |
Password Hash |
Hash and verify passwords with 3 Argon2 variants |
The CLI respects the following environment variables:
| Variable | Default | Description |
|---|---|---|
CRYPTO_KEY_DIR |
./keys |
Directory for reading key files |
CRYPTO_DATA_DIR |
./data |
Directory for reading data files |
CRYPTO_KEY_OUT_DIR |
./keys/out |
Directory for writing generated key files |
export CRYPTO_KEY_DIR="$HOME/.crypto/keys"
export CRYPTO_DATA_DIR="$HOME/.crypto/data"
export CRYPTO_KEY_OUT_DIR="$HOME/.crypto/keys/out"
cryptocli
## Examples
Runnable shell scripts are provided in the examples/
directory:
| Category | Example | Purpose |
|---|---|---|
| Keygen | keygen.sh | Generate Ed25519, P-256, and ML-KEM keys |
| Hashing | hash.sh | Hash data with various algorithms |
| Encryption | encrypt.sh | Encrypt and decrypt with modern ciphers |
| Signing | sign.sh | Sign and verify with modern algorithms |
| Passwords | password.sh | Hash and verify passwords with Argon2 |
| Legacy | legacy.sh | Legacy OpenPGP key generation and signing |
Run any example:
bash examples/keygen.sh
pnpm --filter @sebastienrousseau/crypto-cli run build
pnpm --filter @sebastienrousseau/crypto-cli run test
pnpm --filter @sebastienrousseau/crypto-cli run lint
pnpm --filter @sebastienrousseau/crypto-cli run format
All 14 packages in the Crypto Service workspace maintain a 100% coverage floor across statements, branches, functions, and lines.
Report vulnerabilities privately via GitHub Security Advisories or according to SECURITY.md. Never report security issues publicly.
All cryptographic operations leverage audited primitives, enforce constant-time execution where applicable, and zero sensitive key material upon disposal.
Versions advance strictly one step at a time on the 0.0.x line (v0.0.1 → v0.0.2 → v0.0.3 ... → v0.0.999 → v0.1.0). Work for every release iteration begins on a dedicated feat/v<version> branch.
All 14 packages in the workspace move in lockstep. Public API signatures, cipher output formats, and serialization schemas are strictly versioned. Breaking changes to serialized formats or algorithm defaults are considered major breaking changes. Minimum toolchain upgrades (e.g. Node.js LTS floor) are governed by POLICIES.md.
Dual-licensed under Apache 2.0 or MIT, at your option.
Copyright (c) 2022-2026 Sebastien Rousseau and The Crypto Service Suite contributors.