Encrypt plaintext using AEAD (AES-GCM or XChaCha20-Poly1305).
Decrypt ciphertext and return the original plaintext.
Compute a cryptographic hash digest.
Derive a key from a password using a KDF algorithm.
Compute a message authentication code (HMAC or KMAC).
Verify a message authentication code.
Hash a password using Argon2.
Verify a password against a stored Argon2 hash.
Generate a new asymmetric key pair.
Optionalparams: { algorithm?: string; metadata?: Record<string, string> }Sign a message with a private key.
Verify a digital signature against a public key.
Generate a hybrid X25519+ML-KEM key pair.
Encapsulate a shared secret using hybrid KEM.
Decapsulate a shared secret using hybrid KEM.
Sign a message using ML-DSA (FIPS 204).
Verify an ML-DSA signature.
Generate an ML-DSA key pair.
Sign a message using SLH-DSA (FIPS 205).
Verify an SLH-DSA signature.
Generate an SLH-DSA key pair.
Seal plaintext with symmetric authenticated encryption (XChaCha20-Poly1305).
Open a secretbox sealed ciphertext.
Seal plaintext with anonymous public-key encryption.
Open a sealed box ciphertext with the recipient's secret key.
Encrypt plaintext with a password (Argon2 + AEAD).
Decrypt password-encrypted ciphertext.
Wrap (encrypt) a key with a key-encryption key.
Unwrap (decrypt) a wrapped key.
List all supported algorithms by category.
Check API server health.
Typed HTTP client for the Crypto Service Suite v2 API.
Example