Weave Crypto
Encryption
Recipient sealed-box encryption, error handling, and sender-authentication boundaries.
Purpose
Ed25519, X25519, Merkle hashing, HKDF, random bytes, discovery keys, and namespaces.
Recipient and sender boundary
encrypt and decrypt call sodiumoxide sealed-box operations. The helper manages the ephemeral encryption material; callers do not pass a symmetric nonce. A successful sealed-box open authenticates the ciphertext for the recipient key, but does not identify a sender. Sign a separately defined payload when sender attribution is required.
Primary types to know
EncryptionKeyPair— libs/weave-crypto/src/lib.rsKeyPair— libs/weave-crypto/src/lib.rsNode— libs/weave-crypto/src/lib.rsCryptoError— libs/weave-crypto/src/lib.rsNamespaceCount— libs/weave-crypto/src/lib.rs
Example shape
use weave_crypto::{decrypt, encrypt, encryption_key_pair};
fn main() -> Result<(), Box<dyn std::error::Error>> {
// Curve25519 sealed-box style encryption: a deterministic recipient keypair
// is built from a seed (use None in production for a random keypair).
let recipient = encryption_key_pair(Some(&[0x11; 32]));
// The sender encrypts to the recipient's public key — no shared secret needed.
let plaintext = b"weave secret payload";
let ciphertext = encrypt(plaintext, &recipient.public_key);
// Only the recipient with the matching secret_key can decrypt.
let recovered = decrypt(&ciphertext, &recipient).ok_or("decrypt failed")?;
assert_eq!(recovered, plaintext);
println!("ciphertext={} bytes plaintext_roundtrip_ok", ciphertext.len());
Ok(())
}