# @doctormckay/steam-crypto

> Node.js implementation of Valve's crypto

Latest version **1.2.0** (published 2017-01-27) · MIT license · 0 weekly downloads

## Install

```sh
npm install @doctormckay/steam-crypto
pnpm add @doctormckay/steam-crypto
yarn add @doctormckay/steam-crypto
bun add @doctormckay/steam-crypto
```

## Health

**Score 15/100 (F)** — status: abandoned.

Positive: no vulnerabilities.

Warnings: low downloads; no types; no esm support.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 1.2.0 |
| Published | 2017-01-27 |
| First published | 2016-04-11 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | none |
| Module format | CommonJS |
| Dependencies | 0 |
| Known vulnerabilities | 0 |
| Install scripts | no |
| Author | Alexander Corn |
| Maintainers | doctormckay |
| Keywords | steam, crypto |

## Links

- npm: https://www.npmjs.com/package/@doctormckay/steam-crypto
- Repository: https://github.com/DoctorMcKay/node-steam-crypto
- Homepage: https://github.com/DoctorMcKay/node-steam-crypto#readme
- Issues: https://github.com/DoctorMcKay/node-steam-crypto/issues
- npm.io page: https://npm.io/package/@doctormckay/steam-crypto

## Alternatives

- [@gemini-wallet/core](https://npm.io/package/@gemini-wallet/core.md) — 515.6K weekly downloads
- [utility](https://npm.io/package/utility.md) — 416.6K weekly downloads
- [@primno/dpapi](https://npm.io/package/@primno/dpapi.md) — 7.2K weekly downloads
- [pi-readseek](https://npm.io/package/pi-readseek.md) — 3.7K weekly downloads
- [@emilia-protocol/verify](https://npm.io/package/@emilia-protocol/verify.md) — 1.1K weekly downloads

## Recent versions

- 1.2.0 (latest) — 2017-01-27
- 1.1.0 — 2016-05-25
- 1.0.0 — 2016-04-13
- 0.0.1 — 2016-04-11

## README

# node-steam-crypto

Node.js implementation of Steam crypto. All keys, data, and signatures are passed as Buffers.

Fork of, and compatible with, [steam-crypto](https://www.npmjs.com/package/steam-crypto).

## verifySignature(data, signature[, algorithm])

Verifies an RSA signature using the Steam system's public key. `algorithm` defaults to "RSA-SHA1". Returns `true` if the signature is valid, or `false` if not.

## generateSessionKey([nonce])
- `nonce` - If you were prompted by Steam with a nonce, provide it here (as a Buffer)

Generates a 32 byte random blob of data and encrypts it with RSA using the Steam system's public key. Returns an object with the following properties:
* `plain` - the generated session key
* `encrypted` - the encrypted session key

If you provided a nonce, then `encrypted` is the RSA'd concatenation of the session key and the nonce (in that order).

## symmetricEncrypt(input, sessionKey[, iv])

Encrypts `input` using `sessionKey` and `iv` (or a securely-random IV if you don't provide one) and returns the result.

## symmetricEncryptWithHmacIv(input, sessionKey)

Encrypts `input` using `sessionKey` and an IV which is partially comprised of an HMAC of the `input`.

## symmetricDecrypt(input, sessionKey[, checkHmac])

Decrypts `input` using `sessionKey` and returns the result.

If the IV in this ciphertext contains an HMAC, pass `true` for `checkHmac` and it will be validated. Otherwise, it will
not be validated (default behavior).

## symmetricDecryptECB(input, sessionKey)

Decrypts `input` using `sessionKey` and the AES/ECB/PKCS7 cipher without an IV and returns the result.

---
_Source: https://npm.io/package/@doctormckay/steam-crypto · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
