Skip to content

Latest commit

Β 

History

49 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

WebCrypt v1.0.1

Zero-dependency Web Crypto & native AI Agent Tooling (MCP) for modern JavaScript.

npm version npm downloads Node TypeScript MCP Tests Coverage PuterVision Triad License: MIT

AES-256-GCM symmetric encryption, RSA-4096 hybrid public keys, ECDH key agreement, ECDSA/HMAC digital signatures, and Post-Quantum KEM (Kyber/Dilithium) β€” zero runtime dependencies, pure Web Crypto API.


⚑ Quickstart (15 Seconds)

1. Installation

# πŸ“¦ Install as project library (Node.js, TypeScript, Browser)
npm install webcrypt

# 🌐 Install globally (CLI utilities & global MCP tools)
npm install -g webcrypt
import { WebCrypt, WebCryptAsym } from "webcrypt";

// πŸ”’ Symmetric AES-256-GCM (600k PBKDF2 iterations)
const wc = new WebCrypt();
const encrypted = await wc.encryptText("Secret payload", "password");
const decrypted = await wc.decryptText(encrypted, "password");

// πŸ”‘ Asymmetric RSA-4096 Hybrid Encryption
const wca = new WebCryptAsym();
const keyPair = await wca.generateKeyPair(4096);
const cipher = await wca.encryptText("Secret payload", keyPair.publicKey);
const plain = await wca.decryptText(cipher, keyPair.privateKey);

2. Auto-Setup for AI Agents & IDEs (MCP Server)

# Initialize MCP server, agent skills, and rules across your project
npx webcrypt init  # or `webcrypt init` if installed globally

Supports Google Antigravity, Cursor, Claude Desktop, VS Code / Copilot, Windsurf, Cline, and Zed.


πŸ€– Why AI Agents Need WebCrypt MCP

Equip autonomous coding agents with an authenticated cryptographic vault directly in their toolbelt:

  • πŸ” Confidential Local Vaulting (encrypt_payload): Encrypt API keys and state memory before writing to disk to prevent prompt log leaks.
  • πŸ›‘οΈ Tamper-Proof Provenance (sign_verify): Cryptographically sign test evidence packs, release binaries, and code diffs with ECDSA or HMAC.
  • 🀝 Inter-Agent Key Exchange (manage_keys): Ephemeral JWK keypairs (RSA-4096, ECDH P-256/P-384) for private agent-to-agent messaging.
  • βš›οΈ Post-Quantum Guardrails (pqc_kem_sign): Built-in Kyber KEM and Dilithium signatures future-proof long-term agent artifacts.
  • ⚑ Zero Dependencies: 100% native crypto.subtle execution across Node.js 18+, Bun, browsers, and Edge runtimes.
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚              Autonomous AI Coding Agent                   β”‚
β”‚     (Antigravity / Cursor / Claude / Copilot / Cline)     β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”¬β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
          β”‚                   β”‚                   β”‚
          β–Ό                   β–Ό                   β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ state-memory-mcp  β”‚β”‚ vision-memory-mcp β”‚β”‚     webcrypt      β”‚
β”‚  (Workflow State) β”‚β”‚  (Visual Cache)   β”‚β”‚  (Security Vault) β”‚
β”‚  β€’ Task Graph DAG β”‚β”‚  β€’ UI Grounding   β”‚β”‚  β€’ AES-256 Vault  β”‚
β”‚  β€’ Decisions & SDDβ”‚β”‚  β€’ Layout Trees   β”‚β”‚  β€’ RSA/ECDH Keys  β”‚
β”‚  β€’ Event Ledger   β”‚β”‚  β€’ Visual History β”‚β”‚  β€’ Digital Sigs   β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

πŸ› οΈ MCP Tools Reference (6 Core Tools)

Tool Action / Mode Description
encrypt_payload symmetric | asymmetric | data Encrypt text, JSON objects, or files with AES-256-GCM or RSA-4096.
decrypt_payload symmetric | asymmetric | data Decrypt ciphertext back to plaintext or structured JSON.
manage_keys generate | generate_random_password Generate JWK keypairs (RSA, ECDH, ECDSA, RSA-PSS) or high-entropy passwords.
crypto_hash SHA-256 | SHA-512 | SHA-3 Compute cryptographic hash digests in hex or base64.
sign_verify sign | verify Sign and verify messages, release hashes, and evidence packs.
pqc_kem_sign kyber_* | dilithium_* | hybrid_* Post-quantum Kyber KEM encapsulation and Dilithium signatures.

πŸ“š Technical Documentation Directory

Explore dedicated guides in docs/ and examples/:

Guide Topic
πŸš€ Live Interactive Playground Test all crypto features in the browser demo.
πŸ’» CLI Reference Guide Scaffolding, global project scanning, and terminal utilities.
βš™οΈ Multi-IDE MCP Setup Guide Step-by-step MCP JSON configs for all major IDEs.
πŸ”’ Symmetric Encryption API (WebCrypt) AES-256-GCM, streaming files, WebRTC E2EE, PBKDF2.
πŸ”‘ Asymmetric Encryption API (WebCryptAsym) RSA-4096 hybrid, ECDH key agreement, ECDSA/RSA-PSS.
βš›οΈ Post-Quantum Cryptography Guide Kyber KEM, Dilithium signatures, and Hybrid KEM.
πŸ—οΈ Architecture & MCP Specifications Stdio JSON-RPC 2.0 protocol and chunk framing specs.
πŸ€– Agent Skill Definition Custom agent skill with automated test runner script.
πŸ“‹ Project Instructions Template Multi-agent rules template (<!-- webcrypt-mcp:start -->).
πŸ’‘ Code Examples Directory Ready-to-run Node.js & browser recipes.

🌐 PuterVision Triad Standard

  • πŸ“Š @putervision/state-memory-mcp: Persistent SQLite graph for workflow states, task DAGs, and decision trails.
  • πŸ‘οΈ @putervision/vision-memory-mcp: Multimodal visual layout cache, AX grounding, and video replay analysis.
  • πŸ” webcrypt: Zero-dependency cryptographic vault, payload encryption, key management, and digital signatures.

πŸ§ͺ Testing & Diagnostics

# Run unit & integration test matrix (30 suites, 247 tests)
npm test

# Run live MCP tool test runner (25 assertions, 100% verified)
node .agents/skills/webcrypt-mcp/scripts/exercise_tools.js

# Audit environment & project configuration health
webcrypt doctor

βš–οΈ License & Disclaimers

Developed and maintained by PuterVision. Released under the MIT License.

  • 100% Local Execution Guarantee: All cryptographic operations execute locally in memory via standard W3C Web Crypto API (crypto.subtle). Zero external API calls, telemetry, or network transmissions.
  • Trademarks & Non-Affiliation: Product names (Cursor, Claude, Google Antigravity, VS Code, GitHub Copilot, Windsurf, Cline, Zed) are property of their respective owners and used solely for compatibility identification.

About

Zero-dependency Web Crypto suite & Model Context Protocol (MCP) server for AES-256-GCM, RSA-4096, and AI agent security.

Topics

Resources

Contributing

Security policy

Stars

27 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages