Transaction API

EncryptionUtil

List of Classes

CommonController

TransactionController

AjaxResponse

AnalyticDataViewFilter

Archive

ArchiveManager

AreaChart

Attachment

AudioFile

BarChart

BillingEngine

BillingEvent

Browser

Buffer

BusinessUtil

CacheManager

Cell

CellFilter

Chart

ChartSharedSettings

ChartTool

Chunk

ClientSocket

ClientSocketManager

CommonPacket

ConsoleManager

ConsolePacket

ConsoleResponse

Cube

Data

DataList

DataListFilter

DataReader

DataRecord

DataSet

DataSetRecord

DataSetResult

DataView

DataViewBuilder

DataViewCriteria

DataViewFilter

DataViewList

DataViewRecord

DatasetFile

DateUtil

DisplaySettings

Document

DocumentFile

DownloadResponse

Email

EncryptionUtil

Enterprise

EnterpriseInfo

ExcelFile

File

FileBuffer

Formatter

Fragment

FtpRequest

GeoUtil

GroupConcat

ImageFile

Inspector

Installer

InstallerPal

InvoiceInfo

JSONBuffer

JSONParser

Job

JobManager

LineChart

LockManager

Logger

MailBox

MailBoxList

MailMessage

MailResponse

Message

MessageManager

Modules

Monitor

PWA

Packet

PacketDataList

PacketDataRecord

Page

PagingInfo

Pal

PalActivationKeyInfo

PalInfo

Payload

PdfFile

PieChart

Profile

ProfileInfo

ProfilePacket

ProfilePalManager

ProfileTxManager

QRUtil

Render

Request

Role

RuntimePal

SSOToken

SafeBox

ScatterPlotChart

ServiceRequest

ServiceResponse

ShellPal

ShellPalManager

SignSettings

SiteBuilder

Slice

SmartDoc

SmartDocManager

Socket

SocketResponse

StorageProvider

StorageProviderDataList

StoredObject

SystemDataView

SystemDataViewFilter

TextEmail

TextMessage

TiffBuilder

TransactionPacket

TransactionUtil

Tunnel

TunnelResult

UnknownFile

Upload

User

VCardFile

Validator

ValidityCheck

Wizard

WorkflowResponse

XMLReader

ZoneAccess

Provides utility methods for message digests, HMAC, symmetric (AES) and asymmetric (RSA, EC) encryption and signing, PGP/CSR/PKCS12 key material, OTP, web push encryption and related conversions. All string conversions are made using UTF-8 encoding. In case of encryption/digest/encoding errors all methods of this class will throw workflow exception that should be handled by Pal developer

Method Summary
String ECDSASign(String message, String privateKey)

Signs a message with the given key using ECDSA along the P-256 curve and SHA-256 hash. Result is base64url encoded.

boolean authorizeOtp(String secretKey, int passcode)

Returns true on successful OTP authentication.

String base16toBase64(String base16)

Converts Base 16 encoded content into Base 64 encoded content

String base64toBase16(String base64)

Converts Base 64 encoded content into Base 16 encoded content

String base64toURLSafe(String base64)

Converts a base64 encoded string to a base64url string.

String createAESKey(int length)

Creates an AES key of the specified length and returns the Base64 encoded raw value.

Data createCSR(String privateKey, Data subjectInfo)

Generates a PKCS#10 Certificate Signing Request for an existing key pair. Returns a Data with one field, csr, containing the PEM-encoded CSR ready to submit to a CA.

Data createECDHKeyPair()

Generates an EC key pair on the P-256 curve. Returns a Data with five values: publicKeyRaw and privateKeyRaw (raw key bytes, Base64url encoded), publicKeyX509 and privateKeyPKCS8 (PEM encoded), and publicKeyPKCS1 (PEM encoded, EC-specific format).

Data createKeyStore(String privateKey, String certificate, DataList caChain, String password)

Assembles a PKCS12 keystore from a private key, its signed certificate, and the issuing chain. Returns a Data with one field, keystore, containing the Base64 encoded PKCS12 bytes.

String createNonce(int length)

Creates a nonce (AKA salt) of the specified length and returns the Base64 encoded raw value.

Data createOtpAuth(String issuer, String accountName)

Returns information that can be used for an OTP Auth service. See QRUtil to create an image from the url.

int createOtpPassCode(String secretKey)

Creates an OTP pass code.

Data createPGPKeyPair(String password)

Returns a Data with two values: privateKey and publicKey. Key size is 1024. Content is Base64 encoded.

Data createRSAKeyPair(int keySize)

Returns a Data with two values: privateKey and publicKey, generated at the requested keySize (up to 3072 bits). Content is Base64 encoded.

Data decodeCertificate(String certificate)

Decodes an X.509 certificate given as PEM or as Base64 encoded DER (for example ServiceResponse.readBase64 of a downloaded .crt). Returns a Data with: pem (the certificate as PEM with 64 character lines, ready for a certificate DataList), subject and issuer (RFC 2253 form), serialNumber, notBefore and notAfter (ISO 8601 UTC), notAfterMinutes (whole minutes from now until notAfter, zero or negative if expired, useful as the expiry of CacheManager.put), caIssuersUrl (the first HTTP(S) 'CA Issuers' address in the Authority Information Access extension, where the issuing certificate can be downloaded; empty if none) and ocspUrl (empty if none).

MailResponse decodeMessage(String message)

Decodes a raw email message.

Payload decodeTimestampResponse(String base64)

Decodes a Base64 encoded RFC 3161 TimeStampResp (as returned by a timestamp authority, see ServiceResponse.readBase64). Returns a Payload with a Data named 'timestamp' and a DataList named 'timestampChain'. The Data has: status (0 granted, 1 granted with modifications, 2 rejection, 3 waiting, 4 revocation warning, 5 revocation notification), statusText, and, if granted, token (Base64 timeStampToken to pass as the 'timestamp' of applyExternalSignature), genTime (ISO 8601 UTC), serialNumber, imprintAlgorithm and imprint (Base16 hash the token stamps; compare it to sha256Base16FromBase16 of the signature). The DataList has one 'certificate' column (PEM), one row per certificate embedded in the token, ordered TSA certificate first then its issuers; it is empty if the response was not granted or the timestamp authority did not include certificates.

