{"_id":"@aws-crypto/node-jose_aws-kms-extension","_rev":"5-a2afbecd5a66995e863926112a230761","name":"@aws-crypto/node-jose_aws-kms-extension","dist-tags":{"latest":"2.1.0"},"versions":{"2.0.0":{"name":"@aws-crypto/node-jose_aws-kms-extension","version":"2.0.0","author":{"name":"lynx-tech@amazon.com"},"license":"Apache-2.0","_id":"@aws-crypto/node-jose_aws-kms-extension@2.0.0","maintainers":[{"name":"jaswantcoder","email":"jaswantarya442@gmail.com"}],"homepage":"https://github.com/amzn/node-jose_aws-kms-extension#readme","bugs":{"url":"https://github.com/amzn/node-jose_aws-kms-extension/issues"},"dist":{"shasum":"0f09a0434c2b7e2eba7284caece53eca726374b6","tarball":"https://registry.npmjs.org/@aws-crypto/node-jose_aws-kms-extension/-/node-jose_aws-kms-extension-2.0.0.tgz","fileCount":25,"integrity":"sha512-XEnxL4jf4Z1h/CTqNTXP7P3KGpehVYxj6ZvH7O50kiwZSWU0b0MmnNNZPvulw4aas5OYcnPubjxycB+ZFehPvA==","signatures":[{"sig":"MEUCIDzr3H1voSba9H8KeR6rNBWRp6w7aJZumaqLyu7Ny94CAiEA6Fm853lfdcfC6Lq+ragdQis/zQBQgHLYsB2awNwtZ9Q=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":65352},"jest":{"testMatch":["**/**.test.ts"],"transform":{".(js|ts)":"ts-jest"},"coverageReporters":["cobertura","html","text"],"transformIgnorePatterns":["[/\\\\]node_modules[/\\\\].+\\.(js|jsx|ts|tsx|json)$","package.json"]},"main":"dist/index.js","types":"dist/types/index.d.ts","engines":{"node":">= 18.0.0"},"gitHead":"53f6c647f9fda4e582734d426de58c22ee2c1fa7","scripts":{"fix":"npx eslint --ext .ts src --fix","lint":"npx eslint --ext .ts src","test":"jest --collectCoverage --collectCoverageFrom=src/**/*.{ts,js} && npm run format && npm run fix","build":"tsc","clean":"rm -rf dist && rm -rf node_modules","watch":"tsc -w","format":"prettier --ignore-path .gitignore --write \"**/*.+(js|ts|json)\"","prepublishOnly":"npm run build && npm run test"},"_npmUser":{"name":"jaswantcoder","email":"jaswantarya442@gmail.com"},"repository":{"url":"git+https://github.com/amzn/node-jose_aws-kms-extension.git","type":"git"},"_npmVersion":"9.6.7","description":"This library is an extension of node-jose library with AWS KMS support","directories":{},"_nodeVersion":"18.17.0","dependencies":{"node-jose":"^2.2.0","@aws-sdk/client-kms":"^3.414.0"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.5.0","eslint":"^8.49.0","ts-jest":"^29.1.0","ts-node":"^10.9.1","prettier":"^3.0.3","typescript":"~5.1.3","@types/jest":"^29.5.2","eslint-plugin-prettier":"^5.0.0","@typescript-eslint/parser":"^6.7.0","@typescript-eslint/eslint-plugin":"^6.7.0"},"npm-pretty-much":{"runTest":"never"},"_npmOperationalInternal":{"tmp":"tmp/node-jose_aws-kms-extension_2.0.0_1696017888392_0.362285081819973","host":"s3://npm-registry-packages"}},"2.0.1":{"name":"@aws-crypto/node-jose_aws-kms-extension","version":"2.0.1","author":{"name":"lynx-tech@amazon.com"},"license":"Apache-2.0","_id":"@aws-crypto/node-jose_aws-kms-extension@2.0.1","maintainers":[{"name":"jaswantcoder","email":"jaswantarya442@gmail.com"}],"homepage":"https://github.com/amzn/node-jose_aws-kms-extension#readme","bugs":