# Crypto

The `Crypto` interface gives access to a cryptographically strong random number generator and to cryptographic primitives. In Azion Runtime, the global `crypto` object is an instance of `Crypto`, so a function runs these operations without an external library. For more information, refer to [Crypto](https://developer.mozilla.org/en-US/docs/Web/API/Crypto) on MDN Web Docs.

Use `crypto.randomUUID()` to create collision-resistant identifiers for sessions, requests, or traces, and `crypto.getRandomValues()` to build nonces and tokens. Use `crypto.subtle` to hash or digest a request payload and verify its integrity before you forward it. The same property validates a signed token, such as a JWT, inside the function, with no call to an origin.

> **Note**
>
> Under `azion dev`, a call to `crypto.getRandomValues()` with more than 65,536 bytes throws `QuotaExceededError: The requested length exceeds 65,536 bytes`. Both environments accept 65,536 bytes.

---

## Properties

| Property        | Type           | Description                                                                                                                                                                                                            |
| --------------- | -------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `crypto.subtle` | `SubtleCrypto` | Gives access to common cryptographic primitives, such as hashing, signing, encryption, and decryption. For more information, refer to [SubtleCrypto](/en/documentation/devtools/runtime/api-reference/subtle-crypto/). |

---

## Methods

| Method                               | Description                                                                                                                     |
| ------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------- |
| `crypto.getRandomValues(typedArray)` | Fills the typed array you pass with cryptographically strong random values and returns it. Accepts up to 65,536 bytes per call. |
| `crypto.randomUUID()`                | Returns a randomly generated version 4 UUID, a string of 36 characters.                                                         |

A call to `crypto.getRandomValues()` with more than 65,536 bytes throws. The value a `catch` block receives is `undefined`, not an error object: it has no `name` and no `message`. Keep each call at or below 65,536 bytes.

---

## Example

This handler generates a UUID with `crypto.randomUUID()`, then returns it with its length and whether it matches the version 4 format:

```javascript
export default {
  async fetch(request, env, ctx) {
    const uuid = crypto.randomUUID();
    return Response.json({
      value: uuid,
      length: uuid.length,
      v4: /^[0-9a-f]{8}-[0-9a-f]{4}-4[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$/.test(uuid),
    });
  },
};
```

The function returns these values. The UUID differs on every call:

```json
{
 "value": "86cdb8d1-d6c9-44bd-9d61-07812b71c758",
 "length": 36,
 "v4": true
}
```

---

## Related resources

- [SubtleCrypto](/en/documentation/devtools/runtime/api-reference/subtle-crypto.md): The hashing, signing, encryption, and key operations behind `crypto.subtle`.
- [CryptoKey](/en/documentation/devtools/runtime/api-reference/crypto-key.md): The key object that `crypto.subtle` methods generate, import, and use.
- [node:crypto](/en/documentation/devtools/runtime/node/crypto.md): The Node.js crypto module, for code that imports `node:crypto`.
- [Web APIs](/en/documentation/devtools/runtime/api-reference/javascript.md): The other Web APIs that Azion Runtime supports.
