WebCrypto-backed primitive modules wrapping the platform crypto.subtle.
They are an opt-in, async alternative to the pure-JS crypto suite, which
stays the default. "Choosing pure-JS vs WebCrypto" = which module a consumer
resolves/imports; there is no runtime provider-selector (that orchestration
belongs to consumers, per the fw scope filter).
These modules cover the subset of the fw crypto surface that WebCrypto
implements. SHA-3/SHA-224, BLAKE2b, Argon2, ChaCha20-Poly1305, Poly1305, CMAC
and post-quantum (ml_kem/ml_dsa/slh_dsa) have no WebCrypto equivalent and
remain pure-JS only.
Contract (differs from pure-JS): every operation is async and resolves to
Promise<Result | false> over Uint8Array / CryptoKey (WebCrypto's native
BufferSource/CryptoKey types — not the pure-JS bitArray). No exception
is ever thrown: on an unavailable crypto.subtle, an invalid argument, or a
rejected subtle call, the module logs (console.error/console.warn) and
resolves false. Each module exposes isAvailable(): boolean. All factories
are pure and worker-safe (crypto.subtle is available in Web Workers).
| Module | Returns | Deps | Description |
|---|---|---|---|
| digest | object |
none | SHA-1/256/384/512 one-shot digest (crypto.subtle.digest, FIPS 180-4 subset) |
| hmac | object |
none | HMAC sign/verify over SHA-256/384/512 (+ SHA-1 legacy), RFC 2104 |
| pbkdf2 | object |
none | PBKDF2 deriveBits/deriveKey, default 600 000 iterations (SP 800-132) |
| hkdf | object |
none | HKDF deriveBits/deriveKey, combined extract+expand (RFC 5869) |
| aes | object |
none | AES-GCM/CBC/CTR encrypt/decrypt + key generate/import/export (SP 800-38A/D) |
| aeskw | object |
none | AES-KW key wrap/unwrap (RFC 3394 / SP 800-38F) |
| rsa | object |
none | RSA-OAEP / RSA-PSS / RSASSA-PKCS1-v1_5 + keypair generate/import/export |
| ecc | object |
none | ECDSA + ECDH on P-256/384/521, raw r||s signatures + key formats |
| ed25519 | object |
none | Ed25519 sign/verify + import/export (RFC 8032) |
| x25519 | object |
none | X25519 key agreement + import/export (RFC 7748) |
Common pattern
const webcryptoDigest = fw.runtime.resolve('webcryptoDigest');
if (webcryptoDigest.isAvailable()) {
const digest = await webcryptoDigest.sha256(new TextEncoder().encode('hello'));
// digest is a Uint8Array, or false on failure
}
Notes
- Newer algorithms:
Ed25519andX25519are recent WebCrypto additions; on older engines the underlying calls reject and the methods resolvefalse. - Key formats: import/export is DER (
spki/pkcs8),jwk, orraw— for PEM, use the pure-JSpemmodule.
See also
- Hash, Mode, PKC
— the pure-JS (default, synchronous,
bitArray) counterparts. NIST_CONFORMANCE.md