ConstEncrypt plaintext with a 256-bit key (secretbox: XChaCha20-Poly1305).
256-bit key as hex string or Uint8Array.
Data to encrypt (UTF-8 string or bytes).
Base64-encoded ciphertext (nonce prepended).
Decrypt ciphertext with a 256-bit key.
256-bit key as hex string or Uint8Array.
Base64-encoded ciphertext (as returned by encrypt).
Decrypted plaintext bytes.
Hash data with the specified algorithm.
Hash algorithm (e.g., "sha3-256", "sha256", "blake3").
Data to hash (UTF-8 string or bytes).
Hex-encoded hash digest.
Generate a key pair for any supported algorithm.
Key algorithm identifier (e.g., "ed25519", "ml-dsa-65").
Optionalmetadata: KeyMetadata
Optional metadata (kid, use, exp) to attach.
Generated key pair with public/private keys, algorithm, kid, metadata.
Sign a message with any supported signing algorithm.
Signing algorithm (e.g., "ed25519", "schnorr", "ml-dsa-65").
Hex-encoded private key.
Message to sign (UTF-8 string or bytes).
Hex-encoded signature.
Verify a signature with any supported signing algorithm.
Signing algorithm (e.g., "ed25519", "schnorr", "ml-dsa-65").
Hex-encoded public key.
Original message that was signed (UTF-8 string or bytes).
Hex-encoded signature to verify.
true if the signature is valid, false otherwise.
Hash a password with Argon2id using safe defaults.
Password to hash (UTF-8 string or raw bytes).
Hash result with hex-encoded hash, salt, params, and PHC string.
Verify a password against an Argon2id hash.
Verification options containing password, hash, salt, and params.
Object with valid boolean indicating whether the password matches.
Verify a password against a PHC-format hash string.
Password to verify (UTF-8 string or raw bytes).
PHC-format hash string (e.g., $argon2id$v=19$...).
Object with valid boolean indicating whether the password matches.
Compute an HMAC.
HMAC algorithm (e.g., "sha256", "sha512").
Hex-encoded key or raw bytes.
Data to authenticate (UTF-8 string or bytes).
Hex-encoded MAC.
Verify an HMAC.
Verification options containing algorithm, key, data, and mac.
true if the MAC is valid, false otherwise.
Readonlyregistry: {Algorithm registry helpers.
Readonlyget: (idOrAlias: string) => AlgorithmInfo | undefinedLook up an algorithm by name.
Readonlylist: (List all registered algorithms, optionally filtered by category.
Get the recommended algorithm for a category.
Check whether an algorithm is deprecated.
Unified crypto namespace.