# panda-confidential

> Simple, extensible interface for the tweetnacl-js cryptography library

Latest version **3.1.2** (published 2021-11-11) · MIT license · 0 weekly downloads

## Install

```sh
npm install panda-confidential
pnpm add panda-confidential
yarn add panda-confidential
bun add panda-confidential
```

## Health

**Score 20/100 (F)** — status: abandoned.

Positive: esm support; no vulnerabilities.

Warnings: low downloads; no types.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 3.1.2 |
| Published | 2021-11-11 |
| First published | 2018-03-28 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | none |
| Module format | ESM + CommonJS |
| Dependencies | 3 |
| Unpacked size | 127.8 KB |
| Known vulnerabilities | 0 |
| Install scripts | no |
| GitHub stars | 0 |
| Maintainers | dyoder, freeformflow |
| Keywords | encryption, PKE, public key encryption, symmetric encryption, asymmetric encryption, browser, node, universal |

## Links

- npm: https://www.npmjs.com/package/panda-confidential
- Repository: https://github.com/pandastrike/panda-confidential
- Homepage: https://github.com/pandastrike/panda-confidential#readme
- Issues: https://github.com/pandastrike/panda-confidential/issues
- npm.io page: https://npm.io/package/panda-confidential

## Dependencies (3)

- [@dashkite/joy](https://npm.io/package/@dashkite/joy.md) ^0.3.15
- [@dashkite/bake](https://npm.io/package/@dashkite/bake.md) ^0.0.6
- [@dashkite/tweetnacl](https://npm.io/package/@dashkite/tweetnacl.md) ^1.0.3

## Alternatives

- [@opentelemetry/exporter-zipkin](https://npm.io/package/@opentelemetry/exporter-zipkin.md) — 14.8M weekly downloads
- [pusher-js](https://npm.io/package/pusher-js.md) — 2.0M weekly downloads
- [browserify](https://npm.io/package/browserify.md) — 1.7M weekly downloads
- [sqs-consumer](https://npm.io/package/sqs-consumer.md) — 1.7M weekly downloads
- [@sanity/eventsource](https://npm.io/package/@sanity/eventsource.md) — 930.8K weekly downloads

## Recent versions

- 3.1.2 (latest) — 2021-11-11
- 3.1.1 — 2021-11-08
- 3.1.0 — 2021-08-05
- 3.0.2 — 2020-10-17
- 3.0.1 — 2020-09-11
- 3.0.0 — 2019-08-17
- 2.0.0 — 2019-02-07
- 1.0.0 — 2018-10-21
- 0.0.1 — 2018-03-28

## README

# panda-confidential
Simple, extensible interface for the tweetnacl-js cryptography library

## Motivation
Cryptography is hard. Even subtle bugs in implementation can render your efforts insecure.  That inspired the creation of TweetNaCl and its JavaScript port, [TweetNaCl.js][tweetnacl]. TweetNaCl.js is an opinionated bundle of [universal JavaScript][universal] that distills cryptography best practices and is auditable (that is, [making it easier for other security professionals to review it][cure53]). That's good because the code is short and introduces minimal abstraction. However, that lack of abstraction can make the API hard to use.

Panda Confidential aims to make Tweet NaCl easier to use—and extend—with minimal reduction in auditability.

[tweetnacl]: https://github.com/dchest/tweetnacl-js#documentation
[universal]: https://medium.com/@ghengeveld/isomorphism-vs-universal-javascript-4b47fb481beb
[cure53]:https://cure53.de/tweetnacl.pdf


## Usage
Because panda-confidential is extensible, you must instantiate a new instance before using it. This helps prevent unexpected changes by third parties.

```coffeescript
import {confidential} from "panda-confidential"

do ->
  # Instantiate Panda-Confidential
  {encrypt, decrypt, key} = confidential()
```

Panda-confidential wraps the TweetNaCl.js interface with three pairs of opposing functions:
1. `encrypt` and `decrypt`
2. `sign` and `verify`
3. `encode` and `decode`

These functions are [_generics_][generics] and infer intent based on their arguments. For example, if you invoke `encrypt` with a symmetric key, you get symmetric encryption. 

```coffeescript
  # Generate symmetric key of correct length that should be saved.
  myKey = await key.Symmetric()

  # Person A symmetrically encrypts their data.
  message = "Hello World!"
  ciphertext = await encrypt myKey, message
```

The details -- key length, ensuring a robust source of randomness, encryption algorithm, etc -- are all handled by TweetNaCl.js.  `encrypt` and the key type system just provides a super simple interface for that power.

Use `decrypt` to retrieve the data just as simply.
```coffeescript
  # Later, Person A decrypts that ciphertext.
  output = await decrypt myKey, ciphertext
```

Please see the [full API documentation][api-docs] for more detailed information about key types and function pairs.

[generics]: https://en.wikipedia.org/wiki/Generic_programming

## Installation

For the browser, bundle using your favorite bundler:

```
npm i -s panda-confidential
```

[Full API Documentation][api-docs]

[api-docs]:https://github.com/pandastrike/panda-confidential/blob/master/API.md

---
_Source: https://npm.io/package/panda-confidential · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