{"url":"https://github.com/amzn/node-jose_aws-kms-extension/issues"},"dist":{"shasum":"cb190faac6af45a778fda7f2ba3b99358b54faac","tarball":"https://registry.npmjs.org/@aws-crypto/node-jose_aws-kms-extension/-/node-jose_aws-kms-extension-2.0.1.tgz","fileCount":25,"integrity":"sha512-oHBOgWF6T+VYHGlbt4v4yIk/BtUK3fpxWvwTMhWagAhvXp+rBz/K0DpYpH9smLuhV/Qf5orpxwkv4UHzFIwmmA==","signatures":[{"sig":"MEUCIQCOC6Nfv7X7LSHV4XMo68TWARrKMKai9P/viEgWCExeCgIgczml4feuCnnItQjE6YsrCpBaNcJUi7SdShBqDsakmJ4=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":66261},"jest":{"testMatch":["**/**.test.ts"],"transform":{".(js|ts)":"ts-jest"},"coverageReporters":["cobertura","html","text"],"transformIgnorePatterns":["[/\\\\]node_modules[/\\\\].+\\.(js|jsx|ts|tsx|json)$","package.json"]},"main":"dist/index.js","types":"dist/types/index.d.ts","engines":{"node":">= 18.0.0"},"gitHead":"e77998267e7ea60f340395e6f0afdf5e93254e62","scripts":{"fix":"npx eslint --ext .ts src --fix","lint":"npx eslint --ext .ts src","test":"jest --collectCoverage --collectCoverageFrom=src/**/*.{ts,js} && npm run format && npm run fix","build":"tsc","clean":"rm -rf dist && rm -rf node_modules","watch":"tsc -w","format":"prettier --ignore-path .gitignore --write \"**/*.+(js|ts|json)\"","prepublishOnly":"npm run build && npm run test"},"_npmUser":{"name":"jaswantcoder","email":"jaswantarya442@gmail.com"},"repository":{"url":"git+https://github.com/amzn/node-jose_aws-kms-extension.git","type":"git"},"_npmVersion":"9.6.7","description":"This library is an extension of node-jose library with AWS KMS support","directories":{},"_nodeVersion":"18.17.0","dependencies":{"node-jose":"^2.2.0","@aws-sdk/client-kms":"^3.414.0"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.5.0","eslint":"^8.49.0","ts-jest":"^29.1.0","ts-node":"^10.9.1","prettier":"^3.0.3","typescript":"~5.1.3","@types/jest":"^29.5.2","eslint-plugin-prettier":"^5.0.0","@typescript-eslint/parser":"^6.7.0","@typescript-eslint/eslint-plugin":"^6.7.0"},"npm-pretty-much":{"runTest":"never"},"_npmOperationalInternal":{"tmp":"tmp/node-jose_aws-kms-extension_2.0.1_1697089008394_0.018812718399586092","host":"s3://npm-registry-packages"}},"2.0.2":{"name":"@aws-crypto/node-jose_aws-kms-extension","version":"2.0.2","author":{"name":"lynx-tech@amazon.com"},"license":"Apache-2.0","_id":"@aws-crypto/node-jose_aws-kms-extension@2.0.2","maintainers":[{"name":"jaswantcoder","email":"jaswantarya442@gmail.com"}],"homepage":"https://github.com/amzn/node-jose_aws-kms-extension#readme","bugs":{"url":"https://github.com/amzn/node-jose_aws-kms-extension/issues"},"dist":{"shasum":"246d26cac1e9d9fe171701753311344aed3fecd8","tarball":"https://registry.npmjs.org/@aws-crypto/node-jose_aws-kms-extension/-/node-jose_aws-kms-extension-2.0.2.tgz","fileCount":25,"integrity":"sha512-tR4SFRw0hM6CKJqCXZek+1myTC6M2sX3fSeo6pvJwp3cqqx/3qaP6sFUD+jR5N+Y5E2WqrIcKSIr/jeIkPF3CA==","signatures":[{"sig":"MEUCIQDfZxNdCuMmj4GSw2XyNGv9/PlIHK+LiI2vuzlQEOw/1gIgP5KsJ6eEJAEogD4b/RcScBXX0uEF4NbT1GAPRhiv64k=","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":66730},"jest":{"testMatch":["**/**.test.ts"],"transform":{".