Skip to content

Node and browser compatibility ​

The package exposes the same Promise-based class and shared TypeScript interface in Node and browsers. Native ESM, CommonJS, browser bundlers, and the browser global build are covered by consumer smoke checks.

FeatureNodeBrowser
Generate RSA/SPKI + PKCS#8 keysNonblocking crypto.generateKeyPaircrypto.subtle.generateKey
Direct RSA-OAEP encryptionSHA-1 default; SHA-256 opt-inSame
AES-256-GCM hybrid encryptionLegacy default; v1 opt-inSame
RSA-PSS signaturesSHA-256, 32-byte saltSame
JSON encryptionBounded v1 SHA-256 hybrid + schema parserSame
Signed messagesCanonical claims, expiry, atomic replay callbackSame
Strict RSA key helpersAsync parsing; SPKI/PKCS#8Same
PEM formatting helpersSynchronous header/footer checksSame
Buffer methodsAccept Uint8Array/Buffer; return BufferAccept/return Uint8Array
Legacy private-key encrypt / public-key decryptSupportedRejected Promise
Cryptographic operation keysAlso accepts legacy PKCS#1SPKI/PKCS#8 only
Missing-key failureRejected PromiseRejected Promise
Unicode including leading BOMPreservedPreserved

Node 22 and 24 are the CI targets. Browser operations require a secure context and Web Crypto. Browser code has no Node crypto or Buffer dependency. Browser tests execute in Chromium; compatibility with every browser release is not implied.

Both sides may use keys generated on either side. Direct encryption requires an agreed OAEP hash; hybrid v1 payloads identify their hash. Signatures use the same fixed RSA-PSS parameters in both builds. Constructor keys are defaults for operations; key generation returns keys without changing the instance.

For Node CommonJS, use require('encrypt-rsa').default. For Node ESM and browser bundlers, use import NodeRSA from 'encrypt-rsa'. The standalone browser script exposes encryptRSA.NodeRSA and convenience functions for key generation, direct/hybrid strings, signatures, and strict RSA validation.

Released under the MIT License.