Skip to content
Effect Days 2026 Get your ticket

EventLogEncryption

Cryptographic service for encrypted event-log replication.

EventLogEncryption turns local journal entries into encrypted remote payloads and decrypts encrypted changes received from a server. It also hashes byte data and creates event-log identities, so remote replication can use storage or transport that should not see plaintext event data.

6 exports Added in v4.0.0 Source

Encryption

Creates an EventLogEncryption service backed by the Web Crypto SubtleCrypto APIs from the supplied Crypto implementation.

Signature

declare function makeEncryptionSubtle(crypto: Crypto): Effect<{
readonly decrypt: (identity: {
readonly privateKey: Redacted<Uint8Array<ArrayBuffer>>;
readonly publicKey: string;
}, entries: readonly Array<EncryptedRemoteEntry>) => Effect<Array<RemoteEntry>>;
readonly encrypt: (identity: {
readonly privateKey: Redacted<Uint8Array<ArrayBuffer>>;
readonly publicKey: string;
}, entries: readonly Array<Entry>) => Effect<readonly Array<{
readonly encryptedEntry: Uint8Array<ArrayBuffer>;
readonly iv: Uint8Array<ArrayBuffer>;
}>>;
readonly generateIdentity: Effect<{
readonly privateKey: Redacted<Uint8Array<ArrayBuffer>>;
readonly publicKey: string;
}>;
readonly sha256: (data: Uint8Array) => Effect<Uint8Array<ArrayBufferLike>>;
readonly sha256String: (data: Uint8Array) => Effect<string>;
}>

Layers

layerSubtle

Added in v4.0.0 Source

Provides EventLogEncryption using globalThis.crypto.

Signature

declare const layerSubtle: Layer.Layer<EventLogEncryption>

Models

Schema for an encrypted journal entry paired with its initialization vector and the id of the original entry.

Signature

declare const EncryptedEntry: Struct<{
readonly encryptedEntry: Transferable<instanceOf<Uint8Array<ArrayBuffer>, Uint8Array<ArrayBuffer>>>;
readonly entryId: brand<instanceOf<Uint8Array<ArrayBuffer>, Uint8Array<ArrayBuffer>>, "effect/eventlog/EventJournal/EntryId">;
readonly iv: Transferable<instanceOf<Uint8Array<ArrayBuffer>, Uint8Array<ArrayBuffer>>>;
}>

Schema for encrypted entries exchanged with a remote event-log server.

Signature

declare const EncryptedRemoteEntry: Struct<{
readonly encryptedEntry: Transferable<instanceOf<Uint8Array<ArrayBuffer>, Uint8Array<ArrayBuffer>>>;
readonly entryId: brand<instanceOf<Uint8Array<ArrayBuffer>, Uint8Array<ArrayBuffer>>, "effect/eventlog/EventJournal/EntryId">;
readonly iv: Transferable<instanceOf<Uint8Array<ArrayBuffer>, Uint8Array<ArrayBuffer>>>;
readonly sequence: Natural;
}>

EncryptedRemoteEntry interface

Added in v4.0.0 Source

Type of an encrypted remote entry, including its remote sequence number, initialization vector, entry id, and encrypted entry bytes.

Signature

interface EncryptedRemoteEntry extends Type<typeof EncryptedRemoteEntry> {}

Services

Service that provides identity generation, entry encryption and decryption, and SHA-256 hashing for event-log replication.

When to use

Use to provide cryptographic operations required by encrypted event-log replication.

Signature

declare class EventLogEncryption extends Shape<"effect/eventlog/EventLogEncryption", {
readonly decrypt: (identity: {
readonly privateKey: Redacted<Uint8Array<ArrayBuffer>>;
readonly publicKey: string;
}, entries: readonly Array<EncryptedRemoteEntry>) => Effect<Array<RemoteEntry>>;
readonly encrypt: (identity: {
readonly privateKey: Redacted<Uint8Array<ArrayBuffer>>;
readonly publicKey: string;
}, entries: readonly Array<Entry>) => Effect<readonly Array<{
readonly encryptedEntry: Uint8Array<ArrayBuffer>;
readonly iv: Uint8Array<ArrayBuffer>;
}>>;
readonly generateIdentity: Effect<{
readonly privateKey: Redacted<Uint8Array<ArrayBuffer>>;
readonly publicKey: string;
}>;
readonly sha256: (data: Uint8Array) => Effect<Uint8Array<ArrayBufferLike>>;
readonly sha256String: (data: Uint8Array) => Effect<string>;
}, this> {
constructor(_: never);
}