String decrypt(String encrypted)

Decrypts the content using the cloud supplied encryption key. See encrypt(string).

String decryptAES(String key, String content)
⚠Deprecated since 09-28-2026. See encryptAES. Use decryptAESGCM instead.

Decrypts the content using the specified AES key (the same key passed to encryptAES). Content is expected to be Base64 encoded.

String decryptAESGCM(String key, String content)

Decrypts content produced by encryptAESGCM, using the same AES key. Content is expected to be Base64 encoded and to include the 12-byte nonce prepended by encryptAESGCM.

String decryptRSA(String publicKey, String content)

Decrypts content produced by encryptRSA, using the matching public key. This is the counterpart to encryptRSA only - it is not a signature-verification method and will not accept output from rsaSha1/rsaSha256. Content is expected to be Base64 encoded.

String encrypt(String content)

Encrypts the content using the cloud supplied encryption key and returns it as Base16 (hex). See decrypt(string).

String encryptAES(String key, String content)
⚠Deprecated since 09-28-2026. Uses AES/ECB with no IV, which is not semantically secure (identical plaintext blocks produce identical ciphertext). Use encryptAESGCM instead.

Encrypts the content using the specified Base64 AES key. Result is Base64 encoded.

String encryptAESGCM(String key, String content)

Encrypts the content using the specified Base64 AES key with AES/GCM (authenticated encryption). A random 12-byte nonce is generated per call and prepended to the ciphertext before Base64 encoding, so the result is self-contained - pass it directly to decryptAESGCM with the same key.

String encryptPushPayload(String plaintext, String salt, String localPrivateKey, String localPublicKey, String uaPublicKey, String authSecret)

Performs encryption on a web push message using the aesgcm spec.

String encryptRSA(String privateKey, String content)

Encrypts the content using the specified private key. This proves the ciphertext came from the private-key holder (anyone with the matching public key can decrypt it via decryptRSA) - it does NOT keep the content secret from third parties. For actual confidentiality (only the private-key holder can read it), this class does not currently expose an encrypt-with-public-key operation. Result is Base64 encoded.

String fromBase16(String base16)

Decodes the Base16 content and attempts to return it as a string

String fromBase64(String base64)

Decodes the Base64 content and attempts to return it as a string

String hmacMd5(String key, String str)

Creates MD5-hashed message authentication code for a string. Result is Base16 encoded.

String hmacSha1(String key, File file, boolean isBase64Key)

Creates SHA1-hashed message authentication code for a file and returns it as Base64.

String hmacSha1(String key, String str, boolean isBase64Key)

Creates SHA1-hashed message authentication code for a string. Result is Base64 encoded.

String hmacSha256(String key, String str, boolean isBase64Key)

Creates SHA256-hashed message authentication code for a string. Result is Base64 encoded.

String md5(File file)

Calculates MD5 digest for a file and returns it as Base64.

String md5(String str)

Calculates MD5 digest for a string and returns it as Base64.

String md5Base16(File file)

Calculates MD5 digest for a file and returns it as Base16.

String md5Base16(String str)

Calculates MD5 digest for a string and returns it as Base16.

String pSha1(String requestEntropy, String serviceEntropy, int key length)

Creates P_SHA1 key with specifid length. See RFC 2246 section 5: HMAC and the pseudorandom function. Result is Base64 encoded.

String rsaSha1(String privateKey, String content)

Creates a base64 encoded RSA-SHA1 signature for the string, signed with the given private key. To verify a signature produced this way, use verifySha1RsaSignature (not decryptRSA - the output here is a signature, not ciphertext). Note that key should be provided as base 64 string (PEM) PKCS8 or X509.

String rsaSha256(String privateKey, String content)

Creates a base64 encoded RSA-SHA256 signature for the string, signed with the given private key. To verify a signature produced this way, use verifySha256RsaSignature (not decryptRSA - the output here is a signature, not ciphertext). Note that key should be provided as base 64 string (PEM) PKCS8 or X509.

String sha1(File file)

Calculates SHA1 digest for a file and returns it as Base64.

String sha1(String str)

Calculates SHA1 digest for a string and returns it as Base64.

String sha1Base16(File file)

Calculates SHA1 digest for a file and returns it as Base16.

String sha1Base16(String str)

Calculates SHA1 digest for a string and returns it as Base16.

String sha256(String str)

Calculates SHA256 digest for a string and returns it as Base64.

String sha256Base16(String str)

Calculates SHA256 digest for a string and returns it as Base16.

String sha256Base16FromBase16(String base16, boolean timestampRequest)

Calculates SHA256 digest of the raw bytes that a Base16 (hex) string represents and returns it as Base16. Unlike sha256Base16, which hashes the characters of a string, this hashes the decoded bytes, so it works for binary values such as the hex encoded signature returned by a signing service. An RFC 3161 signature timestamp must imprint the hash of the signature value, not the document digest. When timestampRequest is true, the digest is not returned; instead it is wrapped in a DER encoded RFC 3161 TimeStampReq (SHA-256 imprint, no nonce, certReq=TRUE so the timestamp authority includes its certificates in the token) and returned as Base16. Send the request bytes (Base16 converted with base16toBase64 and set with ServiceRequest.setBinaryBody, content type application/timestamp-query) to the timestamp authority, then pass the Base64 reply (ServiceResponse.readBase64) to decodeTimestampResponse.

String sha512Base16(String str, int iterations)

Calculates SHA512 digest for an input over n iterations and returns it as Base16.

String toBase16(File file)

Converts file content into Base 16 encoded content.

