Skip to content

Class: SecretKey ​

Defined in: keys.ts:129

A secret key (KEM or signature), held in WASM memory. Call SecretKey.free (or use using) when finished: it wipes the key material. Never log or serialize it casually.

Copies you extract with SecretKey.exportBytes, toCbor() or toPem() live in the JavaScript heap, outside this library's control; wipe them with wipe() after use.

Accessors ​

algorithm ​

Get Signature ​

get algorithm(): string

Defined in: keys.ts:150

Returns ​

string


migrationState ​

Get Signature ​

get migrationState(): MigrationState

Defined in: keys.ts:153

Returns ​

MigrationState

Methods ​

[dispose]() ​

[dispose](): void

Defined in: keys.ts:175

Returns ​

void


exportBytes() ​

exportBytes(): Uint8Array

Defined in: keys.ts:157

Copies the raw secret key bytes out of WASM memory. Wipe the copy after use.

Returns ​

Uint8Array


free() ​

free(): void

Defined in: keys.ts:172

Returns ​

void


toCbor() ​

toCbor(): Uint8Array

Defined in: keys.ts:161

CBOR serialization. Contains the secret; handle accordingly.

Returns ​

Uint8Array


toJSON() ​

toJSON(): object

Defined in: keys.ts:183

Never reveals key material.

Returns ​

object

redacted ​

redacted: true

type ​

type: "SecretKey"


toPem() ​

toPem(): string

Defined in: keys.ts:165

PEM serialization. Contains the secret; handle accordingly.

Returns ​

string


toString() ​

toString(): string

Defined in: keys.ts:179

Never reveals key material.

Returns ​

string


fromBytes() ​

static fromBytes(algorithm, raw, migrationState?): SecretKey

Defined in: keys.ts:137

Parameters ​

algorithm ​

string

raw ​

Uint8Array

migrationState? ​

MigrationState

Returns ​

SecretKey


fromCbor() ​

static fromCbor(data): SecretKey

Defined in: keys.ts:142

Parameters ​

data ​

Uint8Array

Returns ​

SecretKey


fromPem() ​

static fromPem(pem): SecretKey

Defined in: keys.ts:146

Parses a QUANTUM SAFE SECRET KEY PEM. The PEM text itself contains the secret.

Parameters ​

pem ​

string

Returns ​

SecretKey

Apache-2.0.