(js|ts)":"ts-jest"},"coverageReporters":["cobertura","html","text"],"transformIgnorePatterns":["[/\\\\]node_modules[/\\\\].+\\.(js|jsx|ts|tsx|json)$","package.json"]},"main":"dist/index.js","types":"dist/types/index.d.ts","engines":{"node":">= 18.0.0"},"gitHead":"b61c3155f1512348c4bef53a58adbf91dad2bd02","scripts":{"fix":"npx eslint --ext .ts src --fix","lint":"npx eslint --ext .ts src","test":"jest --collectCoverage --collectCoverageFrom=src/**/*.{ts,js} && npm run format && npm run fix","build":"tsc","clean":"rm -rf dist && rm -rf node_modules","watch":"tsc -w","format":"prettier --ignore-path .gitignore --write \"**/*.+(js|ts|json)\"","prepublishOnly":"npm run build && npm run test"},"_npmUser":{"name":"jaswantcoder","email":"jaswantarya442@gmail.com"},"repository":{"url":"git+https://github.com/amzn/node-jose_aws-kms-extension.git","type":"git"},"_npmVersion":"9.6.7","description":"This library is an extension of node-jose library with AWS KMS support","directories":{},"_nodeVersion":"18.17.0","dependencies":{"node-jose":"^2.2.0","@aws-sdk/client-kms":"^3.414.0"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.5.0","eslint":"^8.49.0","ts-jest":"^29.1.0","ts-node":"^10.9.1","prettier":"^3.0.3","typescript":"~5.1.3","@types/jest":"^29.5.2","eslint-plugin-prettier":"^5.0.0","@typescript-eslint/parser":"^6.7.0","@typescript-eslint/eslint-plugin":"^6.7.0"},"npm-pretty-much":{"runTest":"never"},"_npmOperationalInternal":{"tmp":"tmp/node-jose_aws-kms-extension_2.0.2_1699358207627_0.4475499053094798","host":"s3://npm-registry-packages"}},"2.1.0":{"name":"@aws-crypto/node-jose_aws-kms-extension","version":"2.1.0","author":{"name":"lynx-tech@amazon.com"},"license":"Apache-2.0","_id":"@aws-crypto/node-jose_aws-kms-extension@2.1.0","maintainers":[{"name":"jaswantcoder","email":"jaswantarya442@gmail.com"}],"homepage":"https://github.com/amzn/node-jose_aws-kms-extension#readme","bugs":{"url":"https://github.com/amzn/node-jose_aws-kms-extension/issues"},"dist":{"shasum":"c16cfaa2ae3c7a48b3dfe53be4f49b855f7cf2c2","tarball":"https://registry.npmjs.org/@aws-crypto/node-jose_aws-kms-extension/-/node-jose_aws-kms-extension-2.1.0.tgz","fileCount":25,"integrity":"sha512-Acbi0QbINtXv673EToSP5c7zr0yR38JuBj0IrXIkOHa3LGvOeXVA4zTJtPnNuGAhNdsI0azfD4DKsh6u4QweRg==","signatures":[{"sig":"MEYCIQCGlGIH7BMcRtpxwh68FBgdf1nA6JXg/7qHGZ1q/C5AyAIhAKvmsAI1gCM0YwfXCYdYaPpe/Rn0+hDxld/Dh7g6PNBD","keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA"}],"unpackedSize":73994},"jest":{"testMatch":["**/**.test.ts"],"transform":{".(js|ts)":"ts-jest"},"coverageReporters":["cobertura","html","text"],"transformIgnorePatterns":["[/\\\\]node_modules[/\\\\].+\\.(js|jsx|ts|tsx|json)$","package.json"]},"main":"dist/index.js","types":"dist/types/index.d.ts","engines":{"node":">= 18.0.0"},"gitHead":"44ca0413e3bb6b16bda12e2237ce025f07cff0c4","scripts":{"fix":"npx eslint --ext .ts src --fix","lint":"npx eslint --ext .ts src","test":"jest --collectCoverage --collectCoverageFrom=src/**/*.