@lovelace-ai/lattice-relay-crypto
v0.0.1
Published
End-to-end encryption envelope for relayed personal Lattice work
Maintainers
Readme
@lovelace-ai/lattice-relay-crypto
This package is for Lattice controllers and runtimes that must pass work through an untrusted relay. It seals work with a runtime public key and opens work with the matching private key. The relay receives ciphertext and routing metadata. It never receives the plaintext or private key.
The package is incubating at 0.0.x. Consumers must pin a compatible patch
range until the public contract completes an AI-deslop review.
Install
pnpm add @lovelace-ai/lattice-relay-cryptoSeal and open work
import {
generateWorkKey,
openWork,
sealWork,
} from "@lovelace-ai/lattice-relay-crypto";
const runtimeKey = await generateWorkKey("work-key-2026-08");
const aad = {
latticeId: "lat_01JZ8Q9X1M2N3P4R5S6T7V8W9X",
workId: "work_01JZ8Q9X1M2N3P4R5S6T7V8W9X",
};
const envelope = await sealWork(
new TextEncoder().encode("run this on the selected runtime"),
runtimeKey.publicKey,
aad,
);
const plaintext = await openWork(envelope, runtimeKey.privateKey, aad);The latticeId and workId are authenticated data. Changing either value
causes openWork to throw RelayEnvelopeOpenError. Callers must branch on the
error code instead of parsing the message.
The implementation uses P-256 ECDH, HKDF-SHA-256, and AES-256-GCM. It pads plaintext before encryption and rejects envelopes that exceed the relay size limit before transport starts. Browser and Node.js consumers must provide the Web Crypto API.
Key handling
Store private keys outside relay state. Register only public work keys. Rotate keys by publishing a new key ID while the prior private key remains available for work that is still in flight.
License
MIT
