The decrypt widget opens a CMS EnvelopedData envelope (.p7e). The user
picks the key file and enters the password inside the iframe — just like when
signing, the key never reaches your page.
Paid option. Together with encryption, it is part of the "Encryption and decryption" add-on (see pricing). Without it,
decryptreturns an error witherror.code === 'ENCRYPTION_NOT_ENABLED'(during the trial / on localhost it is available).
Example
import { embed } from 'https://dstucrypt.io/embed/dstucrypt-embed.mjs';
const dec = await embed('decrypt', { mount: 'modal' });
const plain = await dec.decrypt(envelopeFile); // key and password stay in the iframe
plain.download('document.pdf'); // or plain.bytes / plain.text()
dec.destroy();
API
const plain = await dec.decrypt(envelope);
envelope— the.p7eenvelope (File|Uint8Array|ArrayBuffer).- The result is a
Bytesobject with the decrypted data.
The widget picks the key-agreement key (keyAgreement) in the container by itself —
the user does not need to understand key types. A single "Decrypt" button:
it opens the container and decrypts right away.
Errors
They are shown in plain language inside the widget ("Wrong key password", "This
certificate is for signing only" — when the container has no encryption key).
Your integration code receives the error as an exception with a message.