{ts,js} && npm run format && npm run fix","build":"tsc","clean":"rm -rf dist && rm -rf node_modules","watch":"tsc -w","format":"prettier --ignore-path .gitignore --write \"**/*.+(js|ts|json)\"","prepublishOnly":"npm run build && npm run test"},"_npmUser":{"name":"jaswantcoder","email":"jaswantarya442@gmail.com"},"repository":{"url":"git+https://github.com/amzn/node-jose_aws-kms-extension.git","type":"git"},"_npmVersion":"9.6.7","description":"This library is an extension of node-jose library with AWS KMS support","directories":{},"_nodeVersion":"18.17.0","dependencies":{"node-jose":"^2.2.0","@aws-sdk/client-kms":"^3.414.0"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.5.0","eslint":"^8.49.0","ts-jest":"^29.1.0","ts-node":"^10.9.1","prettier":"^3.0.3","typescript":"~5.1.3","@types/jest":"^29.5.2","eslint-plugin-prettier":"^5.0.0","@typescript-eslint/parser":"^6.7.0","@typescript-eslint/eslint-plugin":"^6.7.0"},"npm-pretty-much":{"runTest":"never"},"_npmOperationalInternal":{"tmp":"tmp/node-jose_aws-kms-extension_2.1.0_1716146525862_0.6046724028806629","host":"s3://npm-registry-packages"}}},"time":{"created":"2023-09-29T20:04:48.325Z","modified":"2025-05-22T20:13:41.580Z","2.0.0":"2023-09-29T20:04:48.594Z","2.0.1":"2023-10-12T05:36:48.572Z","2.0.2":"2023-11-07T11:56:47.777Z","2.1.0":"2024-05-19T19:22:06.076Z"},"bugs":{"url":"https://github.com/amzn/node-jose_aws-kms-extension/issues"},"author":{"name":"lynx-tech@amazon.com"},"license":"Apache-2.0","homepage":"https://github.com/amzn/node-jose_aws-kms-extension#readme","repository":{"url":"git+https://github.com/amzn/node-jose_aws-kms-extension.git","type":"git"},"description":"This library is an extension of node-jose library with AWS KMS support","maintainers":[],"readme":"# node-jose_aws-kms-extension\n\nThis library is an extension of the [node-jose](https://www.npmjs.com/package/node-jose) library, and uses monkey-patching to extend the capabilities of node-jose. It provides JWE-based encrypters/decrypters and JWS-based signers/verifiers for cryptographic operations with keys stored in AWS Key Management Service (KMS).\n\n## Installation\n\nYou can install the library from [npm](https://www.npmjs.com/package/@aws-crypto/node-jose_aws-kms-extension) using the following command. This library requires Node.js 18 or above.\n\n```bash\nnpm install @aws-crypto/node-jose_aws-kms-extension\n```\n\n\n## Usage\nImport the necessary classes from `@aws-crypto/node-jose_aws-kms-extension` module:\n\n```ts\nimport {\n  KMSAsymmetricSigningKey,\n  KMSSymmetricCEK,\n  KMSSymmetricKey,\n} from '@aws-crypto/node-jose_aws-kms-extension';\n```\n\nImport the main jose object.\n```ts\nimport { jose } from '@aws-crypto/node-jose_aws-kms-extension';\n```\n\nNow, you can use all existing node-jose features as you would in the absence of this library. This library adds AWS KMS support transparently. You can use your AWS KMS keys for various encryption and signing operations using the regular node-jose functions. AWS KMS-specific algorithm names are supported.