Description Hash functions
Hashes
Algorithms
Operations
init() -> ctx
update(ctx, data)
copy(ctx) -> ctx
finalize(ctx) -> digest
Extendable-output functions
Algorithms
Operations
init() -> ctx
update(ctx, data)
copy(ctx) -> ctx
finalize(ctx, length) -> bytes
squeeze(ctx, n) -> bytes
Message authentication codes
Block ciphers
ECB mode
Algorithms
Operations
init(key, direction) -> ctx
update(ctx, data) -> bytes
finalize(ctx) -> bytes
IV-based modes
Algorithms
Operations
init(key, iv, direction) -> ctx
update(ctx, data) -> bytes
finalize(ctx) -> bytes
CTR mode
Algorithms
Operations
init(key, nonce) -> ctx
update(ctx, data) -> bytes
finalize(ctx) -> bytes
reset_nonce(ctx, nonce)
AES-XTS
init(key, tweak, direction) -> ctx
update(ctx, data) -> bytes
finalize(ctx) -> bytes
Stream ciphers
Authenticated encryption
Streaming GCM
Algorithms
Operations
init(key, iv, direction) -> ctx
update_aad(ctx, aad)
update(ctx, data) -> bytes
set_tag(ctx, tag)
finalize(ctx) -> bytes
get_tag(ctx) -> tag
One-shot AEADs
Algorithms
Operations
init(key) -> ctx
encrypt(ctx, nonce, aad, plaintext) -> ciphertext
decrypt(ctx, nonce, aad, ciphertext) -> plaintext
One-shot AEADs with configurable tag length
Algorithms
Operations
init(key, tag_length) -> ctx
encrypt(ctx, nonce, aad, plaintext) -> ciphertext
decrypt(ctx, nonce, aad, ciphertext) -> plaintext
AES-SIV
init(key) -> ctx
encrypt(ctx, nonce, [aad], plaintext) -> ciphertext
decrypt(ctx, nonce, [aad], ciphertext) -> plaintext
Password-based key derivation
PBKDF2-HMAC-{hash}
derive(password, salt, iterations, length) -> key
scrypt
derive(password, salt, n, r, p, max_memory, length) -> key
Argon2
Algorithms
Operations
derive(password, salt, iterations, memory_cost, lanes, threads, secret, associated_data, length) -> key
RSA
RSA keys
generate(bits, public_exponent) -> private_key
from_components(n, e) -> public_key
from_components(n, e, d, p, q, dmp1, dmq1, iqmp) -> private_key
to_components(key) -> (n, e, [d, p, q, dmp1, dmq1, iqmp])
RSASSA-PKCS1-v1_5
sign(private_key, digest, hash) -> signature
verify(public_key, signature, digest, hash) -> bool
recover(public_key, signature, hash) -> data
RSASSA-PSS
sign(private_key, digest, hash, mgf1_hash, salt_length) -> signature
verify(public_key, signature, digest, hash, mgf1_hash, salt_length) -> bool
RSAES-PKCS1-v1_5
encrypt(public_key, plaintext) -> ciphertext
decrypt(private_key, ciphertext) -> plaintext
RSAES-OAEP
encrypt(public_key, plaintext, hash, mgf1_hash, label) -> ciphertext
decrypt(private_key, ciphertext, hash, mgf1_hash, label) -> plaintext
Elliptic curves
EC keys
Algorithms
Operations
generate(curve) -> private_key
from_private_scalar(curve, d) -> private_key
from_components(curve, d, x, y) -> private_key
from_encoded_point(curve, bytes) -> public_key
encode_point(public_key, compressed) -> bytes
to_components(key) -> (x, y, [d])
ECDSA
sign(private_key, digest) -> signature
sign_deterministic(private_key, digest, hash) -> signature
verify(public_key, signature, digest) -> bool
ECDH
exchange(private_key, peer_public_key) -> shared_secret
Edwards and Montgomery curves
EdDSA
Algorithms
Operations
generate() -> private_key
from_private_bytes(bytes) -> private_key
from_public_bytes(bytes) -> public_key
private_bytes(private_key) -> bytes
public_bytes(public_key) -> bytes
sign(private_key, message) -> signature
verify(public_key, signature, message) -> bool
Montgomery key exchange
Algorithms
Operations
generate() -> private_key
from_private_bytes(bytes) -> private_key
from_public_bytes(bytes) -> public_key
private_bytes(private_key) -> bytes
public_bytes(public_key) -> bytes
exchange(private_key, peer_public_key) -> shared_secret
Finite-field Diffie-Hellman
DH
generate_parameters(bits, generator) -> params
parameters_from(p, g, [q]) -> params
generate(params) -> private_key
from_components(params, y, [x]) -> key
to_components(key) -> (p, g, [q], y, [x])
exchange(private_key, peer_public_key) -> shared_secret
DSA
DSA
generate_parameters(bits) -> params
generate(params) -> private_key
from_components(p, q, g, y, [x]) -> key
to_components(key) -> (p, q, g, y, [x])
sign(private_key, digest) -> signature
verify(public_key, signature, digest) -> bool
ML-KEM
ML-KEM
Algorithms
Operations
from_seed(seed) -> private_key
seed(private_key) -> bytes
from_public_bytes(bytes) -> public_key
public_bytes(public_key) -> bytes
encapsulate(public_key) -> (ciphertext, shared_secret)
decapsulate(private_key, ciphertext) -> shared_secret
ML-DSA
ML-DSA
Algorithms
Operations
from_seed(seed) -> private_key
seed(private_key) -> bytes
from_public_bytes(bytes) -> public_key
public_bytes(public_key) -> bytes
sign(private_key, message, context) -> signature
verify(public_key, signature, message, context) -> bool
sign_mu(private_key, mu) -> signature
verify_mu(public_key, signature, mu) -> bool
Reactions are currently unavailable
You can’t perform that action at this time.
