{"_id":"@aithos/assets-crypto","_rev":"2-5cc724d52ac6e1257355d08767e81631","name":"@aithos/assets-crypto","dist-tags":{"alpha":"0.1.0-alpha.1","latest":"0.1.0-alpha.2"},"versions":{"0.1.0-alpha.1":{"name":"@aithos/assets-crypto","version":"0.1.0-alpha.1","keywords":["aithos","assets","pds","personal-data-server","encryption","x25519","xchacha20poly1305","envelope-encryption","file-encryption"],"author":{"name":"Mathieu Colla","email":"mathieu.colla.pro@gmail.com"},"license":"Apache-2.0","_id":"@aithos/assets-crypto@0.1.0-alpha.1","maintainers":[{"name":"aithos","email":"mathieu@aithos.be"}],"homepage":"https://github.com/aithos-protocol/aithos-protocol#readme","bugs":{"url":"https://github.com/aithos-protocol/aithos-protocol/issues"},"dist":{"shasum":"8dc4f5dadc2928cf4407b1d68549f82afc2e7b7e","tarball":"https://registry.npmjs.org/@aithos/assets-crypto/-/assets-crypto-0.1.0-alpha.1.tgz","fileCount":15,"integrity":"sha512-aOnRIUQS/dM/E2zjyQxZnx/jaNpqI/NvAGYRtB2nGrz8+uc4AKTBPJUBDuoDDiPqdxvJ90bFi2mfYex4/nZEdQ==","signatures":[{"sig":"MEUCIGl7VziroNAdw9OOIuCKGWYSfsQm9D8hr700MRQucHczAiEA/EWbRAMJX7KRdiElE85W74bRqDyl7dcYKlJgYIAftew=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":47896},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./aad":{"types":"./dist/aad.d.ts","import":"./dist/aad.js"},"./amk":{"types":"./dist/amk.d.ts","import":"./dist/amk.js"},"./asset":{"types":"./dist/asset.d.ts","import":"./dist/asset.js"},"./types":{"types":"./dist/types.d.ts","import":"./dist/types.js"}},"gitHead":"916085f310b0cc590778e51f1250d6b8472a9d68","scripts":{"test":"node --import tsx --test --test-reporter=spec \"test/**/*.test.ts\"","build":"tsc -p tsconfig.json","clean":"rm -rf dist","check-types":"tsc --noEmit"},"_npmUser":{"name":"aithos","email":"mathieu@aithos.be"},"repository":{"url":"git+https://github.com/aithos-protocol/aithos-protocol.git","type":"git","directory":"packages/assets-crypto"},"_npmVersion":"10.9.2","description":"Reference cryptographic primitives for the Aithos assets sub-protocol: AMK generation, X25519-HKDF-AEAD wraps, XChaCha20-Poly1305 byte encryption. See spec/assets/.","directories":{},"_nodeVersion":"23.9.0","dependencies":{"@scure/base":"^1.1.6","@noble/curves":"^2.2.0","@noble/hashes":"^1.4.0","@stablelib/hkdf":"^2.0.1","@stablelib/sha256":"^2.0.1","@stablelib/xchacha20poly1305":"^2.0.1"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.11.0","typescript":"^5.5.0","@types/node":"^20.11.0"},"_npmOperationalInternal":{"tmp":"tmp/assets-crypto_0.1.0-alpha.1_1779805386271_0.8381700014130691","host":"s3://npm-registry-packages-npm-production"}},"0.1.0-alpha.2":{"name":"@aithos/assets-crypto","version":"0.1.0-alpha.2","description":"Reference cryptographic primitives for the Aithos assets sub-protocol: AMK generation, X25519-HKDF-AEAD wraps, XChaCha20-Poly1305 byte encryption. See spec/assets/.","license":"Apache-2.0","author":{"name":"Mathieu