Kryptic.Encryption 1.0.3

There is a newer version of this package available.
See the version list below for details.
dotnet add package Kryptic.Encryption --version 1.0.3
                    
NuGet\Install-Package Kryptic.Encryption -Version 1.0.3
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Kryptic.Encryption" Version="1.0.3" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Kryptic.Encryption" Version="1.0.3" />
                    
Directory.Packages.props
<PackageReference Include="Kryptic.Encryption" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Kryptic.Encryption --version 1.0.3
                    
#r "nuget: Kryptic.Encryption, 1.0.3"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Kryptic.Encryption@1.0.3
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Kryptic.Encryption&version=1.0.3
                    
Install as a Cake Addin
#tool nuget:?package=Kryptic.Encryption&version=1.0.3
                    
Install as a Cake Tool

Kryptic.Encryption (.NET)

The C# implementation of Kryptic's open-source (Apache-2.0) encryption engine. This is the package the Kryptic Platform consumes: envelope parsing, Argon2id password hashing, and operational ciphertexts the server itself must read (SSO IdP secrets, directory sync credentials). Customer secret values are end-to-end encrypted on clients; this library is not a decrypt path for those values.

NuGet package id: Kryptic.Encryption (unchanged). This GitHub repository is named Kryptic.Encryption.Net so auditors can tell the three runtimes apart.

Sibling implementations of the same wire formats:

Repository Runtime Consumed by
Kryptic.Encryption.Net .NET (Kryptic.Encryption on nuget.org) Kryptic Platform
Kryptic.Encryption.NPM TypeScript / WebCrypto (@krypticdev/encryption) Management dashboard
Kryptic.Encryption.Go Go Daemon, CLI, Kubernetes operator

A format change (envelope, sealed box, Argon2id parameters) must land in all three repositories in the same release. The committed files in interop-vectors/ are the contract: every runtime must open and, where the test is deterministic, reproduce those bytes.

No custom primitives. The engine composes established, widely audited implementations exclusively:

  • AES-256-GCM via .NET platform cryptography (System.Security.Cryptography.AesGcm)
  • Argon2id via Konscious.Security.Cryptography.Argon2
  • CSPRNG via System.Security.Cryptography.RandomNumberGenerator

Kryptic's engineering lives in the composition: the envelope format, the key hierarchy, nonce management, context binding, and parameter versioning. Never in the primitives. Read SECURITY.md for the full security architecture before reading code.

Install

dotnet add package Kryptic.Encryption

What's in the box

Type Purpose
SecretCipher High-level: encrypt/decrypt string secrets to/from the envelope form, bound to a context
SecretEnvelope The versioned ciphertext container (v1.<keyId>.<nonce>.<ciphertext+tag>)
AesGcmCipher AES-256-GCM with random 96-bit nonces and associated-data support
DataKeys Data-key generation, key ids, and key wrapping (envelope encryption)
SealedBox P-256 ECDH sealed box: encrypt a key to a recipient's public key (end-to-end key delivery)
Argon2KeyDerivation Argon2id passphrase → 256-bit key, with versioned parameter sets
PasswordHasher Argon2id password hashing (argon2id.<params>.<salt>.<hash>)

Usage

Encrypt and decrypt a secret

using Kryptic.Encryption;

byte[] dataKey = DataKeys.GenerateDataKey();
string keyId   = DataKeys.GenerateKeyId();

// Context binds the ciphertext to where it belongs - moving it elsewhere fails decryption.
string context = $"secret:{secretId}:env:{environmentId}";

string stored    = SecretCipher.EncryptString(dataKey, keyId, "postgres://…", context);
string plaintext = SecretCipher.DecryptString(dataKey, stored, context);

Envelope encryption (key hierarchy)

The wrapping key is whoever you pass in. Kryptic secret values are end-to-end encrypted: the org key that opens them exists only on clients (browser, daemon, CI), delivered via SealedBox grants. The platform uses WrapKey/UnwrapKey only for operational ciphertexts it must read itself, such as SSO IdP client secrets, never for your secret values.

// The data key is stored only in wrapped form, never in plaintext.
SecretEnvelope wrapped = DataKeys.WrapKey(wrappingKey, "key_x01", dataKey);
byte[] unwrapped       = DataKeys.UnwrapKey(wrappingKey, wrapped);

Seal a key to a recipient (end-to-end delivery)

// e.g. an admin's browser granting the org key to an approved daemon device.
KeyPair device = SealedBox.GenerateKeyPair();

SealedKey grant  = SealedBox.Seal(device.PublicKey, "device-key-1", orgKey);
byte[] received  = SealedBox.Open(device, grant); // only the device can do this

Derive a key from a passphrase

byte[] salt = Argon2KeyDerivation.GenerateSalt();
byte[] key  = Argon2KeyDerivation.DeriveKey(passphrase, salt); // Argon2id, 64 MiB, 3 passes

Hash a password

string hash = PasswordHasher.Hash(password);
bool ok     = PasswordHasher.Verify(password, hash);

Build & test

dotnet build
dotnet test

Publishing (maintainers)

CI lives in .github/workflows/publish.yml. Pull requests only run tests. A publish on main (or workflow_dispatch) commits the version bump, pushes it as the Kryptic Release Bot, publishes the package, then tags vX.Y.Z and opens a GitHub Release.

GitHub Actions secrets

Add these at the org or on the GitHub repo (Settings > Secrets and variables > Actions):

Secret What it is Where to get it
RELEASE_BOT_APP_ID App ID of Kryptic Release Bot GitHub App settings
RELEASE_BOT_PRIVATE_KEY Private key .pem of that app GitHub App settings > Generate a private key
NUGET_USER nuget.org username used by NuGet trusted publishing nuget.org account that owns the Kryptic.Encryption package. The NuGet/login action exchanges GitHub OIDC for a short-lived API key, so you do not store a long-lived NUGET_API_KEY.

Trusted publishing setup on nuget.org (one-time):

  1. Sign in as the package owner.
  2. Open Trusted Publishing for Kryptic.Encryption.
  3. Register this GitHub repository (dev-kryptic/Kryptic.Encryption.Net), the Build and publish workflow, and the main branch.

If the GitHub repo was renamed from Kryptic.Encryption, update the trusted-publishing registration to dev-kryptic/Kryptic.Encryption.Net or publishes will fail OIDC. On GitHub: Settings > General > Repository name.

No other secrets are required for git. The Release Bot is a ruleset bypass actor and commits the csproj version, the vX.Y.Z tag, and the GitHub Release.

Versioning

Patch versions auto-increment from the latest nuget.org release when major.minor is unchanged. To ship 1.1.0 or 2.0.0, set <Version> in Kryptic.Encryption/Kryptic.Encryption.csproj (or pass it to workflow_dispatch) and the workflow publishes that version as-is.

Reporting vulnerabilities

Please report security issues to security@kryptic.dev. See SECURITY.md for the disclosure process. Do not open public issues for vulnerabilities.

License

Apache-2.0

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
1.1.0 68 9/10/2026
1.0.3 171 9/5/2026
1.0.2 90 9/3/2026
1.0.1 87 9/3/2026