Skip to content
NorscodeNorscode

std.krypto

ReferenceBy the Norscode project

std.krypto gathers cryptography and security in one place: hashing, password handling, signing and verifying, random tokens and UUIDs — the right modern choices, made easy to reach.

std.krypto gathers cryptography and security in one place: hashing, password handling, signing and verifying, random tokens and UUIDs. The point is that the right, modern choices should be easy to reach — so you do not have to be a cryptographer to do things safely.

Here you find hash_passord and sjekk_passord for storing passwords properly, token and uuid4 for unpredictable identifiers, signer and verifiser for protecting data you send out and take in, and hash functions such as sha256 and hmac_sha256. Older algorithms like md5 are included only to read old data — never use them for anything new.

When to use it

Use std.krypto when you need to store passwords safely, make unpredictable tokens, sign data you send out and verify what comes in, or hash content. The safe choices are already made for you — you just need to pick the right function.

Getting started

bruk std.krypto som krypto

funksjon start() -> heiltall {
    la hash = krypto.hash_passord("hemmeleg")   // store this, not the password
    hvis krypto.sjekk_passord("hemmeleg", hash) {
        skriv("riktig passord")
    }
    la id = krypto.uuid4()                        // unpredictable identifier
    skriv(id)
    returner 0
}

Always store the result of hash_passord, never the password itself. sjekk_passord compares an attempt against the stored hash in a safe way.

The functions

The functions group by purpose: identifiers and tokens (uuid4, uuid_kompakt, token, token_url, token_sifre), hashing (sha256, sha256_med_salt, hmac_sha256, pbkdf2_sha256), passwords (hash_passord, sjekk_passord, er_sterkt_passord), signing (signer, verifiser, usigner, and the variants with expiry), and helpers such as konstant_lik and base64.

  • uuid_kompakt() -> tekst — Returns a UUID without hyphens.
  • er_gyldig_uuid(s: tekst) -> boolsk — True if the text is a valid UUID.
  • token(n_bytes: heltall) -> tekst — A random token with n_bytes bytes of randomness.
  • token_url(n_bytes: heltall) -> tekst — A URL-safe random token.
  • token_sifre(n: heltall) -> tekst — A random token made up of digits only.
  • hash_passord(passord: tekst) -> tekst — Hashes a password safely for storage (with salt, deliberately slow).
  • sjekk_passord(passord: tekst, lagra_hash: tekst) -> boolsk — Checks a password attempt against a stored hash.
  • er_sterkt_passord(passord: tekst) -> boolsk — True if the password meets the strength requirements.
  • signer(hemmeleg: tekst, data: tekst) -> tekst — Signs data with a secret, so you can verify it later.
  • verifiser(hemmeleg: tekst, signert: tekst) -> boolsk — True if a signature is valid for the secret.
  • usigner(hemmeleg: tekst, signert: tekst) -> tekst — Extracts the original data from something signed.
  • signer_med_utløp(hemmeleg: tekst, data: tekst, ttl_sek: heltall) -> tekst — Signs data with a lifetime in seconds.
  • usigner_med_utløp(hemmeleg: tekst, signert: tekst) -> tekst — Extracts data, but fails if the signature has expired.
  • konstant_lik(a: tekst, b: tekst) -> boolsk — Compares two texts in constant time, without leaking through timing.

Good to know

  • Never store passwords in clear text — use hash_passord, and check with sjekk_passord.
  • konstant_lik compares without leaking information through how long it takes; use it when you compare secrets.
  • md5 is included only for backwards compatibility; choose sha256 or stronger for anything new.

std.krypto is one of the modules in the standard library. Everything ships with the runtime — no installation, no external dependencies. See also Documentation for the language and the runtime.

Related

Back to the overview