Crypto Lib
    Preparing search index...

    Variable cryptoConst

    crypto: {
        randomKey(): string;
        encrypt(
            key: string | Uint8Array<ArrayBufferLike>,
            plaintext: string | Uint8Array<ArrayBufferLike>,
        ): string;
        decrypt(
            key: string | Uint8Array<ArrayBufferLike>,
            ciphertext: string,
        ): Uint8Array;
        hash(
            algorithm:
                | "sha256"
                | "sha384"
                | "sha512"
                | "sha3-256"
                | "sha3-512"
                | "blake2b"
                | "blake3",
            data: string | Uint8Array<ArrayBufferLike>,
        ): string;
        generateKeyPair(
            algorithm:
                | "ed25519"
                | "x25519"
                | "ed448"
                | "x448"
                | "p256"
                | "p384"
                | "ml-kem-512"
                | "ml-kem-768"
                | "ml-kem-1024"
                | "ml-dsa-44"
                | "ml-dsa-65"
                | "ml-dsa-87",
            metadata?: KeyMetadata,
        ): GeneratedKeyPair;
        sign(
            algorithm: SignAlgorithm,
            privateKeyHex: string,
            message: string | Uint8Array<ArrayBufferLike>,
        ): string;
        verify(
            algorithm: SignAlgorithm,
            publicKeyHex: string,
            message: string | Uint8Array<ArrayBufferLike>,
            signatureHex: string,
        ): boolean;
        hashPassword(
            password: string | Uint8Array<ArrayBufferLike>,
        ): HashPasswordResult;
        verifyPassword(options: VerifyPasswordOptions): VerifyPasswordResult;
        verifyPasswordPhc(
            password: string | Uint8Array<ArrayBufferLike>,
            phc: string,
        ): VerifyPasswordResult;
        hmac(
            algorithm: "sha256" | "sha384" | "sha512" | "sha3-256" | "sha3-512",
            key: string | Uint8Array<ArrayBufferLike>,
            data: string | Uint8Array<ArrayBufferLike>,
        ): string;
        hmacVerify(options: HmacVerifyOptions): boolean;
        registry: {
            get: (idOrAlias: string) => AlgorithmInfo | undefined;
            list: (
                filters?: { category?: AlgorithmCategory; status?: AlgorithmStatus },
            ) => AlgorithmInfo[];
            recommended: (category?: AlgorithmCategory) => AlgorithmInfo[];
            isDeprecated: (idOrAlias: string) => boolean;
        };
    } = ...

    Unified crypto namespace.

    Type Declaration

    • randomKey: function
      • Generate a random 256-bit key (hex string).

        Returns string

        A 64-character hex string representing 32 random bytes.

        const key = crypto.randomKey(); // "a1b2c3...64 hex chars"
        
    • encrypt: function
      • Encrypt plaintext with a 256-bit key (secretbox: XChaCha20-Poly1305).

        Parameters

        • key: string | Uint8Array<ArrayBufferLike>

          256-bit key as hex string or Uint8Array.

        • plaintext: string | Uint8Array<ArrayBufferLike>

          Data to encrypt (UTF-8 string or bytes).

        Returns string

        Base64-encoded ciphertext (nonce prepended).

        const ct = crypto.encrypt(key, "Hello, world!");
        
    • decrypt: function
      • Decrypt ciphertext with a 256-bit key.

        Parameters

        • key: string | Uint8Array<ArrayBufferLike>

          256-bit key as hex string or Uint8Array.

        • ciphertext: string

          Base64-encoded ciphertext (as returned by encrypt).

        Returns Uint8Array

        Decrypted plaintext bytes.

        const pt = crypto.decrypt(key, ciphertext);
        const text = Buffer.from(pt).toString("utf8");
    • hash: function
      • Hash data with the specified algorithm.

        Parameters

        • algorithm: "sha256" | "sha384" | "sha512" | "sha3-256" | "sha3-512" | "blake2b" | "blake3"

          Hash algorithm (e.g., "sha3-256", "sha256", "blake3").

        • data: string | Uint8Array<ArrayBufferLike>

          Data to hash (UTF-8 string or bytes).

        Returns string

        Hex-encoded hash digest.

        const h = crypto.hash("sha3-256", "hello");
        
    • generateKeyPair: function
      • Generate a key pair for any supported algorithm.

        Parameters

        • algorithm:
              | "ed25519"
              | "x25519"
              | "ed448"
              | "x448"
              | "p256"
              | "p384"
              | "ml-kem-512"
              | "ml-kem-768"
              | "ml-kem-1024"
              | "ml-dsa-44"
              | "ml-dsa-65"
              | "ml-dsa-87"

          Key algorithm identifier (e.g., "ed25519", "ml-dsa-65").

