SubtleCrypto
The SubtleCrypto interface of Azion Runtime: its methods for hashing, signing, encryption, key derivation, and key wrapping through crypto.subtle.
The SubtleCrypto interface holds the low-level cryptographic functions of the Web Crypto API in Azion Runtime. A function reaches it through the subtle property of the global crypto object. That property holds an instance of SubtleCrypto. Use it to hash data, sign and verify messages, encrypt and decrypt, and derive, import, export, and wrap keys. For more information, refer to SubtleCrypto on MDN Web Docs.
Methods
SubtleCrypto has no parent interface, so it inherits no methods. Every method returns a promise:
| Method | Description |
|---|---|
crypto.subtle.encrypt(algorithm, key, data) | Fulfills with the encrypted form of data, produced with key and algorithm. AES-GCM encrypts with a 256-bit key and an iv. |
crypto.subtle.decrypt(algorithm, key, data) | Fulfills with the clear data recovered from the encrypted data, using key and algorithm. |
crypto.subtle.sign(algorithm, key, data) | Fulfills with the signature of data, computed with key and algorithm. HMAC, ECDSA, RSA-PSS, and Ed25519 sign data. An RSA-PSS signature with a 2048-bit key is 256 bytes, and an Ed25519 signature is 64 bytes. |
crypto.subtle.verify(algorithm, key, signature, data) | Fulfills with true when signature matches data under key and algorithm, and with false when it does not, such as after data changes. |
crypto.subtle.digest(algorithm, data) | Fulfills with the digest of data computed with algorithm. SHA-1, SHA-256, SHA-384, and SHA-512 produce 20, 32, 48, and 64 bytes. MD5 rejects with NotSupportedError: Unrecognized algorithm name. |
crypto.subtle.generateKey(algorithm, extractable, keyUsages) | Fulfills with a CryptoKey for a symmetric algorithm, or a CryptoKeyPair with privateKey and publicKey for an asymmetric one. The keys take the algorithm, usages, and extractability you pass. It generates AES-GCM, AES-KW, ECDSA on the P-256 curve, RSA-PSS, and Ed25519 keys. |
crypto.subtle.deriveKey(algorithm, baseKey, derivedKeyAlgorithm, extractable, keyUsages) | Fulfills with a CryptoKey derived from baseKey with algorithm. PBKDF2 with SHA-256 derives a 256-bit AES-GCM key. |
crypto.subtle.deriveBits(algorithm, baseKey, length) | Fulfills with a buffer of pseudo-random bits derived from baseKey with algorithm. length is the number of bits. |
crypto.subtle.importKey(format, keyData, algorithm, extractable, keyUsages) | Fulfills with a CryptoKey built from keyData in format. The key takes the algorithm, usages, and extractability you pass. It imports a raw key for HMAC or PBKDF2. |
crypto.subtle.exportKey(format, key) | Fulfills with the key data of key in format, such as raw or jwk. exportKey() rejects a key created with extractable set to false, with InvalidAccessError: Key is not extractable. |
crypto.subtle.wrapKey(format, key, wrappingKey, wrapAlgorithm) | Fulfills with key exported in format and encrypted with wrappingKey and wrapAlgorithm. Use it to transfer or store a symmetric key in an untrusted environment. A 256-bit AES-GCM key wrapped in raw format with AES-KW is 40 bytes. |
crypto.subtle.unwrapKey(format, wrappedKey, unwrappingKey, unwrapAlgorithm, unwrappedKeyAlgorithm, extractable, keyUsages) | Fulfills with the CryptoKey that wrappedKey holds, decrypted with unwrappingKey and unwrapAlgorithm. |
Example
This handler imports a secret as an HMAC key, signs a message, and verifies the signature against the message and against altered data. It returns the signature, the two results, and the properties of the key with Response.json():
The function returns these values. rejectsTampered is true because verify() returns false for the altered data: