Open options.
Hex-encoded recipient private key.
Hex-encoded encapsulated key (from seal).
Hex-encoded ciphertext (from seal).
Optionalinfo?: stringHex-encoded info string (must match seal).
Optionalaad?: stringHex-encoded additional authenticated data (must match seal).
Optionalsuite?: HpkeSuiteOptionsCipher suite selection (must match seal).
Optionalpsk?: HpkePskOptionsPre-shared key options (must match seal).
Hex-encoded plaintext.
const kp = hpkeGenerateKeyPair();
const sealed = hpkeSeal({
recipientPublicKey: kp.publicKey,
plaintext: "48656c6c6f",
});
const opened = hpkeOpen({
recipientPrivateKey: kp.privateKey,
encapsulatedKey: sealed.encapsulatedKey,
ciphertext: sealed.ciphertext,
});
console.log(opened.plaintext); // "48656c6c6f"
Decrypt (open) an HPKE ciphertext.
Decapsulates the shared secret using the recipient's private key, re-derives the AEAD key material, and decrypts the ciphertext.