The encrypt widget creates an encrypted CMS EnvelopedData envelope using
the DSTU 7624:2014 Kalyna cipher. Encryption is performed against the recipient's
certificate — no private key is needed, so this is a secret-free widget.
Paid option. Encryption and decryption are a separate add-on, "Encryption and decryption" (see pricing), enabled per domain. Without it,
encrypt/decryptreturn an error witherror.code === 'ENCRYPTION_NOT_ENABLED'(during the trial / on localhost it is available for testing).
Example
import { embed } from 'https://dstucrypt.io/embed/dstucrypt-embed.mjs';
const enc = await embed('encrypt');
// data — what we encrypt; recipientCert — the recipient's certificate (.cer/.crt)
const envelope = await enc.encrypt(data, recipientCertFile);
envelope.download('document.p7e'); // or envelope.bytes to your backend
enc.destroy();
API
const envelope = await enc.encrypt(data, recipientCert);
data—File|Uint8Array|ArrayBuffer| string.recipientCert— the recipient's certificate (file or bytes). The certificate must contain a key-agreement key (keyAgreement) — a regular "encryption" certificate issued by a CA (ACSK).- The result is a
Bytesobject with the.p7eenvelope.
Only the holder of the recipient's private key can decrypt the envelope — see Decryption.
Typical flow
A client encrypts a document against your organization's certificate → sends the
.p7e over an open channel → you decrypt it with your key. The content in transit is
inaccessible to anyone, including our service: encryption happens in the browser.