\n\n\nSupported `node-jose` functions include:\n\n1. `jose.JWE.createEncrypt()`\n1. `jose.JWE.createDecrypt()`\n1. `jose.JWS.createSign()`\n1. `jose.JWS.createVerify()`\n\nThis library uses [@aws-sdk/client-kms](https://docs.aws.amazon.com/AWSJavaScriptSDK/v3/latest/client/kms/)\nfor all its communication with AWS KMS.\n\n[Supported KMS Signing Algorithms](https://docs.aws.amazon.com/AWSJavaScriptSDK/v3/latest/Package/-aws-sdk-client-kms/Variable/SigningAlgorithmSpec/)\n\n[Supported KMS Encryption Algorithms](https://docs.aws.amazon.com/AWSJavaScriptSDK/v3/latest/Package/-aws-sdk-client-kms/Variable/EncryptionAlgorithmSpec/)\n\n[Supported Data Key Spec](https://docs.aws.amazon.com/AWSJavaScriptSDK/v3/latest/Package/-aws-sdk-client-kms/Variable/DataKeySpec/)\n\n## Examples\n\n### Importing variables from modules @aws-crypto/node-jose_aws-kms-extension and @aws-sdk/client-kms\n\n```ts\nimport {\n  jose,\n  KMSAsymmetricSigningKey,\n  KMSSymmetricCEK,\n  KMSSymmetricKey,\n} from '@aws-crypto/node-jose_aws-kms-extension';\nimport { KMSClient } from \"@aws-sdk/client-kms\";\n```\n\n### Creating AWS KMS Client\n\n```ts\nconst kmsClient: KMSClient = new KMSClient({ region: 'REGION' });\n```\n\n### Signing\n\n1. Prepare signing options with format as `compact`, and header fields.\n2. Prepare signatory with key as KMSAsymmetricSigningKey object.\n3. Use jose.JWS.createSign method to sign the payload.\n\n```ts\nconst signingOpts = {\n  format: 'compact',\n  fields: {\n    alg: 'SIGNING_ALGORITHM',\n    kid: 'KMS_SIGNING_KEY_ID',\n    JWS_CRIT_HEADER1: 'JWS_CRIT_HEADER1_VALUE',\n    JWS_CRIT_HEADER2: 'JWS_CRIT_HEADER2_VALUE',\n    crit: ['JWS_CRIT_HEADER1', 'JWS_CRIT_HEADER2'],\n  },\n};\n\nconst signatory = {\n  key: new KMSAsymmetricSigningKey('KMS_SIGNING_KEY_ID', kmsClient),\n};\n\nconst dataToSign = 'This is the data to sign';\nconst signer = jose.JWS.createSign(signingOpts, signatory);\nconst jws: Promise<string> = signer\n  .update(dataToSign)\n  .final()\n  .then(function (result: string) {\n    console.log('JWS: ', result);\n    return result;\n  });\n\n  ```\n\n### Encryption\n\n1. Prepare encryption options with format as `compact`, header fields and cek as KMSSymmetricCEK object.\n2. Prepare encryption recipient with reference as `false`, and key as KMSSymmetricKey object. Use same KMS key to create KMSSymmetricCEK and KMSSymmetricKey.\n3. Use jose.JWE.createEncrypt method to encrypt jws payload.\n\n```ts\nconst encryptionOpts = {\n  format: 'compact',\n  fields: {\n    kid: 'ENCRYPTION_KMS_KEY_ID',\n    alg: 'KEY_ENCRYPTION_ALGORITHM',\n    enc: 'CONTENT_ENCRYPTION_ALGORITHM',\n    JWE_CRIT_HEADER1: 'JWE_CRIT_HEADER1_VALUE',\n    JWE_CRIT_HEADER2: 'JWE_CRIT_HEADER2_VALUE',\n    crit: ['JWE_CRIT_HEADER1', 'JWE_CRIT_HEADER2'],\n  },\n  cek: new KMSSymmetricCEK('KMS_ENCRYPTION_KEY_ID', kmsClient, 'KEY_SPEC'),\n};\n\nconst encryptionRecipient = {\n  reference: false,\n  key: new KMSSymmetricKey('KMS_ENCRYPTION_KEY_ID', kmsClient),\n};\n\nconst encrypter = jose.JWE.createEncrypt(\n  encryptionOpts,\n  encryptionRecipient,\n);\nconst jwe: Promise<string> = jws.then(function (jws: string) {\n  return encrypter\n    .update(jws)\n    .final()\n    .then(function (result: string) {\n      console.log('JWE: ', result);\n      return result;\n    });\n});\n\n```\n\n###  Decryption\n\n1. Prepare decryption options with handlers to process jwe critical headers.