String toBase16(String str)

Converts string bytes into Base 16 encoded content

String toBase64(File file)

Converts file content into Base 64 encoded content.

String toBase64(String str)

Converts string bytes into Base 64 encoded content

String toBase64URL(String str)

Converts string bytes into Base 64 URL encoded content.

boolean verifySha1RsaSignature(File x509Cert, String base64Signature, String canonicalMessage)

Verifies the base64 encoded signature against the x509 public certificate and non encoded canonical message

boolean verifySha256RsaSignature(File x509Cert, String base64Signature, String canonicalMessage)

Verifies the base64 encoded signature against the x509 public certificate and non encoded canonical message

Method Detail


String ECDSASign(String message, String privateKey)

Signs a message with the given key using ECDSA along the P-256 curve and SHA-256 hash. Result is base64url encoded.

Parameters:

  • String   message Required parameter.
  • String   privateKey Required parameter.

Returns:  String

Since: 02-03-2025

top

boolean authorizeOtp(String secretKey, int passcode)

Returns true on successful OTP authentication.

Parameters:

  • String   secretKey Required parameter.
  • int   passcode Required parameter.

Returns:  boolean

Since: 11-05-2019

top

String base16toBase64(String base16)

Converts Base 16 encoded content into Base 64 encoded content

Parameters:

  • String   base16  - base 16 string. Required parameter.

Returns:  String

Since: 02-07-2012

top

String base64toBase16(String base64)

Converts Base 64 encoded content into Base 16 encoded content

Parameters:

  • String   base64  - base 64 string. Required parameter.

Returns:  String

Since: 02-07-2012

top

String base64toURLSafe(String base64)

Converts a base64 encoded string to a base64url string.

Parameters:

  • String   base64  - base 64 string. Required parameter.

Returns:  String

Since: 02-03-2019

top

String createAESKey(int length)

Creates an AES key of the specified length and returns the Base64 encoded raw value.

Parameters:

  • int   length  - length of key: 128, 192, 256.

Returns:  String

Since: 03-21-2013

top

Data createCSR(String privateKey, Data subjectInfo)

Generates a PKCS#10 Certificate Signing Request for an existing key pair. Returns a Data with one field, csr, containing the PEM-encoded CSR ready to submit to a CA.

Parameters:

  • String   privateKey  - Base64 encoded private key - reuse the privateKey field returned by createRSAKeyPair(). Do not generate a second key pair here.. Required parameter.
  • Data   subjectInfo  - Data bag of Subject DN fields. Supported keys: CN (required), O, OU, C, ST, L (optional).. Required parameter.

Returns:  Data

Since: 07-22-2026

top

Data createECDHKeyPair()

Generates an EC key pair on the P-256 curve. Returns a Data with five values: publicKeyRaw and privateKeyRaw (raw key bytes, Base64url encoded), publicKeyX509 and privateKeyPKCS8 (PEM encoded), and publicKeyPKCS1 (PEM encoded, EC-specific format).

Returns:  Data

Since: 02-03-2025

top

Data createKeyStore(String privateKey, String certificate, DataList caChain, String password)

Assembles a PKCS12 keystore from a private key, its signed certificate, and the issuing chain. Returns a Data with one field, keystore, containing the Base64 encoded PKCS12 bytes.

Parameters:

  • String   privateKey  - Base64 encoded private key - the same key used for the CSR.. Required parameter.
  • String   certificate  - PEM signed leaf certificate, returned by the CA after the CSR is submitted.. Required parameter.
  • DataList   caChain  - DataList with a single 'certificate' column (PEM), one row per intermediate/root cert in the chain, ordered leaf-to-root. May be empty.. Required parameter.
  • String   password  - Password to encrypt the resulting PKCS12 store.. Required parameter.

Returns:  Data

Since: 07-22-2026

top

String createNonce(int length)

Creates a nonce (AKA salt) of the specified length and returns the Base64 encoded raw value.

Parameters:

  • int   length

Returns:  String

Since: 03-21-2013

top

Data createOtpAuth(String issuer, String accountName)

Returns information that can be used for an OTP Auth service. See QRUtil to create an image from the url.

Parameters:

  • String   issuer Required parameter.
  • String   accountName Required parameter.

Returns:  Data

Since: 11-05-2019

top

int createOtpPassCode(String secretKey)

Creates an OTP pass code.

Parameters:

  • String   secretKey Required parameter.

Returns:  int

Since: 02-07-2020

top

Data createPGPKeyPair(String password)

Returns a Data with two values: privateKey and publicKey. Key size is 1024. Content is Base64 encoded.

Parameters:

  • String   password Required parameter.

Returns:  Data

Since: 10-04-2013

top

Data createRSAKeyPair(int keySize)

Returns a Data with two values: privateKey and publicKey, generated at the requested keySize (up to 3072 bits). Content is Base64 encoded.

Parameters:

  • int   keySize Maximum allowed size of parameter: 3072

Returns:  Data

Since: 11-06-2014

Sample:

// Example 1: RSA signing and verification (proves who sent a message, tamper-evident)
//
// rsaSha256/rsaSha1 create a SIGNATURE, not ciphertext - sign with the PRIVATE key,
// verify with the matching PUBLIC key (as an X.509 certificate). Do not pass a
// signature to decryptRSA - it is not the same thing and will fail.
var crypto = c.getEncryptionUtil();
var keys = crypto.createRSAKeyPair(2048);

var message = "this document was approved by Homer Simpson";
var signature = crypto.rsaSha256(keys.get("privateKey"), message);
c.debug("signature: " + signature);

// verification normally happens on the receiving end, against an X.509 certificate
// for the signer's public key (see createCSR/createKeyStore for issuing one).
// var valid = crypto.verifySha256RsaSignature(certFile, signature, message);


