Weave documentation
Weave Crypto

Encryption

Recipient sealed-box encryption, error handling, and sender-authentication boundaries.

Purpose

Ed25519, X25519, Merkle hashing, HKDF, random bytes, discovery keys, and namespaces.

Recipient and sender boundary

encrypt and decrypt call sodiumoxide sealed-box operations. The helper manages the ephemeral encryption material; callers do not pass a symmetric nonce. A successful sealed-box open authenticates the ciphertext for the recipient key, but does not identify a sender. Sign a separately defined payload when sender attribution is required.

Primary types to know

  • EncryptionKeyPair — libs/weave-crypto/src/lib.rs
  • KeyPair — libs/weave-crypto/src/lib.rs
  • Node — libs/weave-crypto/src/lib.rs
  • CryptoError — libs/weave-crypto/src/lib.rs
  • NamespaceCount — libs/weave-crypto/src/lib.rs

Example shape

use weave_crypto::{decrypt, encrypt, encryption_key_pair};

fn main() -> Result<(), Box<dyn std::error::Error>> {
    // Curve25519 sealed-box style encryption: a deterministic recipient keypair
    // is built from a seed (use None in production for a random keypair).
    let recipient = encryption_key_pair(Some(&[0x11; 32]));

    // The sender encrypts to the recipient's public key — no shared secret needed.
    let plaintext = b"weave secret payload";
    let ciphertext = encrypt(plaintext, &recipient.public_key);

    // Only the recipient with the matching secret_key can decrypt.
    let recovered = decrypt(&ciphertext, &recipient).ok_or("decrypt failed")?;
    assert_eq!(recovered, plaintext);

    println!("ciphertext={} bytes plaintext_roundtrip_ok", ciphertext.len());
    Ok(())
}

On this page