🚀 Launch Week Day 5:Introducing Immutable Scans.Learn More →
Socket
Book a DemoInstallSign in
Socket

secure-key

Package Overview
Dependencies
Maintainers
2
Versions
2
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

secure-key

Password protected ed25519 key pairs

latest
Source
npmnpm
Version
1.1.0
Version published
Maintainers
2
Created
Source

secure-key

Password protected ed25519 key pairs.

Usage

await SecureKey.generate('/path/to/keyfile')

// interactive prompt for password
const keyPair = await SecureKey.open('/path/to/keyfile')

// interactive prompt for password

// key pair is locked initially  
keyPair.unlock()

// use key pair  
const signature = crypto.sign(message, keyPair)

// lock key pair in between usage
keyPair.lock()

// ... do some more

// clear key pair finally
keyPair.clear()

API

SecureKey.secretKeyLength

Byte length of secret key

SecureKey.publicKeyLength

Byte length of public key

await SecureKey.generate(path, opts)

Generate a new key pair and store to path.

Public key will be written to path.public

opts can be passed:

  • password: specify password for non-interactive mode

const keyPair = await SecureKey.open(path, opts)

Open a key pair stored at path.

opts can be passed:

  • password: specify password for non-interactive mode
  • protected: true by default. If set to false, secret key will be written to a plain buffer

keyPair.unlock()

Unlock the key pair.

Throws an error if secret key is not in secure memory.

keyPair.lock()

Lock the key pair.

Any attmept to access keyPair.secretKey will trigger a segfault.

Throws an error if secret key is not in secure memory.

keyPair.clear()

Clear the secret key from memory.

keyPair.secretKey

The secret key.

keyPair.publicKey

The public key.

keyPair.locked

Boolean indicating if the key pair is locked.

License

Apache-2.0

FAQs

Package last updated on 29 Feb 2024

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts