Documentation · Widgets

Encryption

The encrypt widget creates an encrypted CMS EnvelopedData envelope using the DSTU 7624:2014 Kalyna cipher. Encryption is performed against the recipient's certificate — no private key is needed, so this is a secret-free widget.

Paid option. Encryption and decryption are a separate add-on, "Encryption and decryption" (see pricing), enabled per domain. Without it, encrypt/decrypt return an error with error.code === 'ENCRYPTION_NOT_ENABLED' (during the trial / on localhost it is available for testing).

Example

import { embed } from 'https://dstucrypt.io/embed/dstucrypt-embed.mjs';

const enc = await embed('encrypt');

//  data — what we encrypt; recipientCert — the recipient's certificate (.cer/.crt)
const envelope = await enc.encrypt(data, recipientCertFile);

envelope.download('document.p7e');       //  or envelope.bytes to your backend
enc.destroy();

API

const envelope = await enc.encrypt(data, recipientCert);
  • data — File | Uint8Array | ArrayBuffer | string.
  • recipientCert — the recipient's certificate (file or bytes). The certificate must contain a key-agreement key (keyAgreement) — a regular "encryption" certificate issued by a CA (ACSK).
  • The result is a Bytes object with the .p7e envelope.

Only the holder of the recipient's private key can decrypt the envelope — see Decryption.

Typical flow

A client encrypts a document against your organization's certificate → sends the .p7e over an open channel → you decrypt it with your key. The content in transit is inaccessible to anyone, including our service: encryption happens in the browser.