AbsoluteJS

@absolutejs/secure-transfer-webcrypto

@absolutejs/secure-transfer-webcryptov0.1.1betaPlatform & Infra

WebCrypto AES-256-GCM authenticated-record provider for @absolutejs/secure-transfer.

#Installation

BASH
bun add @absolutejs/secure-transfer-webcrypto

#Capabilities

Overview

Interchangeable WebCrypto provider for @absolutejs/secure-transfer. Each transfer receives fresh random AES-256-GCM key material and a 96-bit nonce base. Every record nonce is derived by XORing that base with the record sequence, following the construction used by RFC 8188. Record metadata is authenticated as additional data.

Protect resumable-upload receipts with a separate root key:

Persist that root key in a platform keystore rather than regenerating it. It is imported as a non-exportable HKDF key, derives an isolated AES-256-GCM key for each receipt ID, and uses a fresh 96-bit nonce for every checkpoint. Do not reuse the transfer content key as the receipt root key.

Show 3 more

The capability contains the content key and nonce base. It is a bearer secret and must only appear inside an E2EE-protected transfer descriptor. This provider does not store or distribute capabilities.

The provider caps plaintext records at 16 MiB and the number of records at 1,048,576. Applications should normally choose smaller records for bounded memory and resumability.

This is an experimental 0.x release without an independent audit. Run bun run certify:browser from the repository root to repeat the real Chromium round-trip and context-substitution gate.

Outcomes

What you can build

Build on the supported package contract

Use @absolutejs/secure-transfer-webcrypto through its supported public entry points.

Hardening checklist

Production guidance

Make every external boundary explicitPin the deployed @absolutejs/secure-transfer-webcrypto version, replace example or memory-backed dependencies with durable implementations, bound external calls, protect credentials, and emit enough evidence to retry or recover safely.

Follow in order

Troubleshooting path

1
Trace from the first failed boundary
Reproduce the smallest canonical @absolutejs/secure-transfer-webcrypto example, confirm the supported entry point and version in the API explorer, then inspect the first boundary that did not produce its documented result.

#@absolutejs/secure-transfer-webcrypto quick start

Partial snippet

# @absolutejs/secure-transfer-webcrypto

TS
import { createSecureTransferWebcryptoProvider } from "@absolutejs/secure-transfer-webcrypto";

const cryptoProvider = createSecureTransferWebcryptoProvider();

#@absolutejs/secure-transfer-webcrypto quick start 2

Partial snippet

# @absolutejs/secure-transfer-webcrypto

TS
const receiptProtector = await createSecureTransferWebcryptoReceiptProtector({
  key: crypto.getRandomValues(new Uint8Array(32)),
});

#Public entry points

Supported entry points declared by this package manifest.

Package entry point declared in package.json.

@absolutejs/secure-transfer-webcrypto@absolutejs/secure-transfer-webcrypto/provider-manifest@absolutejs/secure-transfer-webcrypto/manifest@absolutejs/secure-transfer-webcrypto/manifest.json

#Package commands

Scripts declared by this package manifest.

bun run buildrm -rf dist && bun build src/index.ts src/provider-manifest.ts src/manifest.ts --outdir dist --root src --sourcemap --target=browser --external @absolutejs/secure-transfer --external @absolutejs/manifest --external @sinclair/typebox && tsc --project tsconfig.build.json && absolute-manifest emit
bun run check:packagebun run format && bun run typecheck && bun run test && bun run build && bun run verify-package
bun run formatprettier --write "./**/*.{ts,json,md}"
bun run testbun test tests/
bun run typechecktsc --noEmit

#API reference

Search the declarations exported by the current package type files. Expand a symbol to inspect its source-backed signature.

6 symbols
SecureTransferWebcryptoErrorclassPermalinkSource
TS
class SecureTransferWebcryptoError extends Error {
    readonly name = "SecureTransferWebcryptoError";
}
Exported from @absolutejs/secure-transfer-webcrypto