---
source_url: https://www.pubnub.com/docs/serverless-sdk/modules-and-libraries/crypto
title: crypto
updated_at: 2026-09-30T07:20:08.000Z
---

# crypto

## Documentation index

To discover more PubNub resources:

1. Fetch [PubNub's llms.txt](https://www.pubnub.com/llms-full.txt) for a list of available pages in Markdown format.
2. Identify relevant URLs from that index.
3. Fetch the target pages.

Do not assume a path exists, always check the index first.

The `crypto` built-in module is available only inside a PubNub Function. Its asynchronous methods hash, sign, and verify values.

```javascript
const crypto = require('crypto');
```

## ALGORITHM

`crypto.ALGORITHM` lists the supported algorithms: `ED25519`, `ECDSA_P256_SHA1`, `ECDSA_P256_SHA256`, `ECDSA_P256_SHA512`, `HMAC_SHA1`, `HMAC_SHA256`, `HMAC_SHA512`.

```javascript
console.log(crypto.ALGORITHM);
// -> ED25519, ECDSA_P256_SHA1, ECDSA_P256_SHA256, ECDSA_P256_SHA512, HMAC_SHA1, HMAC_SHA256, HMAC_SHA512
```

## hmac

`hmac(key, msg, algorithm)`

| Parameter | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| key | String | Yes |  | Signature key. |
| msg | String | Yes |  | Message to sign. |
| algorithm | String | Yes |  | One of `crypto.ALGORITHM.HMAC_*`. |

Returns: Promise resolving to a Base64-encoded HMAC signature.

```javascript
const crypto = require('crypto');
const base64 = require('codec/base64');
crypto.hmac(base64.btoa('sharedSecretKey'), 'secretPayload', crypto.ALGORITHM.HMAC_SHA1).then((result) => {
    console.log(result);
}).catch((error) => {
    console.log(error);
});
```

## sha1, sha256, sha512

`sha1(msg)`, `sha256(msg)`, `sha512(msg)`

| Parameter | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| msg | String | Yes |  | Message to hash. |

Returns: Promise resolving to the hash of `msg`.

```javascript
const crypto = require('crypto');
crypto.sha256('secretPayload').then((result) => {
    console.log('secretPayload:' + result);
}).catch((error) => {
    console.log(error);
});
```

## sign

`sign(key, msg, algorithm)`

| Parameter | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| key | Object | Yes |  | Private key for signing. |
| msg | String | Yes |  | Message to sign. |
| algorithm | String | Yes |  | One of `crypto.ALGORITHM.*`. |

Returns: Promise resolving to the signature.

A private or public key for `ED25519` takes this shape:

```javascript
const secretKey_ed25519 = {
    kty: 'EdDSA',
    crv: 'Ed25519',
    sk: 'bfk0DBOMwYi1_kRk66o_f8IGotVcNDRwfnTJ_ATiDrs',
    use: 'sig',
};
const publicKey_ed25519 = {
    kty: 'EdDSA',
    crv: 'Ed25519',
    pk: 'wNrBAsRTMYbiXcQxKEcjU-qr24eLFSrrjgAfktkCM6c',
    use: 'sig',
};
```

```javascript
const crypto = require('crypto');
crypto.sign(privateKey, 'secretPayload', crypto.ALGORITHM.ECDSA_P256_SHA1).then((result) => {
    console.log(result);
}).catch((error) => {
    console.log(error);
});
```

## verify

`verify(sig, key, msg, algorithm)`

| Parameter | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| sig | String | Yes |  | Signature to verify. |
| key | Object | Yes |  | Public key for verification. |
| msg | String | Yes |  | Original message. |
| algorithm | String | Yes |  | One of `crypto.ALGORITHM.*`. |

Returns: Promise resolving to the verification result.

```javascript
const crypto = require('crypto');
crypto.verify(existingSignature, publicKey, 'secretPayload', crypto.ALGORITHM.ECDSA_P256_SHA1).then((result) => {
    console.log(result);
}).catch((error) => {
    console.log(error);
});
```

## Related reference

* [Modules and libraries](https://www.pubnub.com/docs/serverless-sdk/modules-and-libraries/overview.md). Every built-in module available inside a Function.
* [codec](https://www.pubnub.com/docs/serverless-sdk/modules-and-libraries/codec.md). Base64 encoding used to prepare keys for `hmac()`.

Last updated at: 2026-09-30T07:20:08.000Z
