Documentation · Widgets

Decryption

The decrypt widget opens a CMS EnvelopedData envelope (.p7e). The user picks the key file and enters the password inside the iframe — just like when signing, the key never reaches your page.

Paid option. Together with encryption, it is part of the "Encryption and decryption" add-on (see pricing). Without it, decrypt returns an error with error.code === 'ENCRYPTION_NOT_ENABLED' (during the trial / on localhost it is available).

Example

import { embed } from 'https://dstucrypt.io/embed/dstucrypt-embed.mjs';

const dec = await embed('decrypt', { mount: 'modal' });

const plain = await dec.decrypt(envelopeFile);   //  key and password stay in the iframe

plain.download('document.pdf');                  //  or plain.bytes / plain.text()
dec.destroy();

API

const plain = await dec.decrypt(envelope);
  • envelope — the .p7e envelope (File | Uint8Array | ArrayBuffer).
  • The result is a Bytes object with the decrypted data.

The widget picks the key-agreement key (keyAgreement) in the container by itself — the user does not need to understand key types. A single "Decrypt" button: it opens the container and decrypts right away.

Errors

They are shown in plain language inside the widget ("Wrong key password", "This certificate is for signing only" — when the container has no encryption key). Your integration code receives the error as an exception with a message.