// Example 2: RSA private-key "encryption" - proves authenticity, NOT secrecy
//
// encryptRSA encrypts with the PRIVATE key; decryptRSA decrypts with the matching
// PUBLIC key. Since the public key is not secret, anyone holding it can decrypt this -
// it only proves the ciphertext came from the private-key holder. If you need to keep
// a message confidential from everyone except one recipient, this is the wrong tool;
// use AES-GCM (Example 3) with a key shared only with that recipient instead.
var keys2 = crypto.createRSAKeyPair(2048);
var proof = crypto.encryptRSA(keys2.get("privateKey"), "this really came from us");
var recovered = crypto.decryptRSA(keys2.get("publicKey"), proof);
c.debug("recovered: " + recovered);


// Example 3: AES-GCM - actual secret-keeping, shared between two parties who both
// already have the same key (e.g. exchanged out of band, or via a key-management
// service). This is authenticated: any tampering with the ciphertext causes
// decryptAESGCM to throw rather than silently returning corrupted data.
var key = crypto.createAESKey(256);
var ciphertext = crypto.encryptAESGCM(key, "just our little secret...");
c.debug("ciphertext: " + ciphertext);
var plaintext = crypto.decryptAESGCM(key, ciphertext);
c.debug("plaintext: " + plaintext);

// encryptAES/decryptAES (no GCM suffix) are deprecated - they use AES/ECB with no IV,
// which is not semantically secure. Use encryptAESGCM/decryptAESGCM for new code.
top

Data decodeCertificate(String certificate)

Decodes an X.509 certificate given as PEM or as Base64 encoded DER (for example ServiceResponse.readBase64 of a downloaded .crt). Returns a Data with: pem (the certificate as PEM with 64 character lines, ready for a certificate DataList), subject and issuer (RFC 2253 form), serialNumber, notBefore and notAfter (ISO 8601 UTC), notAfterMinutes (whole minutes from now until notAfter, zero or negative if expired, useful as the expiry of CacheManager.put), caIssuersUrl (the first HTTP(S) 'CA Issuers' address in the Authority Information Access extension, where the issuing certificate can be downloaded; empty if none) and ocspUrl (empty if none).

Parameters:

  • String   certificate  - PEM certificate or Base64 encoded DER certificate. Required parameter.

Returns:  Data

Since: 09-30-2026

top

MailResponse decodeMessage(String message)

Decodes a raw email message.

Parameters:

  • String   message Required parameter.

Returns:  MailResponse

Since: 02-28-2022

top

Payload decodeTimestampResponse(String base64)

Decodes a Base64 encoded RFC 3161 TimeStampResp (as returned by a timestamp authority, see ServiceResponse.readBase64). Returns a Payload with a Data named 'timestamp' and a DataList named 'timestampChain'. The Data has: status (0 granted, 1 granted with modifications, 2 rejection, 3 waiting, 4 revocation warning, 5 revocation notification), statusText, and, if granted, token (Base64 timeStampToken to pass as the 'timestamp' of applyExternalSignature), genTime (ISO 8601 UTC), serialNumber, imprintAlgorithm and imprint (Base16 hash the token stamps; compare it to sha256Base16FromBase16 of the signature). The DataList has one 'certificate' column (PEM), one row per certificate embedded in the token, ordered TSA certificate first then its issuers; it is empty if the response was not granted or the timestamp authority did not include certificates.

Parameters:

  • String   base64  - Base64 encoded DER TimeStampResp. Required parameter.

Returns:  Payload

Since: 09-30-2026

top

String decrypt(String encrypted)

Decrypts the content using the cloud supplied encryption key. See encrypt(string).

Parameters:

  • String   encrypted Required parameter.

Returns:  String

Since: 11-30-2016

top

String decryptAES(String key, String content)

Decrypts the content using the specified AES key (the same key passed to encryptAES). Content is expected to be Base64 encoded.

Parameters:

  • String   key  - base64 encoded AES key. Required parameter.
  • String   content  - Content to encrypt, base64. Required parameter.

Returns:  String

Since: 12-14-2022

This method has been deprecated since 09-28-2026. See encryptAES. Use decryptAESGCM instead.

top

String decryptAESGCM(String key, String content)

Decrypts content produced by encryptAESGCM, using the same AES key. Content is expected to be Base64 encoded and to include the 12-byte nonce prepended by encryptAESGCM.

Parameters:

  • String   key  - base64 encoded AES key. Required parameter.
  • String   content  - Content to decrypt, base64. Required parameter.

Returns:  String

Since: 09-28-2026

Sample:

// Example 1: RSA signing and verification (proves who sent a message, tamper-evident)
//
// rsaSha256/rsaSha1 create a SIGNATURE, not ciphertext - sign with the PRIVATE key,
// verify with the matching PUBLIC key (as an X.509 certificate). Do not pass a
// signature to decryptRSA - it is not the same thing and will fail.
var crypto = c.getEncryptionUtil();
var keys = crypto.createRSAKeyPair(2048);

var message = "this document was approved by Homer Simpson";
var signature = crypto.rsaSha256(keys.get("privateKey"), message);
c.debug("signature: " + signature);

// verification normally happens on the receiving end, against an X.509 certificate
// for the signer's public key (see createCSR/createKeyStore for issuing one).
// var valid = crypto.verifySha256RsaSignature(certFile, signature, message);


// Example 2: RSA private-key "encryption" - proves authenticity, NOT secrecy
//
// encryptRSA encrypts with the PRIVATE key; decryptRSA decrypts with the matching
// PUBLIC key. Since the public key is not secret, anyone holding it can decrypt this -
// it only proves the ciphertext came from the private-key holder. If you need to keep
// a message confidential from everyone except one recipient, this is the wrong tool;
// use AES-GCM (Example 3) with a key shared only with that recipient instead.
var keys2 = crypto.createRSAKeyPair(2048);
var proof = crypto.encryptRSA(keys2.get("privateKey"), "this really came from us");
var recovered = crypto.decryptRSA(keys2.get("publicKey"), proof);
c.debug("recovered: " + recovered);


