About this project

Crypto Service is a TypeScript cryptography toolkit distributed as 18 coordinated packages in a pnpm monorepo. The core library (@sebastienrousseau/crypto-lib) provides 50+ algorithms spanning symmetric AEAD (AES-128/256-GCM, AES-GCM-SIV, XChaCha20-Poly1305), signatures (Ed25519, Ed448, ECDSA P-256/P-384, Schnorr BIP-340), key exchange and KEM (X25519, X448, ECDH, ML-KEM-512/768/1024 per FIPS 203, hybrid KEMs), post-quantum signatures (ML-DSA-44/65/87 per FIPS 204, SLH-DSA SHA-2/SHAKE per FIPS 205, FN-DSA-512/1024), HPKE (RFC 9180), hash functions (SHA-2, SHA-3, BLAKE2b, BLAKE3), KDFs (HKDF, PBKDF2, scrypt, Argon2id/i/d), HMAC/KMAC, OpenPGP key generation and operations, and protocols including PQXDH, double ratchet, PAKE, Shamir threshold sharing, and PASETO v4. The ecosystem includes a Fastify REST microservice (crypto-server) with OpenAPI/Swagger schemas, OpenTelemetry tracing, Prometheus metrics, and configurable API-key/JWT authentication; an interactive terminal CLI (crypto-cli); a typed SDK client; Express and Fastify request encryption/decryption middleware; React hooks (useEncryption, useKeypair) and Vue 3 composables for client-side cryptography; Prisma and TypeORM extensions for transparent database field-level encryption; edge runtime adapters for Cloudflare Workers, Vercel Edge, and Deno; a KMS interface with AWS and local providers; and AI/IDE tooling via a Model Context Protocol server (crypto-mcp) for agents like Claude and Cursor, plus a Language Server Protocol server (crypto-lsp) for real-time crypto diagnostics and PEM linting. A CycloneDX 1.6 / SPDX 3.0 cryptographic bill-of-materials generator (crypto-cbom) and a comparative benchmarking suite are also included. Important limitations documented by the project: no module is FIPS 140-3 validated. Post-quantum algorithms come from @noble/post-quantum, which has not been independently audited and does not guarantee constant-time execution. Key zeroization is limited because JavaScript strings and garbage-collected buffers cannot be reliably wiped. Only four packages are published to npm at older versions (0.0.1–0.0.3); the repository is at v0.0.6, and most packages are source-only via the pnpm workspace. KMS providers for GCP, Azure, and Vault are stubs, and there is no PKCS#11 binding. No benchmark numbers are published. Requires Node.js >= 22 and pnpm >= 9. Docker images are published to GHCR. CI enforces 100% line and function coverage across packages. Dual-licensed under Apache-2.0 OR MIT.