Read the key backup and recovery guide. Signatures below come from the published SDK declarations. Access SDK services through db; use their constructors only when integrating at a lower level.
KeyEncryptionOptions
interface KeyEncryptionOptions {
/** NIP-49 scrypt cost. Defaults to 16 (about 64 MiB); supported range is 10 to 18. */
logn?: number;
/** NIP-49 key handling marker: insecure, not known insecure, or untracked (default). */
keySecurity?: 0 | 1 | 2;
signal?: AbortSignal;
}
KeyDecryptionOptions
interface KeyDecryptionOptions {
signal?: AbortSignal;
}
encryptKey
/** Encrypt a copied raw private key as an interoperable NIP-49 ncryptsec string. */
declare function encryptKey(
key: Uint8Array,
password: string,
options?: KeyEncryptionOptions,
): Promise<Result<string>>;
decryptKey
/** Decrypt a bounded NIP-49 envelope. The caller owns and must clear successful key bytes. */
declare function decryptKey(
ncryptsec: string,
password: string,
options?: KeyDecryptionOptions,
): Promise<Result<Uint8Array>>;