// Example 3: AES-GCM - actual secret-keeping, shared between two parties who both
// already have the same key (e.g. exchanged out of band, or via a key-management
// service). This is authenticated: any tampering with the ciphertext causes
// decryptAESGCM to throw rather than silently returning corrupted data.
var key = crypto.createAESKey(256);
var ciphertext = crypto.encryptAESGCM(key, "just our little secret...");
c.debug("ciphertext: " + ciphertext);
var plaintext = crypto.decryptAESGCM(key, ciphertext);
c.debug("plaintext: " + plaintext);

// encryptAES/decryptAES (no GCM suffix) are deprecated - they use AES/ECB with no IV,
// which is not semantically secure. Use encryptAESGCM/decryptAESGCM for new code.
top

String decryptRSA(String publicKey, String content)

Decrypts content produced by encryptRSA, using the matching public key. This is the counterpart to encryptRSA only - it is not a signature-verification method and will not accept output from rsaSha1/rsaSha256. Content is expected to be Base64 encoded.

Parameters:

  • String   publicKey  - base64 encoded public key. Required parameter.
  • String   content  - Content to encrypt, base64. Required parameter.

Returns:  String

Since: 12-14-2022

Sample:

// Example 1: RSA signing and verification (proves who sent a message, tamper-evident)
//
// rsaSha256/rsaSha1 create a SIGNATURE, not ciphertext - sign with the PRIVATE key,
// verify with the matching PUBLIC key (as an X.509 certificate). Do not pass a
// signature to decryptRSA - it is not the same thing and will fail.
var crypto = c.getEncryptionUtil();
var keys = crypto.createRSAKeyPair(2048);

var message = "this document was approved by Homer Simpson";
var signature = crypto.rsaSha256(keys.get("privateKey"), message);
c.debug("signature: " + signature);

// verification normally happens on the receiving end, against an X.509 certificate
// for the signer's public key (see createCSR/createKeyStore for issuing one).
// var valid = crypto.verifySha256RsaSignature(certFile, signature, message);


// Example 2: RSA private-key "encryption" - proves authenticity, NOT secrecy
//
// encryptRSA encrypts with the PRIVATE key; decryptRSA decrypts with the matching
// PUBLIC key. Since the public key is not secret, anyone holding it can decrypt this -
// it only proves the ciphertext came from the private-key holder. If you need to keep
// a message confidential from everyone except one recipient, this is the wrong tool;
// use AES-GCM (Example 3) with a key shared only with that recipient instead.
var keys2 = crypto.createRSAKeyPair(2048);
var proof = crypto.encryptRSA(keys2.get("privateKey"), "this really came from us");
var recovered = crypto.decryptRSA(keys2.get("publicKey"), proof);
c.debug("recovered: " + recovered);


// Example 3: AES-GCM - actual secret-keeping, shared between two parties who both
// already have the same key (e.g. exchanged out of band, or via a key-management
// service). This is authenticated: any tampering with the ciphertext causes
// decryptAESGCM to throw rather than silently returning corrupted data.
var key = crypto.createAESKey(256);
var ciphertext = crypto.encryptAESGCM(key, "just our little secret...");
c.debug("ciphertext: " + ciphertext);
var plaintext = crypto.decryptAESGCM(key, ciphertext);
c.debug("plaintext: " + plaintext);

// encryptAES/decryptAES (no GCM suffix) are deprecated - they use AES/ECB with no IV,
// which is not semantically secure. Use encryptAESGCM/decryptAESGCM for new code.
top

String encrypt(String content)

Encrypts the content using the cloud supplied encryption key and returns it as Base16 (hex). See decrypt(string).

Parameters:

  • String   content Required parameter.

Returns:  String

Since: 11-30-2016

top

String encryptAES(String key, String content)

Encrypts the content using the specified Base64 AES key. Result is Base64 encoded.

Parameters:

  • String   key  - base64 encoded AES key. Required parameter.
  • String   content  - Content to encrypt. Required parameter.

Returns:  String

Since: 12-14-2022

This method has been deprecated since 09-28-2026. Uses AES/ECB with no IV, which is not semantically secure (identical plaintext blocks produce identical ciphertext). Use encryptAESGCM instead.

top

String encryptAESGCM(String key, String content)

Encrypts the content using the specified Base64 AES key with AES/GCM (authenticated encryption). A random 12-byte nonce is generated per call and prepended to the ciphertext before Base64 encoding, so the result is self-contained - pass it directly to decryptAESGCM with the same key.

Parameters:

  • String   key  - base64 encoded AES key. Required parameter.
  • String   content  - Content to encrypt. Required parameter.

Returns:  String

Since: 09-28-2026

Sample:

// Example 1: RSA signing and verification (proves who sent a message, tamper-evident)
//
// rsaSha256/rsaSha1 create a SIGNATURE, not ciphertext - sign with the PRIVATE key,
// verify with the matching PUBLIC key (as an X.509 certificate). Do not pass a
// signature to decryptRSA - it is not the same thing and will fail.
var crypto = c.getEncryptionUtil();
var keys = crypto.createRSAKeyPair(2048);

var message = "this document was approved by Homer Simpson";
var signature = crypto.rsaSha256(keys.get("privateKey"), message);
c.debug("signature: " + signature);

// verification normally happens on the receiving end, against an X.509 certificate
// for the signer's public key (see createCSR/createKeyStore for issuing one).
// var valid = crypto.verifySha256RsaSignature(certFile, signature, message);