Colla","email":"mathieu.colla.pro@gmail.com"},"homepage":"https://github.com/aithos-protocol/aithos-protocol#readme","repository":{"type":"git","url":"git+https://github.com/aithos-protocol/aithos-protocol.git","directory":"packages/assets-crypto"},"keywords":["aithos","assets","pds","personal-data-server","encryption","x25519","xchacha20poly1305","envelope-encryption","file-encryption"],"type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./amk":{"types":"./dist/amk.d.ts","import":"./dist/amk.js"},"./asset":{"types":"./dist/asset.d.ts","import":"./dist/asset.js"},"./aad":{"types":"./dist/aad.d.ts","import":"./dist/aad.js"},"./types":{"types":"./dist/types.d.ts","import":"./dist/types.js"}},"scripts":{"build":"tsc -p tsconfig.json","check-types":"tsc --noEmit","clean":"rm -rf dist","test":"node --import tsx --test --test-reporter=spec \"test/**/*.test.ts\""},"dependencies":{"@noble/curves":"^2.2.0","@noble/hashes":"^1.4.0","@stablelib/xchacha20poly1305":"^2.0.1","@stablelib/hkdf":"^2.0.1","@stablelib/sha256":"^2.0.1","@scure/base":"^1.1.6"},"devDependencies":{"@types/node":"^20.11.0","tsx":"^4.11.0","typescript":"^5.5.0"},"engines":{"node":">=20"},"_id":"@aithos/assets-crypto@0.1.0-alpha.2","gitHead":"e43083344882c1f670d89cbe056eaf95fa80dbee","bugs":{"url":"https://github.com/aithos-protocol/aithos-protocol/issues"},"_nodeVersion":"23.9.0","_npmVersion":"10.9.2","dist":{"integrity":"sha512-DAOzpI89+1Y6iaWzWoNDYQhbzmTc9OWCh6UyKkZXAdKPsSYPdwJ2sc79I//yau3fBon6F655xqIbUoPiOzCL1w==","shasum":"e58684f2f412361033b438860e09d63b7d1944b1","tarball":"https://registry.npmjs.org/@aithos/assets-crypto/-/assets-crypto-0.1.0-alpha.2.tgz","fileCount":15,"unpackedSize":47896,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCw7OGBC1fslua7jqth1MLM/bovB30aduQOlodWvqSgQwIgPGlLmAKzhKWUMQPppprv4LC/z4BrUDTh0vuVoMQfiTQ="}]},"_npmUser":{"name":"aithos","email":"mathieu@aithos.be"},"directories":{},"maintainers":[{"name":"aithos","email":"mathieu@aithos.be"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/assets-crypto_0.1.0-alpha.2_1780654262570_0.455611733510483"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-26T14:23:06.093Z","modified":"2026-06-05T10:11:02.815Z","0.1.0-alpha.1":"2026-05-26T14:23:06.408Z","0.1.0-alpha.2":"2026-06-05T10:11:02.711Z"},"bugs":{"url":"https://github.com/aithos-protocol/aithos-protocol/issues"},"author":{"name":"Mathieu Colla","email":"mathieu.colla.pro@gmail.com"},"license":"Apache-2.0","homepage":"https://github.com/aithos-protocol/aithos-protocol#readme","keywords":["aithos","assets","pds","personal-data-server","encryption","x25519","xchacha20poly1305","envelope-encryption","file-encryption"],"repository":{"type":"git","url":"git+https://github.com/aithos-protocol/aithos-protocol.git","directory":"packages/assets-crypto"},"description":"Reference cryptographic primitives for the Aithos assets sub-protocol: AMK generation, X25519-HKDF-AEAD wraps, XChaCha20-Poly1305 byte encryption. See spec/assets/.","maintainers":[{"name":"aithos","email":"mathieu@aithos.be"}],"readme":"# @aithos/assets-crypto\n\nReference cryptographic primitives for the [Aithos assets\nsub-protocol](https://github.com/aithos-protocol/aithos-protocol/tree/main/spec/assets).\nImplements AMK (Asset Master Key) generation, X25519-HKDF-AEAD wraps\nfor recipients, XChaCha20-Poly1305 byte encryption with the canonical\nnonce-prefix on-disk layout, and SHA-256 content-addressing.\n\n## Status\n\n**Alpha** — API surface likely to shift until 0.1.0 stable. Use at\nyour own risk for production.