node:crypto
The node:crypto module in Azion Runtime: hashes, HMAC signatures, secure random values, and access to the Web Crypto API, with examples and the supported APIs.
The node:crypto module provides the Node.js cryptographic functions: hashing, HMAC signatures, encryption, decryption, and secure random values. In Node.js, the module wraps the OpenSSL hash, HMAC, cipher, decipher, sign, and verify functions. In Azion Runtime, the module is available through Node.js compatibility, so you can use it inside a function to sign requests, verify message integrity, or generate unique identifiers. Its subtle export, on the named import and on the default export, is the same object as globalThis.crypto.subtle, and the module also exports webcrypto.
Examples
Each example is a complete function that imports from node:crypto. The response below each example is the one a deployed function returns. Random values, such as UUIDs and tokens, differ on every request.
HMAC and UUID generation
This function signs a string with an HMAC key, prints the signature, and responds with a random UUID:
The function responds with the UUID:
Hash generation with SHA-256
This function hashes a fixed string to check data integrity, and hashes the request URL to build a deterministic cache key:
The function responds with both hashes. The digest value is the same on every request; the cacheKey value depends on the request URL, so yours differs:
Random bytes generation
This function generates secure random values for a token, a session ID, and a nonce, and sets the nonce in a Content-Security-Policy header:
The function responds with the three values and sets Content-Security-Policy to script-src 'nonce-<nonce>', where <nonce> is the nonce value of the same response. The values differ on every request:
Web Crypto API integration
The crypto module also gives access to the Web Crypto API through crypto.subtle, which is the same object as globalThis.crypto.subtle. This function generates an AES key, exports it, and encrypts a string with it:
The function responds with a confirmation, after it logs a key length of 32 bytes and an encrypted length of 41 bytes:
Supported APIs
The table lists the status of each node:crypto API in Azion Runtime:
| API | Status |
|---|---|
constants | 🟢 Supported |
createHash() | 🟢 Supported |
createHmac() | 🟢 Supported |
getRandomValues() | 🟢 Supported |
randomBytes() | 🟢 Supported |
randomUUID() | 🟢 Supported |
subtle | 🟢 Supported |
webcrypto | 🟢 Supported |
createCipher() | 🟡 Partially supported |
createDecipher() | 🟡 Partially supported |
createSign() | 🟡 Partially supported |
createVerify() | 🟡 Partially supported |
APIs marked 🟡 Partially supported have limited functionality compared to the full Node.js implementation. For encryption and signing, the Web Crypto API (crypto.subtle) is a more complete alternative. The module also exports functions the table does not list: createCipheriv() and createDecipheriv() encrypt and decrypt with aes-256-cbc, pbkdf2Sync() derives a key from a password, getHashes() is available, and timingSafeEqual() and generateKeyPairSync() work in a deployed function.