The Workers Web Crypto API now supports ML-KEM-768, ML-KEM-1024, ML-DSA-44, ML-DSA-65, and ML-DSA-87. ML-KEM establishes shared secrets, while ML-DSA signs and verifies data.
The opt-in API also adds key encapsulation and decapsulation methods, getPublicKey(), SubtleCrypto.supports(), and JSON Web Keys (JWKs) with the AKP key type.
Turn on the webcrypto_modern_algorithms compatibility flag to use these features:
{
"$schema": "./node_modules/wrangler/config-schema.json",
"compatibility_flags": [
"webcrypto_modern_algorithms"
]
}
compatibility_flags = ["webcrypto_modern_algorithms"]
This example uses ML-KEM-768 to establish the same shared secret on both sides:
const keyPair = await crypto.subtle.generateKey("ML-KEM-768", false, [
"encapsulateBits",
"decapsulateBits",
]);
if (!("publicKey" in keyPair)) {
throw new Error("Expected an ML-KEM key pair");
}
const { sharedKey, ciphertext } = await crypto.subtle.encapsulateBits(
"ML-KEM-768",
keyPair.publicKey,
);
const recoveredSharedKey = await crypto.subtle.decapsulateBits(
"ML-KEM-768",
keyPair.privateKey,
ciphertext,
);
const keyPair = await crypto.subtle.generateKey("ML-KEM-768", false, [
"encapsulateBits",
"decapsulateBits",
]);
if (!("publicKey" in keyPair)) {
throw new Error("Expected an ML-KEM key pair");
}
const { sharedKey, ciphertext } = await crypto.subtle.encapsulateBits(
"ML-KEM-768",
keyPair.publicKey,
);
const recoveredSharedKey = await crypto.subtle.decapsulateBits(
"ML-KEM-768",
keyPair.privateKey,
ciphertext,
);
Workers implements a subset of the evolving Modern Algorithms in the Web Cryptography API ↗︎ draft. ML-KEM-512 and the draft’s other algorithms are not supported. The API may change as the draft evolves.
For current algorithm and operation support, refer to Web Crypto supported algorithms.
Source: Cloudflare