\n\n## Install\n\n```sh\nnpm install @aithos/assets-crypto@alpha\n```\n\n## Quick start\n\n```ts\nimport {\n  generateAMK,\n  wrapAMKForRecipient,\n  unwrapAMK,\n  encryptAssetBytes,\n  decryptAssetBytes,\n  generateX25519Keypair,\n} from \"@aithos/assets-crypto\";\n\n// 1. Generate keys\nconst { privateKey, publicKey } = generateX25519Keypair();\nconst amk = generateAMK();\nconst assetUrn = \"urn:aithos:asset:did:aithos:z6Mkr…:asset_01J…\";\n\n// 2. Wrap the AMK for the recipient\nconst wrap = wrapAMKForRecipient({\n  amk,\n  recipientPublicKey: publicKey,\n  recipientDidUrl: \"did:aithos:z6Mkr…#circle-kex\",\n  assetUrn,\n});\n\n// 3. Encrypt the asset bytes\nconst plaintext = new TextEncoder().encode(\"My private content\");\nconst { blob, sha256_of_plaintext_hex, size_bytes } = encryptAssetBytes({\n  amk,\n  assetUrn,\n  plaintext,\n});\n\n// `blob` is the [nonce(24) | ciphertext+tag] ready to PUT to S3.\n// `sha256_of_plaintext_hex` and `size_bytes` go into the asset metadata.\n\n// 4. Later, decrypt\nconst recoveredAmk = unwrapAMK({\n  wrap,\n  recipientPrivateKey: privateKey,\n  assetUrn,\n});\n\nconst recovered = decryptAssetBytes({\n  amk: recoveredAmk,\n  assetUrn,\n  blob,\n  expectedSha256Hex: sha256_of_plaintext_hex,\n});\n// recovered === plaintext, byte-for-byte\n```\n\n## What's in here\n\nThe package is organized around four concerns:\n\n- **`amk`** — AMK generation, wrap, unwrap (`spec/assets/02-key-hierarchy.md` §2.3).\n- **`asset`** — Asset bytes encryption with the nonce-prefix on-disk layout\n  (§2.3.2), public-regime hash verification (§2.6), and helpers.\n- **`aad`** — Canonical AAD construction binding ciphertexts to\n  `(asset_urn, recipient_did_url)`.\n- **`types`** — Wire-format types (`AssetMetadata`, `AMKEnvelope`,\n  `WrapEntry`, `AssetReference`) plus base64/hex helpers and the\n  `AssetsCryptoError` class.\n\n## Cryptographic constructions\n\n- **AEAD**: XChaCha20-Poly1305 IETF, 24-byte nonce.\n- **Key agreement**: X25519 (RFC 7748).\n- **KDF**: HKDF-SHA256 (RFC 5869) with salt `\"aithos-assets-amk-wrap-v1\"`\n  and info = recipient DID URL.\n- **Content hash**: SHA-256.\n- **All AADs** carry an explicit version marker (`\"aithos-asset-v1\\0\"`,\n  `\"aithos-assets-amk-v1\\0\"`) so cross-version ciphertext substitution\n  fails loudly.\n\n## Related packages\n\n| Package | Scope |\n|---|---|\n| [`@aithos/protocol-core`](https://www.npmjs.com/package/@aithos/protocol-core) | Wire-format primitives, types, canonicalization. |\n| [`@aithos/data-crypto`](https://www.npmjs.com/package/@aithos/data-crypto) | Crypto primitives for the data sub-protocol (CMK/DEK/records). |\n| **`@aithos/assets-crypto`** (this) | Crypto primitives for the assets sub-protocol. |\n| [`@aithos/protocol-client`](https://www.npmjs.com/package/@aithos/protocol-client) | Env-agnostic client: signing, building, API access. |\n\n## License\n\n[Apache License 2.0](https://www.apache.org/licenses/LICENSE-2.0). See\n[LICENSE](./LICENSE).\n\nThe Aithos protocol specification (in the `spec/` directory of this\nrepo) is under [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/).\n\n## Contributing\n\nIssues and pull requests are welcome at\n[github.com/aithos-protocol/aithos-protocol](https://github.com/aithos-protocol/aithos-protocol).\n","readmeFilename":"README.md"}