// Example 2: RSA private-key "encryption" - proves authenticity, NOT secrecy
//
// encryptRSA encrypts with the PRIVATE key; decryptRSA decrypts with the matching
// PUBLIC key. Since the public key is not secret, anyone holding it can decrypt this -
// it only proves the ciphertext came from the private-key holder. If you need to keep
// a message confidential from everyone except one recipient, this is the wrong tool;
// use AES-GCM (Example 3) with a key shared only with that recipient instead.
var keys2 = crypto.createRSAKeyPair(2048);
var proof = crypto.encryptRSA(keys2.get("privateKey"), "this really came from us");
var recovered = crypto.decryptRSA(keys2.get("publicKey"), proof);
c.debug("recovered: " + recovered);


// Example 3: AES-GCM - actual secret-keeping, shared between two parties who both
// already have the same key (e.g. exchanged out of band, or via a key-management
// service). This is authenticated: any tampering with the ciphertext causes
// decryptAESGCM to throw rather than silently returning corrupted data.
var key = crypto.createAESKey(256);
var ciphertext = crypto.encryptAESGCM(key, "just our little secret...");
c.debug("ciphertext: " + ciphertext);
var plaintext = crypto.decryptAESGCM(key, ciphertext);
c.debug("plaintext: " + plaintext);

// encryptAES/decryptAES (no GCM suffix) are deprecated - they use AES/ECB with no IV,
// which is not semantically secure. Use encryptAESGCM/decryptAESGCM for new code.
top

String encryptPushPayload(String plaintext, String salt, String localPrivateKey, String localPublicKey, String uaPublicKey, String authSecret)

Performs encryption on a web push message using the aesgcm spec.

Parameters:

  • String   plaintext Required parameter.
  • String   salt Required parameter.
  • String   localPrivateKey Required parameter.
  • String   localPublicKey Required parameter.
  • String   uaPublicKey Required parameter.
  • String   authSecret Required parameter.

Returns:  String

Since: 02-03-2025

top

String encryptRSA(String privateKey, String content)

Encrypts the content using the specified private key. This proves the ciphertext came from the private-key holder (anyone with the matching public key can decrypt it via decryptRSA) - it does NOT keep the content secret from third parties. For actual confidentiality (only the private-key holder can read it), this class does not currently expose an encrypt-with-public-key operation. Result is Base64 encoded.

Parameters:

  • String   privateKey  - base64 encoded private key. Required parameter.
  • String   content  - Content to encrypt. Required parameter.

Returns:  String

Since: 12-14-2022

Sample:

// Example 1: RSA signing and verification (proves who sent a message, tamper-evident)
//
// rsaSha256/rsaSha1 create a SIGNATURE, not ciphertext - sign with the PRIVATE key,
// verify with the matching PUBLIC key (as an X.509 certificate). Do not pass a
// signature to decryptRSA - it is not the same thing and will fail.
var crypto = c.getEncryptionUtil();
var keys = crypto.createRSAKeyPair(2048);

var message = "this document was approved by Homer Simpson";
var signature = crypto.rsaSha256(keys.get("privateKey"), message);
c.debug("signature: " + signature);

// verification normally happens on the receiving end, against an X.509 certificate
// for the signer's public key (see createCSR/createKeyStore for issuing one).
// var valid = crypto.verifySha256RsaSignature(certFile, signature, message);


// Example 2: RSA private-key "encryption" - proves authenticity, NOT secrecy
//
// encryptRSA encrypts with the PRIVATE key; decryptRSA decrypts with the matching
// PUBLIC key. Since the public key is not secret, anyone holding it can decrypt this -
// it only proves the ciphertext came from the private-key holder. If you need to keep
// a message confidential from everyone except one recipient, this is the wrong tool;
// use AES-GCM (Example 3) with a key shared only with that recipient instead.
var keys2 = crypto.createRSAKeyPair(2048);
var proof = crypto.encryptRSA(keys2.get("privateKey"), "this really came from us");
var recovered = crypto.decryptRSA(keys2.get("publicKey"), proof);
c.debug("recovered: " + recovered);


// Example 3: AES-GCM - actual secret-keeping, shared between two parties who both
// already have the same key (e.g. exchanged out of band, or via a key-management
// service). This is authenticated: any tampering with the ciphertext causes
// decryptAESGCM to throw rather than silently returning corrupted data.
var key = crypto.createAESKey(256);
var ciphertext = crypto.encryptAESGCM(key, "just our little secret...");
c.debug("ciphertext: " + ciphertext);
var plaintext = crypto.decryptAESGCM(key, ciphertext);
c.debug("plaintext: " + plaintext);

// encryptAES/decryptAES (no GCM suffix) are deprecated - they use AES/ECB with no IV,
// which is not semantically secure. Use encryptAESGCM/decryptAESGCM for new code.
top

String fromBase16(String base16)

Decodes the Base16 content and attempts to return it as a string

Parameters:

  • String   base16  - base 16 string. Required parameter.

Returns:  String

Since: 01-09-2019

top

String fromBase64(String base64)

Decodes the Base64 content and attempts to return it as a string

Parameters:

  • String   base64  - base 64 string. Required parameter.

Returns:  String

Since: 01-09-2019

top

String hmacMd5(String key, String str)

Creates MD5-hashed message authentication code for a string. Result is Base16 encoded.

Parameters:

  • String   key  - key, used as literal UTF-8 bytes (not base16 or base64 decoded). Required parameter.
  • String   str  - string with content. Required parameter.

Returns:  String

Since: 08-23-2018

top

String hmacSha1(String key, File file, boolean isBase64Key)

Creates SHA1-hashed message authentication code for a file and returns it as Base64.

Parameters:

  • String   key  - key. Required parameter.
  • File   file  - file with content. Required parameter.
  • boolean   isBase64Key  - true if key is base64. Required parameter.

Returns:  String

Since: 12-02-2015

top

String hmacSha1(String key, String str, boolean isBase64Key)

Creates SHA1-hashed message authentication code for a string. Result is Base64 encoded.

Parameters:

  • String   key  - key. Required parameter.
  • String   str  - string with content. Required parameter.
  • boolean   isBase64Key  - true if key is base64. Required parameter.

