WebCrypt v1.0.1
Zero-dependency Web Crypto & native AI Agent Tooling (MCP) for modern JavaScript.

AES-256-GCM symmetric encryption, RSA-4096 hybrid public keys, ECDH key agreement, ECDSA/HMAC digital signatures, and Post-Quantum KEM (Kyber/Dilithium) โ zero runtime dependencies, pure Web Crypto API.
โก Quickstart (15 Seconds)
1. Installation
npm install webcrypt
npm install -g webcrypt
import { WebCrypt, WebCryptAsym } from "webcrypt";
const wc = new WebCrypt();
const encrypted = await wc.encryptText("Secret payload", "password");
const decrypted = await wc.decryptText(encrypted, "password");
const wca = new WebCryptAsym();
const keyPair = await wca.generateKeyPair(4096);
const cipher = await wca.encryptText("Secret payload", keyPair.publicKey);
const plain = await wca.decryptText(cipher, keyPair.privateKey);
2. Auto-Setup for AI Agents & IDEs (MCP Server)
Supports Google Antigravity, Cursor, Claude Desktop, VS Code / Copilot, Windsurf, Cline, and Zed.
๐ค Why AI Agents Need WebCrypt MCP
Equip autonomous coding agents with an authenticated cryptographic vault directly in their toolbelt:
- ๐ Confidential Local Vaulting (
encrypt_payload): Encrypt API keys and state memory before writing to disk to prevent prompt log leaks.
- ๐ก๏ธ Tamper-Proof Provenance (
sign_verify): Cryptographically sign test evidence packs, release binaries, and code diffs with ECDSA or HMAC.
- ๐ค Inter-Agent Key Exchange (
manage_keys): Ephemeral JWK keypairs (RSA-4096, ECDH P-256/P-384) for private agent-to-agent messaging.
- โ๏ธ Post-Quantum Guardrails (
pqc_kem_sign): Built-in Kyber KEM and Dilithium signatures future-proof long-term agent artifacts.
- โก Zero Dependencies: 100% native
crypto.subtle execution across Node.js 18+, Bun, browsers, and Edge runtimes.
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ Autonomous AI Coding Agent โ
โ (Antigravity / Cursor / Claude / Copilot / Cline) โ
โโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโ
โ โ โ
โผ โผ โผ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ state-memory-mcp โโ vision-memory-mcp โโ webcrypt โ
โ (Workflow State) โโ (Visual Cache) โโ (Security Vault) โ
โ โข Task Graph DAG โโ โข UI Grounding โโ โข AES-256 Vault โ
โ โข Decisions & SDDโโ โข Layout Trees โโ โข RSA/ECDH Keys โ
โ โข Event Ledger โโ โข Visual History โโ โข Digital Sigs โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
| Tool | Action / Mode | Description |
|---|
encrypt_payload | symmetric | asymmetric | data | Encrypt text, JSON objects, or files with AES-256-GCM or RSA-4096. |
decrypt_payload | symmetric | asymmetric | data | Decrypt ciphertext back to plaintext or structured JSON. |
manage_keys | generate | generate_random_password | Generate JWK keypairs (RSA, ECDH, ECDSA, RSA-PSS) or high-entropy passwords. |
crypto_hash | SHA-256 | SHA-512 | SHA-3 | Compute cryptographic hash digests in hex or base64. |
sign_verify | sign | verify | Sign and verify messages, release hashes, and evidence packs. |
pqc_kem_sign | kyber_* | dilithium_* | hybrid_* | Post-quantum Kyber KEM encapsulation and Dilithium signatures. |
๐ Technical Documentation Directory
Explore dedicated guides in docs/ and examples/:
๐ PuterVision Triad Standard
- ๐
@putervision/state-memory-mcp: Persistent SQLite graph for workflow states, task DAGs, and decision trails.
- ๐๏ธ
@putervision/vision-memory-mcp: Multimodal visual layout cache, AX grounding, and video replay analysis.
- ๐
webcrypt: Zero-dependency cryptographic vault, payload encryption, key management, and digital signatures.
๐งช Testing & Diagnostics
npm test
node .agents/skills/webcrypt-mcp/scripts/exercise_tools.js
webcrypt doctor
โ๏ธ License & Disclaimers
Developed and maintained by PuterVision. Released under the MIT License.
- 100% Local Execution Guarantee: All cryptographic operations execute locally in memory via standard W3C Web Crypto API (
crypto.subtle). Zero external API calls, telemetry, or network transmissions.
- Trademarks & Non-Affiliation: Product names (Cursor, Claude, Google Antigravity, VS Code, GitHub Copilot, Windsurf, Cline, Zed) are property of their respective owners and used solely for compatibility identification.