        • Optionalmetadata: KeyMetadata

          Optional metadata (kid, use, exp) to attach.

        Returns GeneratedKeyPair

        Generated key pair with public/private keys, algorithm, kid, metadata.

        const kp = crypto.generateKeyPair("ed25519");
        console.log(kp.publicKey, kp.privateKey);
    • sign: function
      • Sign a message with any supported signing algorithm.

        Parameters

        • algorithm: SignAlgorithm

          Signing algorithm (e.g., "ed25519", "schnorr", "ml-dsa-65").

        • privateKeyHex: string

          Hex-encoded private key.

        • message: string | Uint8Array<ArrayBufferLike>

          Message to sign (UTF-8 string or bytes).

        Returns string

        Hex-encoded signature.

        If the algorithm is not supported.

        const sig = crypto.sign("ed25519", kp.privateKey, "hello");
        
    • verify: function
      • Verify a signature with any supported signing algorithm.

        Parameters

        • algorithm: SignAlgorithm

          Signing algorithm (e.g., "ed25519", "schnorr", "ml-dsa-65").

        • publicKeyHex: string

          Hex-encoded public key.

        • message: string | Uint8Array<ArrayBufferLike>

          Original message that was signed (UTF-8 string or bytes).

        • signatureHex: string

          Hex-encoded signature to verify.

        Returns boolean

        true if the signature is valid, false otherwise.

        If the algorithm is not supported.

        const valid = crypto.verify("ed25519", kp.publicKey, "hello", sig);
        
    • hashPassword: function
      • Hash a password with Argon2id using safe defaults.

        Parameters

        • password: string | Uint8Array<ArrayBufferLike>

          Password to hash (UTF-8 string or raw bytes).

        Returns HashPasswordResult

        Hash result with hex-encoded hash, salt, params, and PHC string.

        const result = crypto.hashPassword("hunter2");
        console.log(result.phc); // "$argon2id$v=19$m=65536,t=3,p=4$..."
    • verifyPassword: function
      • Verify a password against an Argon2id hash.

        Parameters

        Returns VerifyPasswordResult

        Object with valid boolean indicating whether the password matches.

        const { valid } = crypto.verifyPassword({
        password: "hunter2",
        hash: result.hash,
        salt: result.salt,
        params: result.params,
        });
    • verifyPasswordPhc: function
      • Verify a password against a PHC-format hash string.

        Parameters

        • password: string | Uint8Array<ArrayBufferLike>

          Password to verify (UTF-8 string or raw bytes).

        • phc: string

          PHC-format hash string (e.g., $argon2id$v=19$...).

        Returns VerifyPasswordResult

        Object with valid boolean indicating whether the password matches.

        const { valid } = crypto.verifyPasswordPhc("hunter2", result.phc);
        
    • hmac: function
      • Compute an HMAC.

        Parameters

        • algorithm: "sha256" | "sha384" | "sha512" | "sha3-256" | "sha3-512"

          HMAC algorithm (e.g., "sha256", "sha512").

        • key: string | Uint8Array<ArrayBufferLike>

          Hex-encoded key or raw bytes.

        • data: string | Uint8Array<ArrayBufferLike>

          Data to authenticate (UTF-8 string or bytes).

        Returns string

        Hex-encoded MAC.

        const mac = crypto.hmac("sha256", key, "authenticate me");
        
    • hmacVerify: function
      • Verify an HMAC.

        Parameters

        • options: HmacVerifyOptions

          Verification options containing algorithm, key, data, and mac.

        Returns boolean

        true if the MAC is valid, false otherwise.

        const valid = crypto.hmacVerify({
        algorithm: "sha256",
        key,
        data: "authenticate me",
        mac,
        });
    • Readonlyregistry: {
          get: (idOrAlias: string) => AlgorithmInfo | undefined;
          list: (
              filters?: { category?: AlgorithmCategory; status?: AlgorithmStatus },
          ) => AlgorithmInfo[];
          recommended: (category?: AlgorithmCategory) => AlgorithmInfo[];
          isDeprecated: (idOrAlias: string) => boolean;
      }

      Algorithm registry helpers.

      • Readonlyget: (idOrAlias: string) => AlgorithmInfo | undefined

        Look up an algorithm by name.

      • Readonlylist: (
            filters?: { category?: AlgorithmCategory; status?: AlgorithmStatus },
        ) => AlgorithmInfo[]

        List all registered algorithms, optionally filtered by category.

      • recommended: (category?: AlgorithmCategory) => AlgorithmInfo[]

        Get the recommended algorithm for a category.

      • isDeprecated: (idOrAlias: string) => boolean

        Check whether an algorithm is deprecated.