Crypto KMS
    Preparing search index...

    Class LocalKmsProvider

    Local in-memory KMS provider.

    Uses Node.js crypto for AES-256-GCM symmetric operations and @sebastienrousseau/crypto-lib Ed25519 for signing operations. Keys are stored in memory and do not persist across restarts.

    const provider = new LocalKmsProvider();
    const key = await provider.createKey("aes-256-gcm", "encrypt");
    const enc = await provider.encrypt(key.keyId, new TextEncoder().encode("hello"));
    const dec = await provider.decrypt(key.keyId, enc.ciphertext);
    console.log(new TextDecoder().decode(dec.plaintext)); // "hello"

    Implements

    Index
    name: "local"

    Provider identifier.

    • Create a new key with the given algorithm and usage.

      Parameters

      • algorithm: string
      • usage: "encrypt" | "sign" | "wrap"
      • Optional_metadata: Record<string, string>

      Returns Promise<KmsKeyMetadata>

    • Schedule a key for deletion after a pending window.

      Parameters

      • keyId: string
      • pendingWindowDays: number = 30

      Returns Promise<void>

    • Encrypt plaintext with AES-256-GCM using the managed key.

      Parameters

      • keyId: string
      • plaintext: Uint8Array
      • Optionalcontext: Record<string, string>

      Returns Promise<KmsEncryptResult>

    • Decrypt AES-256-GCM ciphertext using the managed key.

      Parameters

      • keyId: string
      • ciphertext: string
      • Optionalcontext: Record<string, string>

      Returns Promise<KmsDecryptResult>

    • Sign data using the Ed25519 signing key.

      Parameters

      • keyId: string
      • data: Uint8Array
      • Optional_algorithm: string

      Returns Promise<KmsSignResult>

    • Verify an Ed25519 signature against data.

      Parameters

      • keyId: string
      • data: Uint8Array
      • signature: string
      • Optional_algorithm: string

      Returns Promise<boolean>

    • Generate a data encryption key (DEK) wrapped by the managed key.

      Parameters

      • keyId: string
      • Optional_keySpec: string

      Returns Promise<{ plaintext: Uint8Array; ciphertext: string }>