Returns:  String

Since: 12-02-2015

top

String hmacSha256(String key, String str, boolean isBase64Key)

Creates SHA256-hashed message authentication code for a string. Result is Base64 encoded.

Parameters:

  • String   key  - key. Required parameter.
  • String   str  - string with content. Required parameter.
  • boolean   isBase64Key  - true if key is base64. Required parameter.

Returns:  String

Since: 11-08-2016

top

String md5(File file)

Calculates MD5 digest for a file and returns it as Base64.

Parameters:

  • File   file  - file to calculate hash for. Required parameter.

Returns:  String

Since: 02-07-2012

top

String md5(String str)

Calculates MD5 digest for a string and returns it as Base64.

Parameters:

  • String   str  - string to calculate hash for. Required parameter.

Returns:  String

Since: 02-07-2012

top

String md5Base16(File file)

Calculates MD5 digest for a file and returns it as Base16.

Parameters:

  • File   file  - file to calculate hash for. Required parameter.

Returns:  String

Since: 09-14-2023

top

String md5Base16(String str)

Calculates MD5 digest for a string and returns it as Base16.

Parameters:

  • String   str  - string to calculate hash for. Required parameter.

Returns:  String

Since: 09-14-2023

top

String pSha1(String requestEntropy, String serviceEntropy, int key length)

Creates P_SHA1 key with specifid length. See RFC 2246 section 5: HMAC and the pseudorandom function. Result is Base64 encoded.

Parameters:

  • String   requestEntropy  - base64 encoded request content. Required parameter.
  • String   serviceEntropy  - base64 encoded service content. Required parameter.
  • int   key length  - length of key. 32 for AES256, etc. Required parameter.

Returns:  String

Since: 03-21-2013

top

String rsaSha1(String privateKey, String content)

Creates a base64 encoded RSA-SHA1 signature for the string, signed with the given private key. To verify a signature produced this way, use verifySha1RsaSignature (not decryptRSA - the output here is a signature, not ciphertext). Note that key should be provided as base 64 string (PEM) PKCS8 or X509.

Parameters:

  • String   privateKey  - base64 encoded private key. Required parameter.
  • String   content  - Content to sign. Required parameter.

Returns:  String

Since: 11-03-2014

Sample:

// Example 1: RSA signing and verification (proves who sent a message, tamper-evident)
//
// rsaSha256/rsaSha1 create a SIGNATURE, not ciphertext - sign with the PRIVATE key,
// verify with the matching PUBLIC key (as an X.509 certificate). Do not pass a
// signature to decryptRSA - it is not the same thing and will fail.
var crypto = c.getEncryptionUtil();
var keys = crypto.createRSAKeyPair(2048);

var message = "this document was approved by Homer Simpson";
var signature = crypto.rsaSha256(keys.get("privateKey"), message);
c.debug("signature: " + signature);

// verification normally happens on the receiving end, against an X.509 certificate
// for the signer's public key (see createCSR/createKeyStore for issuing one).
// var valid = crypto.verifySha256RsaSignature(certFile, signature, message);


// Example 2: RSA private-key "encryption" - proves authenticity, NOT secrecy
//
// encryptRSA encrypts with the PRIVATE key; decryptRSA decrypts with the matching
// PUBLIC key. Since the public key is not secret, anyone holding it can decrypt this -
// it only proves the ciphertext came from the private-key holder. If you need to keep
// a message confidential from everyone except one recipient, this is the wrong tool;
// use AES-GCM (Example 3) with a key shared only with that recipient instead.
var keys2 = crypto.createRSAKeyPair(2048);
var proof = crypto.encryptRSA(keys2.get("privateKey"), "this really came from us");
var recovered = crypto.decryptRSA(keys2.get("publicKey"), proof);
c.debug("recovered: " + recovered);


// Example 3: AES-GCM - actual secret-keeping, shared between two parties who both
// already have the same key (e.g. exchanged out of band, or via a key-management
// service). This is authenticated: any tampering with the ciphertext causes
// decryptAESGCM to throw rather than silently returning corrupted data.
var key = crypto.createAESKey(256);
var ciphertext = crypto.encryptAESGCM(key, "just our little secret...");
c.debug("ciphertext: " + ciphertext);
var plaintext = crypto.decryptAESGCM(key, ciphertext);
c.debug("plaintext: " + plaintext);

// encryptAES/decryptAES (no GCM suffix) are deprecated - they use AES/ECB with no IV,
// which is not semantically secure. Use encryptAESGCM/decryptAESGCM for new code.
top

String rsaSha256(String privateKey, String content)

Creates a base64 encoded RSA-SHA256 signature for the string, signed with the given private key. To verify a signature produced this way, use verifySha256RsaSignature (not decryptRSA - the output here is a signature, not ciphertext). Note that key should be provided as base 64 string (PEM) PKCS8 or X509.

Parameters:

  • String   privateKey  - base64 encoded private key. Required parameter.
  • String   content  - Content to sign. Required parameter.

Returns:  String

Since: 07-25-2026

Sample:

// Example 1: RSA signing and verification (proves who sent a message, tamper-evident)
//
// rsaSha256/rsaSha1 create a SIGNATURE, not ciphertext - sign with the PRIVATE key,
// verify with the matching PUBLIC key (as an X.509 certificate). Do not pass a
// signature to decryptRSA - it is not the same thing and will fail.
var crypto = c.getEncryptionUtil();
var keys = crypto.createRSAKeyPair(2048);

var message = "this document was approved by Homer Simpson";
var signature = crypto.rsaSha256(keys.get("privateKey"), message);
c.debug("signature: " + signature);

// verification normally happens on the receiving end, against an X.509 certificate
// for the signer's public key (see createCSR/createKeyStore for issuing one).
// var valid = crypto.verifySha256RsaSignature(certFile, signature, message);


