# Key backup

Public types and methods for key backup.

[Read the key backup and recovery guide](/docs/key-backup/). Signatures below come from the published SDK declarations. Access SDK services through `db`; use their constructors only when integrating at a lower level.

## KeyEncryptionOptions


```ts
interface KeyEncryptionOptions {
  /** NIP-49 scrypt cost. Defaults to 16 (about 64 MiB); supported range is 10 to 18. */
  logn?: number;
  /** NIP-49 key handling marker: insecure, not known insecure, or untracked (default). */
  keySecurity?: 0 | 1 | 2;
  signal?: AbortSignal;
}
```

## KeyDecryptionOptions


```ts
interface KeyDecryptionOptions {
  signal?: AbortSignal;
}
```

## encryptKey


```ts
/** Encrypt a copied raw private key as an interoperable NIP-49 ncryptsec string. */
declare function encryptKey(
  key: Uint8Array,
  password: string,
  options?: KeyEncryptionOptions,
): Promise<Result<string>>;
```

## decryptKey


```ts
/** Decrypt a bounded NIP-49 envelope. The caller owns and must clear successful key bytes. */
declare function decryptKey(
  ncryptsec: string,
  password: string,
  options?: KeyDecryptionOptions,
): Promise<Result<Uint8Array>>;
```
