Skip to content

Variable: Envelope ​

const Envelope: object

Defined in: envelope.ts:118

Authenticated public-key encryption: hybrid KEM + AES-256-GCM, interoperable with quantum-safe-py's Envelope.

Type Declaration ​

open() ​

readonly open(sealed, secretKey, options?): Uint8Array

Decrypts a sealed message. The returned plaintext is a copy in the JS heap: wipe it with wipe() when it is sensitive and no longer needed.

The AAD travels inside the message and is checked for tampering, but anyone holding the recipient's public key can seal a message with any AAD. To bind a message to a context (a user id, a record id) pass options.expectedAad: opening then fails unless the message's AAD equals it. This is anonymous encryption: it does not tell you who sent the message (sign it separately for that).

Parameters ​

sealed ​

Uint8Array<ArrayBufferLike> | SealedMessage

secretKey ​

SecretKey

options? ​
expectedAad? ​

Uint8Array<ArrayBufferLike>

Returns ​

Uint8Array

Throws ​

on a wrong key, wrong AAD, an AAD that differs from expectedAad, or any tampering.

Throws ​

if the message is structurally invalid.

seal() ​

readonly seal(plaintext, publicKey, options?): SealedMessage

Encrypts plaintext to publicKey.

Parameters ​

plaintext ​

Uint8Array

publicKey ​

PublicKey

options? ​

SealOptions = {}

Returns ​

SealedMessage

Throws ​

if the key is a pure (non-hybrid) KEM key.

Example ​

ts
const kem = new HybridKEM();
using pair = kem.generateKeyPair();
const sealed = Envelope.seal(utf8('secret'), pair.publicKey, { aad: utf8('item-42') });
const plain = Envelope.open(sealed, pair.secretKey); // Uint8Array

Apache-2.0.