oc · docs
docs / documentation

@orangecheck/vault-core


@orangecheck/vault-core / unwrapVaultKey

Function: unwrapVaultKey()

function unwrapVaultKey(w: WrappedKey, passphrase: string): Uint8Array;

Defined in: vault-core/src/crypto.ts:153

Unwrap the vault key from its escrowed WrappedKey using the passphrase. scrypt-derives the wrap key, then AES-256-GCM-decrypts. Throws WrongPassphrase on any failure — never returns a bogus key.

Work factors are checked BEFORE any memory is spent on them, and that failure is deliberately distinct from WrongPassphrase: a blob asking for 17 GiB is not a typo the user can fix.

Parameters

ParameterType
wWrappedKey
passphrasestring

Returns

Uint8Array