Expand description
Authenticated encryption at rest for sensitive credentials (AES-256-GCM).
SealedBox provides a versioned, Base64 envelope (enc:v1:<base64>) around
AES-256-GCM ciphertext with an explicit nonce and optional additional
authenticated data (AAD). It is designed for persisting OAuth session tokens,
refresh tokens, and private DPoP keys in embedded databases.
Plaintext values that do not carry the envelope prefix are passed through unchanged, allowing transparent migration from legacy unencrypted records.
Structs§
- Sealed
Box - AES-256-GCM key plus versioned envelope helpers for encrypting data at rest.
Constants§
- SEALED_
ENVELOPE_ PREFIX - Prefix identifying AES-256-GCM sealed payloads (
enc:v1:...).