Skip to main content

Module sealed

Module sealed 

Source
Expand description

Authenticated encryption at rest for sensitive credentials (AES-256-GCM).

SealedBox provides a versioned, Base64 envelope (enc:v1:<base64>) around AES-256-GCM ciphertext with an explicit nonce and optional additional authenticated data (AAD). It is designed for persisting OAuth session tokens, refresh tokens, and private DPoP keys in embedded databases.

Plaintext values that do not carry the envelope prefix are passed through unchanged, allowing transparent migration from legacy unencrypted records.

Structs§

SealedBox
AES-256-GCM key plus versioned envelope helpers for encrypting data at rest.

Constants§

SEALED_ENVELOPE_PREFIX
Prefix identifying AES-256-GCM sealed payloads (enc:v1:...).