\n2. Preare decryption assumed key as KMSSymmetricKey object\n3. Use jose.JWE.createDecrypt method to decrypt jwe payload.\n\n```ts\nconst decryption_opts = {\n  handlers: {\n    JWE_CRIT_HEADER1: function(jwe: any) {\n      console.log(jwe.header.JWE_CRIT_HEADER1)\n      // process JWE_CRIT_HEADER1\n    },\n    JWE_CRIT_HEADER2: function(jwe: any) {\n      console.log(jwe.header.JWE_CRIT_HEADER2)\n      // process JWE_CRIT_HEADER2\n    }\n  },\n};\n\nconst decryption_assumedKey = new KMSSymmetricKey(\n  'KMS_ENCRYPTION_KEY_ID',\n  kmsClient,\n);\n\nconst decrypter = jose.JWE.createDecrypt(\n  decryption_assumedKey,\n  decryption_opts,\n);\n\nconst decyptedContent: Promise<any> = jwe.then(function (jwe: string) {\n  return decrypter.decrypt(jwe).then(function (result: any) {\n    console.log('JWE decryption result: ', result);\n    return result;\n  });\n});\n```\n\n###  Verification\n\n1. Prepare verification options with handlers to process jws critical headers.\n2. Prepare verification assumed key as KMSAsymmetricSigningKey object\n3. Use jose.JWS.createVerify method to verify jws payload.\n\n```ts\nconst verification_opts = {\n  handlers: {\n    JWS_CRIT_HEADER1: function(jws: any) {\n      console.log(jws.header.JWS_CRIT_HEADER1)\n      // process JWS_CRIT_HEADER1\n    },\n    JWS_CRIT_HEADER2: function(jws: any) {\n      console.log(jws.header.JWS_CRIT_HEADER2)\n      // process JWS_CRIT_HEADER2\n    }\n  },\n};\n\nconst verificationAssumedKey = new KMSAsymmetricSigningKey(\n  'KMS_SIGNING_KEY_ID',\n  kmsClient,\n);\n\nconst verifier = jose.JWS.createVerify(\n  verificationAssumedKey,\n  verification_opts,\n);\nconst verificationResult: Promise<any> = decyptedContent.then(function (\n  decryptedContent: any,\n) {\n  const payloadToVerify = jose.util.utf8.encode(decryptedContent.payload);\n  return verifier.verify(payloadToVerify).then(function (result: any) {\n    console.log('JWS verification result: ', result);\n    console.log('Verified payload: ', jose.util.utf8.encode(result.payload));\n    return result;\n  });\n});\n```\n\n#### Note: KMS_SIGNING_KEY_ID and KMS_ENCRYPTION_KEY_ID can be KMS key ID, key ARN, alias name, or alias ARN. When using an alias name, it will have prefix `alias/`. It should be key ARN or alias ARN to specify in different Amazon Web Services account.\n\n\n# Security\n\nSee [CONTRIBUTING](CONTRIBUTING.md#security-issue-notifications) for more information.\n\n\n## License\n\nThis library is distributed under the\n[Apache License, Version 2.0](http://www.apache.org/licenses/LICENSE-2.0),\nsee [LICENSE](LICENSE) and [NOTICE](NOTICE) for more information.","readmeFilename":"README.md"}