VexaHub
France

@vexahub/opaque (0.0.1-alpha.4)

Published 2026-06-14 07:09:02 +02:00 by breakingbread

Installation

@vexahub:registry=https://dev.unebaguette.fr/api/packages/vexahub/npm/
npm install @vexahub/[email protected]
"@vexahub/opaque": "0.0.1-alpha.4"

About this package

OPAQUE (RFC 9807) client + server (WASM)

@vexahub/opaque

OPAQUE (RFC 9807) authentication library. Contains client + server in one package.

Built in Rust, compiled to WASM.

Install

npm install @vexahub/opaque

Usage

import { client, server } from '@vexahub/opaque';

// --- Server Setup (one-time) ---
const serverSetup = server.createSetup();

// --- Registration ---

// Client
const { clientRegistrationState, registrationRequest } =
  client.startRegistration({ password });

// Server
const { registrationResponse } = server.createRegistrationResponse({
  serverSetup,
  userIdentifier: '[email protected]',
  registrationRequest,
});

// Client
const { registrationRecord, exportKey, serverStaticPublicKey } =
  client.finishRegistration({
    password,
    registrationResponse,
    clientRegistrationState,
  });

// --- Login ---

// Client
const { clientLoginState, startLoginRequest } =
  client.startLogin({ password });

// Server
const { loginResponse, serverLoginState } = server.startLogin({
  serverSetup,
  userIdentifier: '[email protected]',
  registrationRecord,
  startLoginRequest,
});

// Client
const loginResult = client.finishLogin({
  clientLoginState,
  loginResponse,
  password,
});

if (!loginResult) throw new Error('Login failed');
const { finishLoginRequest, sessionKey } = loginResult;

// Server
const { sessionKey: serverSessionKey } = server.finishLogin({
  serverLoginState,
  finishLoginRequest,
});

// sessionKey === serverSessionKey

Key Stretching

Pass keyStretching to client.finishRegistration and client.finishLogin:

Preset Memory Iterations Parallelism
memory-constrained (default) 64 MiB 3 4
vexahub 128 MiB 3 4
high 1 GiB 2 4
custom input input input
client.finishLogin({
  clientLoginState,
  loginResponse,
  password,
  keyStretching: 'vexahub',
});

Memory limit for custom is 1 GiB (1048576 KiB) otherwise it will throw an error.

We recommended that you use high preset if you reach that limit.

Server Static Public Key

Extract for client-side pinning:

const publicKey = server.getPublicKey(serverSetup);

CLI

npx @vexahub/opaque create-server-setup
npx @vexahub/opaque get-server-pubkey <SERVER_SETUP>

Split packages

For smaller bundles, use the split packages instead:

Package Description
@vexahub/opaque-client Client only (browser)
@vexahub/opaque-server Server only (Node.js)

License

This package is dual-licensed under the MIT License or Apache-2.0 License.

Keywords

opaque pake authentication wasm
Details
npm
2026-06-14 07:09:02 +02:00
1
MIT OR Apache-2.0
latest
136 KiB
Assets (1)
Versions (5) View all
0.0.1-alpha.4 2026-06-14
0.0.1-alpha.3 2026-06-14
0.0.1-alpha.2 2026-05-14
0.0.1-alpha.1 2026-05-14
0.0.1-alpha.0 2026-05-14