Crypto spec
Cryptographic Specification
This page documents the implemented cryptographic construction. It avoids phrases like military-grade encryption because those phrases do not let a security engineer evaluate the design.
Fragment-Key Text And Env Shares
Text and environment-variable shares use one random content key per share.
- Content key: 32 random bytes from crypto.getRandomValues.
- Encryption: AES-GCM through the browser Web Crypto API.
- IV/nonce: 12 random bytes per encryption operation.
- Plaintext format: JSON payload, UTF-8 encoded.
- Text/env serialized payload cap: 200 KiB.
- Key verifier: SHA-256 digest of the raw 32-byte share key.
- Key transport: URL fragment, using #key=...
- Ciphertext, IV, key, and verifier encoding: canonical unpadded base64url.
Server-Visible Cryptographic Metadata
The server needs enough metadata to store ciphertext, enforce lifecycle rules, and authorize retrieval without learning plaintext.
- Fragment-key shares: ciphertext, IV, key verifier, lifecycle settings, kind, and approved metadata.
- Password shares: ciphertext, IV, password verifier, KDF version, iteration count, salt, wrapping IV, wrapped share key, lifecycle settings, kind, and approved metadata.
- File shares: encrypted metadata, ciphertext sizes, IVs, opaque object keys, lifecycle settings, and approved metadata.
- The server does not receive plaintext share contents, plaintext files, plaintext share passwords, private decryption keys, or URL fragment keys.
Implementation References
These are source locations in the repository. They are not a public audit claim.
Text/env crypto:
src/lib/share-crypto.ts
File crypto:
src/lib/share-file-crypto.ts
Password wrapping:
src/lib/share-password.ts
Client API serialization:
src/lib/share-client.tsKeep reading
Explore the rest of the security documentation
Every security page links to the others so you can move through the full model without using the browser back button.