Hash functions
init() -> ctxupdate(ctx, data)copy(ctx) -> ctxfinalize(ctx) -> digestinit() -> ctxupdate(ctx, data)copy(ctx) -> ctxfinalize(ctx, length) -> bytessqueeze(ctx, n) -> bytesMessage authentication codes
init(key) -> ctxupdate(ctx, data)copy(ctx) -> ctxfinalize(ctx) -> taginit(key) -> ctxupdate(ctx, data)copy(ctx) -> ctxfinalize(ctx) -> taginit(key) -> ctxupdate(ctx, data)finalize(ctx) -> tagBlock ciphers
init(key, direction) -> ctxupdate(ctx, data) -> bytesfinalize(ctx) -> bytesinit(key, iv, direction) -> ctxupdate(ctx, data) -> bytesfinalize(ctx) -> bytesinit(key, nonce) -> ctxupdate(ctx, data) -> bytesfinalize(ctx) -> bytesreset_nonce(ctx, nonce)init(key, tweak, direction) -> ctxupdate(ctx, data) -> bytesfinalize(ctx) -> bytesStream ciphers
init(key, nonce) -> ctxupdate(ctx, data) -> bytesreset_nonce(ctx, nonce)init(key) -> ctxupdate(ctx, data) -> bytesAuthenticated encryption
init(key, iv, direction) -> ctxupdate_aad(ctx, aad)update(ctx, data) -> bytesset_tag(ctx, tag)finalize(ctx) -> bytesget_tag(ctx) -> taginit(key) -> ctxencrypt(ctx, nonce, aad, plaintext) -> ciphertextdecrypt(ctx, nonce, aad, ciphertext) -> plaintextinit(key, tag_length) -> ctxencrypt(ctx, nonce, aad, plaintext) -> ciphertextdecrypt(ctx, nonce, aad, ciphertext) -> plaintextinit(key) -> ctxencrypt(ctx, nonce, [aad], plaintext) -> ciphertextdecrypt(ctx, nonce, [aad], ciphertext) -> plaintextPassword-based key derivation
derive(password, salt, iterations, length) -> keyderive(password, salt, n, r, p, max_memory, length) -> keyderive(password, salt, iterations, memory_cost, lanes, threads, secret, associated_data, length) -> keyRSA
generate(bits, public_exponent) -> private_keyfrom_components(n, e) -> public_keyfrom_components(n, e, d, p, q, dmp1, dmq1, iqmp) -> private_keyto_components(key) -> (n, e, [d, p, q, dmp1, dmq1, iqmp])sign(private_key, digest, hash) -> signatureverify(public_key, signature, digest, hash) -> boolrecover(public_key, signature, hash) -> datasign(private_key, digest, hash, mgf1_hash, salt_length) -> signatureverify(public_key, signature, digest, hash, mgf1_hash, salt_length) -> boolencrypt(public_key, plaintext) -> ciphertextdecrypt(private_key, ciphertext) -> plaintextencrypt(public_key, plaintext, hash, mgf1_hash, label) -> ciphertextdecrypt(private_key, ciphertext, hash, mgf1_hash, label) -> plaintextElliptic curves
generate(curve) -> private_keyfrom_private_scalar(curve, d) -> private_keyfrom_components(curve, d, x, y) -> private_keyfrom_encoded_point(curve, bytes) -> public_keyencode_point(public_key, compressed) -> bytesto_components(key) -> (x, y, [d])sign(private_key, digest) -> signaturesign_deterministic(private_key, digest, hash) -> signatureverify(public_key, signature, digest) -> boolexchange(private_key, peer_public_key) -> shared_secretEdwards and Montgomery curves
generate() -> private_keyfrom_private_bytes(bytes) -> private_keyfrom_public_bytes(bytes) -> public_keyprivate_bytes(private_key) -> bytespublic_bytes(public_key) -> bytessign(private_key, message) -> signatureverify(public_key, signature, message) -> boolgenerate() -> private_keyfrom_private_bytes(bytes) -> private_keyfrom_public_bytes(bytes) -> public_keyprivate_bytes(private_key) -> bytespublic_bytes(public_key) -> bytesexchange(private_key, peer_public_key) -> shared_secretFinite-field Diffie-Hellman
generate_parameters(bits, generator) -> paramsparameters_from(p, g, [q]) -> paramsgenerate(params) -> private_keyfrom_components(params, y, [x]) -> keyto_components(key) -> (p, g, [q], y, [x])exchange(private_key, peer_public_key) -> shared_secretDSA
generate_parameters(bits) -> paramsgenerate(params) -> private_keyfrom_components(p, q, g, y, [x]) -> keyto_components(key) -> (p, q, g, y, [x])sign(private_key, digest) -> signatureverify(public_key, signature, digest) -> boolML-KEM
from_seed(seed) -> private_keyseed(private_key) -> bytesfrom_public_bytes(bytes) -> public_keypublic_bytes(public_key) -> bytesencapsulate(public_key) -> (ciphertext, shared_secret)decapsulate(private_key, ciphertext) -> shared_secretML-DSA
from_seed(seed) -> private_keyseed(private_key) -> bytesfrom_public_bytes(bytes) -> public_keypublic_bytes(public_key) -> bytessign(private_key, message, context) -> signatureverify(public_key, signature, message, context) -> boolsign_mu(private_key, mu) -> signatureverify_mu(public_key, signature, mu) -> bool