// Example 2: RSA private-key "encryption" - proves authenticity, NOT secrecy
//
// encryptRSA encrypts with the PRIVATE key; decryptRSA decrypts with the matching
// PUBLIC key. Since the public key is not secret, anyone holding it can decrypt this -
// it only proves the ciphertext came from the private-key holder. If you need to keep
// a message confidential from everyone except one recipient, this is the wrong tool;
// use AES-GCM (Example 3) with a key shared only with that recipient instead.
var keys2 = crypto.createRSAKeyPair(2048);
var proof = crypto.encryptRSA(keys2.get("privateKey"), "this really came from us");
var recovered = crypto.decryptRSA(keys2.get("publicKey"), proof);
c.debug("recovered: " + recovered);


// Example 3: AES-GCM - actual secret-keeping, shared between two parties who both
// already have the same key (e.g. exchanged out of band, or via a key-management
// service). This is authenticated: any tampering with the ciphertext causes
// decryptAESGCM to throw rather than silently returning corrupted data.
var key = crypto.createAESKey(256);
var ciphertext = crypto.encryptAESGCM(key, "just our little secret...");
c.debug("ciphertext: " + ciphertext);
var plaintext = crypto.decryptAESGCM(key, ciphertext);
c.debug("plaintext: " + plaintext);

// encryptAES/decryptAES (no GCM suffix) are deprecated - they use AES/ECB with no IV,
// which is not semantically secure. Use encryptAESGCM/decryptAESGCM for new code.
top

String sha1(File file)

Calculates SHA1 digest for a file and returns it as Base64.

Parameters:

  • File   file  - file to calculate hash for. Required parameter.

Returns:  String

Since: 02-07-2012

top

String sha1(String str)

Calculates SHA1 digest for a string and returns it as Base64.

Parameters:

  • String   str  - string to calculate hash for. Required parameter.

Returns:  String

Since: 02-07-2012

top

String sha1Base16(File file)

Calculates SHA1 digest for a file and returns it as Base16.

Parameters:

  • File   file  - file to calculate hash for. Required parameter.

Returns:  String

Since: 09-14-2023

top

String sha1Base16(String str)

Calculates SHA1 digest for a string and returns it as Base16.

Parameters:

  • String   str  - string to calculate hash for. Required parameter.

Returns:  String

Since: 09-14-2023

top

String sha256(String str)

Calculates SHA256 digest for a string and returns it as Base64.

Parameters:

  • String   str  - string to calculate hash for. Required parameter.

Returns:  String

Since: 11-08-2016

top

String sha256Base16(String str)

Calculates SHA256 digest for a string and returns it as Base16.

Parameters:

  • String   str  - string to calculate hash for. Required parameter.

Returns:  String

Since: 09-14-2023

top

String sha256Base16FromBase16(String base16, boolean timestampRequest)

Calculates SHA256 digest of the raw bytes that a Base16 (hex) string represents and returns it as Base16. Unlike sha256Base16, which hashes the characters of a string, this hashes the decoded bytes, so it works for binary values such as the hex encoded signature returned by a signing service. An RFC 3161 signature timestamp must imprint the hash of the signature value, not the document digest. When timestampRequest is true, the digest is not returned; instead it is wrapped in a DER encoded RFC 3161 TimeStampReq (SHA-256 imprint, no nonce, certReq=TRUE so the timestamp authority includes its certificates in the token) and returned as Base16. Send the request bytes (Base16 converted with base16toBase64 and set with ServiceRequest.setBinaryBody, content type application/timestamp-query) to the timestamp authority, then pass the Base64 reply (ServiceResponse.readBase64) to decodeTimestampResponse.

Parameters:

  • String   base16  - Base16 (hex) encoded bytes to calculate hash for. Required parameter.
  • boolean   timestampRequest  - true to return an RFC 3161 TimeStampReq with certReq=TRUE instead of the digest.

Returns:  String

Since: 09-30-2026

top

String sha512Base16(String str, int iterations)

Calculates SHA512 digest for an input over n iterations and returns it as Base16.

Parameters:

  • String   str  - string to calculate hash for. Required parameter.
  • int   iterations Maximum allowed size of parameter: 50

Returns:  String

Since: 08-04-2017

top

String toBase16(File file)

Converts file content into Base 16 encoded content.

Parameters:

  • File   file  - file to encode. Required parameter.

Returns:  String

Since: 02-07-2012

top

String toBase16(String str)

Converts string bytes into Base 16 encoded content

Parameters:

  • String   str  - string to encode. Required parameter.

Returns:  String

Since: 02-07-2012

top

String toBase64(File file)

Converts file content into Base 64 encoded content.

Parameters:

  • File   file  - file to encode. Required parameter.

Returns:  String

Since: 02-07-2012

top

String toBase64(String str)

Converts string bytes into Base 64 encoded content

Parameters:

  • String   str  - string to encode. Required parameter.

Returns:  String

Since: 02-07-2012

top

String toBase64URL(String str)

Converts string bytes into Base 64 URL encoded content.

Parameters:

  • String   str  - string to encode. Required parameter.

Returns:  String

Since: 02-03-2025

top

boolean verifySha1RsaSignature(File x509Cert, String base64Signature, String canonicalMessage)

Verifies the base64 encoded signature against the x509 public certificate and non encoded canonical message

Parameters:

  • File   x509Cert Required parameter.
  • String   base64Signature Required parameter.
  • String   canonicalMessage Required parameter.

Returns:  boolean

Since: 11-13-2018

top

boolean verifySha256RsaSignature(File x509Cert, String base64Signature, String canonicalMessage)

Verifies the base64 encoded signature against the x509 public certificate and non encoded canonical message

Parameters:

  • File   x509Cert Required parameter.
  • String   base64Signature Required parameter.
  • String   canonicalMessage Required parameter.

Returns:  boolean

Since: 06-03-2021

top
Copyright © 2006 - 2026, ContractPal, Inc. All rights reserved. API Date: Oct 02, 2026 11:15 AM