just-crypt
v1.0.0
Published
CLI: encrypt/decrypt a string with a password. Argon2id key derivation + 999 rounds of AES-256-CTR + a final AES-256-GCM authentication layer.
Maintainers
Readme
just-crypt
Small Node.js CLI and library for encrypting and decrypting strings with a password.
The format derives a 32-byte key with Argon2id, applies 999 rounds of AES-256-CTR, and protects the result with AES-256-GCM. Every encryption generates a fresh salt and IV.
Requirements
- Node.js 18 or newer
Install
npm install -g just-cryptCLI
just-crypt 'password' 'secret message'
just-decrypt 'password' '<base64 blob>'The encrypt command joins all arguments after the password with a single space. Quote arguments that contain spaces.
Library
import { decrypt, encrypt } from 'just-crypt';
const blob = await encrypt('password', 'secret message');
const plaintext = await decrypt('password', blob);encrypt returns a base64 string. decrypt throws when the password is wrong or the data is malformed or tampered with.
Security notes
The CLI accepts the password as a command-line argument, which may be visible in shell history or process listings. Use the library API when that exposure is unacceptable.
The format is intended for password-based string encryption. It does not provide password recovery, key rotation, or secure password prompting.
Performance
Key derivation uses 1 GiB of memory and encryption performs 999 inner AES-256-CTR rounds. These parameters are part of the format and make each operation intentionally resource-intensive.
License
This project is dual-licensed. You may choose either license:
- Apache License, Version 2.0 (LICENSE-APACHE)
- MIT License (LICENSE)
SPDX-License-Identifier: MIT OR Apache-2.0
