Seal options.
Hex-encoded recipient public key.
Hex-encoded plaintext.
Optionalinfo?: stringHex-encoded info string (default: empty).
Optionalaad?: stringHex-encoded additional authenticated data (default: empty).
Optionalsuite?: HpkeSuiteOptionsCipher suite selection.
Optionalpsk?: HpkePskOptionsPre-shared key options (enables PSK mode).
Hex-encoded ciphertext and encapsulated key.
Encrypt (seal) a plaintext using HPKE.
Generates an ephemeral key pair, encapsulates a shared secret against the recipient's public key, derives AEAD key material via the HPKE key schedule, and encrypts the plaintext.