{"_id":"@adatechnology/secret-envelope","name":"@adatechnology/secret-envelope","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@adatechnology/secret-envelope","version":"0.1.0","description":"Versioned authenticated secret envelopes for Bun applications","type":"module","main":"dist/index.js","types":"dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"sideEffects":false,"engines":{"bun":">=1.3.0"},"keywords":["aes-gcm","bun","cryptography","encryption","secrets"],"author":{"name":"Ada Technology"},"license":"MIT","publishConfig":{"access":"public"},"devDependencies":{"@types/bun":"1.3.14","tsup":"^8.5.1","typescript":"^5.9.3"},"scripts":{"build":"tsup","check":"tsc --noEmit","test":"bun test test/secret-envelope.contract.test.ts ./test/package.integration.ts","format":"prettier --write package.json README.md src test tsconfig.json tsup.config.ts","format:check":"prettier --check package.json README.md src test tsconfig.json tsup.config.ts"},"_id":"@adatechnology/secret-envelope@0.1.0","_integrity":"sha512-opFaXbrisCrqeIqXDjz+KapafRj4g5SfaOIofyrjiuKhSzynm9644lupH0ZrPALnch8Jjp3cSqnXUMOvPAJm2Q==","_resolved":"/tmp/29a5520515d79c4b21ebdee0c1173fdb/adatechnology-secret-envelope-0.1.0.tgz","_from":"file:adatechnology-secret-envelope-0.1.0.tgz","_nodeVersion":"22.23.1","_npmVersion":"10.9.8","dist":{"integrity":"sha512-opFaXbrisCrqeIqXDjz+KapafRj4g5SfaOIofyrjiuKhSzynm9644lupH0ZrPALnch8Jjp3cSqnXUMOvPAJm2Q==","shasum":"e1a5bfafe9ddd197570971c67e0594481520da2c","tarball":"https://registry.npmjs.org/@adatechnology/secret-envelope/-/secret-envelope-0.1.0.tgz","fileCount":4,"unpackedSize":16325,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDUDUxGvVl7QvaSXFf1z6A8loK6xmfPyj4pmUbLuTt/gAIgF8Y3u5bEVbrMOPzh9UqLqtYyWhgTQDsxG9lJX5gcbuo="}]},"_npmUser":{"name":"miyazaki","email":"andersonfrfilho@gmail.com"},"directories":{},"maintainers":[{"name":"miyazaki","email":"andersonfrfilho@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/secret-envelope_0.1.0_1784495760206_0.07611664584756928"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-19T21:15:59.972Z","0.1.0":"2026-07-19T21:16:00.352Z","modified":"2026-07-19T21:16:00.642Z"},"maintainers":[{"name":"miyazaki","email":"andersonfrfilho@gmail.com"}],"description":"Versioned authenticated secret envelopes for Bun applications","keywords":["aes-gcm","bun","cryptography","encryption","secrets"],"author":{"name":"Ada Technology"},"license":"MIT","readme":"# @adatechnology/secret-envelope\n\nVersioned authenticated secret envelopes for Bun applications.\n\n## Contract\n\n- AES-256-GCM through Web Crypto;\n- 32-byte keys and a 12-byte random nonce;\n- mandatory additional authenticated data;\n- authenticated framing uses the domain `adatechnology:secret-envelope` followed\n  by length-prefixed version, algorithm, key ID, and caller AAD fields;\n- canonical base64url envelope with an explicit version, algorithm, and key ID;\n- ciphertext stores the Web Crypto result as `ciphertext || 16-byte tag`;\n- plaintext is limited to 1 MiB and malformed/oversized envelopes fail closed;\n- provider creation snapshots caller-owned key bytes;\n- key rotation without fallback to unrelated keys;\n- typed errors that never include keys, plaintext, AAD, or envelopes;\n- no runtime dependencies or internal logging.\n\n```ts\nimport { createSecretEnvelopeProvider } from '@adatechnology/secret-envelope'\n\nconst provider = createSecretEnvelopeProvider({\n  activeKeyId: 'local-v1',\n  keys: {\n    'local-v1': crypto.getRandomValues(new Uint8Array(32)),\n  },\n})\n\nconst envelope = await provider.encrypt({\n  plaintext: new TextEncoder().encode('secret'),\n  additionalAuthenticatedData: new TextEncoder().encode('resource:v1'),\n})\n```\n\nThe caller owns key loading, AAD construction, storage, and secret lifecycle.\n","readmeFilename":"README.md","_rev":"1-0ce7cc1c3f28fd7d7c1d5dbd65a13287"}