{"_id":"@astrapi69/passphrase-vault","_rev":"2-9177b60dd7b2d67c6c773dc3df8004b3","name":"@astrapi69/passphrase-vault","dist-tags":{"latest":"0.1.1"},"versions":{"0.1.0":{"name":"@astrapi69/passphrase-vault","version":"0.1.0","keywords":["encryption","passphrase","webcrypto","pbkdf2","aes-gcm","vault"],"author":{"name":"Asterios Raptis"},"license":"MIT","_id":"@astrapi69/passphrase-vault@0.1.0","maintainers":[{"name":"astrapi69","email":"asterios.raptis@gmx.net"}],"homepage":"https://github.com/astrapi69/ai-key-vault#readme","bugs":{"url":"https://github.com/astrapi69/ai-key-vault/issues"},"dist":{"shasum":"76d17dbc2ec48b8ceba4ef1280158b543304b252","tarball":"https://registry.npmjs.org/@astrapi69/passphrase-vault/-/passphrase-vault-0.1.0.tgz","fileCount":8,"integrity":"sha512-TeIHyCIF8cl/sq1znDs5Bm9hUF4/25kMkwz0g1g/+sVkB6Gma8AqpN7gpPQ3O0EmqyMcW5Uv7M3cZXKbV3MoOg==","signatures":[{"sig":"MEUCIQCjaX/EeibYH0wWvYD8kKrddvt0AEj0QM9O8K5RbFm0iAIgI9tiokCXwdabqNDQq1OHYJCmOFf6zZuLUaNzWtS+XXU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":47834},"main":"./dist/index.cjs","type":"module","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=20"},"exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}}},"gitHead":"8b697dd8f34d2c08c8d32e0745d06a0788f33d8e","scripts":{"build":"tsup"},"_npmUser":{"name":"astrapi69","email":"asterios.raptis@gmx.net"},"repository":{"url":"git+https://github.com/astrapi69/ai-key-vault.git","type":"git","directory":"packages/passphrase-vault"},"_npmVersion":"11.16.0","description":"Passphrase-based authenticated encryption of a small JSON value using WebCrypto only (PBKDF2-HMAC-SHA-256 + AES-GCM-256)","directories":{},"sideEffects":false,"_nodeVersion":"24.15.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/passphrase-vault_0.1.0_1784545578388_0.2319183439830741","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@astrapi69/passphrase-vault","version":"0.1.1","description":"Passphrase-based authenticated encryption of a small JSON value using WebCrypto only (PBKDF2-HMAC-SHA-256 + AES-GCM-256)","license":"MIT","author":{"name":"Asterios Raptis"},"repository":{"type":"git","url":"git+https://github.com/astrapi69/ai-key-vault.git","directory":"packages/passphrase-vault"},"keywords":["encryption","passphrase","webcrypto","pbkdf2","aes-gcm","vault"],"type":"module","main":"./dist/index.cjs","module":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"import":{"types":"./dist/index.d.ts","default":"./dist/index.js"},"require":{"types":"./dist/index.d.cts","default":"./dist/index.cjs"}}},"sideEffects":false,"scripts":{"build":"tsup"},"publishConfig":{"access":"public"},"engines":{"node":">=20"},"gitHead":"ba91c13872030084ba2bff73290c1838550532be","_id":"@astrapi69/passphrase-vault@0.1.1","bugs":{"url":"https://github.com/astrapi69/ai-key-vault/issues"},"homepage":"https://github.com/astrapi69/ai-key-vault#readme","_nodeVersion":"24.15.0","_npmVersion":"11.16.0","dist":{"integrity":"sha512-BjWWDRgSKXCrULFGk+VrKv2KrU06M+M5cnkvvYIoisie6a2TBJLcEyThAKC0jMtRJs1vvZy02y79igNZ7g7a9A==","shasum":"20d3f7414e1392c50d3864553b102af1c70d9258","tarball":"https://registry.npmjs.org/@astrapi69/passphrase-vault/-/passphrase-vault-0.1.1.tgz","fileCount":8,"unpackedSize":47834,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDFzb2bmQT7C4O/rZwZmZlYqk1DfklPT+seeT3kEc8qxAIhAJah082xfQu3J9KdRAqX5MZRd49fxNHYsYX2eAl1iA2d"}]},"_npmUser":{"name":"astrapi69","email":"asterios.raptis@gmx.net"},"directories":{},"maintainers":[{"name":"astrapi69","email":"asterios.raptis@gmx.net"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/passphrase-vault_0.1.1_1784567019444_0.4664939351462518"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-20T11:06:18.208Z","modified":"2026-07-20T17:03:39.848Z","0.1.0":"2026-07-20T11:06:18.521Z","0.1.1":"2026-07-20T17:03:39.687Z"},"bugs":{"url":"https://github.com/astrapi69/ai-key-vault/issues"},"author":{"name":"Asterios Raptis"},"license":"MIT","homepage":"https://github.com/astrapi69/ai-key-vault#readme","keywords":["encryption","passphrase","webcrypto","pbkdf2","aes-gcm","vault"],"repository":{"type":"git","url":"git+https://github.com/astrapi69/ai-key-vault.git","directory":"packages/passphrase-vault"},"description":"Passphrase-based authenticated encryption of a small JSON value using WebCrypto only (PBKDF2-HMAC-SHA-256 + AES-GCM-256)","maintainers":[{"name":"astrapi69","email":"asterios.raptis@gmx.net"}],"readme":"# @astrapi69/passphrase-vault\n\nPassphrase-based, authenticated encryption of a small JSON value using\n**WebCrypto only** — no dependencies, no self-built crypto.\n\n- Key derivation: PBKDF2-HMAC-SHA-256, 250,000 iterations, 16-byte random salt\n- Encryption: AES-GCM-256, 12-byte random IV (authenticated — a wrong\n  passphrase or a tampered byte rejects; no partial decrypts)\n- Envelope: a pretty-printed JSON string carrying format, version, KDF\n  parameters, IV and ciphertext — self-contained, safe to write to a file\n\nExtracted from [adaptive-learner](https://github.com/astrapi69/adaptive-learner)\n(EXP-038, the encrypted `.alk` AI-key export).\n\n## Usage\n\n```ts\nimport {\n    encryptToVault,\n    decryptFromVault,\n    looksLikeVaultEnvelope,\n    VaultDecryptError,\n} from \"@astrapi69/passphrase-vault\";\n\n// Encrypt any JSON-serialisable value:\nconst envelope = await encryptToVault({ token: \"secret\" }, passphrase, {\n    format: \"my-app-vault\",\n});\n// -> write `envelope` (a JSON string) to a file\n\n// Gate an import UI without decrypting:\nlooksLikeVaultEnvelope(fileText, { format: \"my-app-vault\" }); // boolean\n\n// Decrypt:\ntry {\n    const value = await decryptFromVault<{ token: string }>(fileText, passphrase, {\n        format: \"my-app-vault\",\n    });\n} catch (err) {\n    if (err instanceof VaultDecryptError) {\n        // wrong passphrase, foreign/malformed file, or tampered content —\n        // deliberately indistinguishable\n    }\n}\n```\n\nThe `format` option identifies your application's envelope. Omitting it uses\n`\"adaptive-learner-keys\"` (the historical default, kept so pre-extraction\n`.alk` files keep importing). An envelope whose format does not match the\nexpected one is rejected with `VaultDecryptError`.\n\n## License\n\nMIT\n","readmeFilename":"README.md"}