Inspired by Hashicorp's Vault's Transit secrets engine (pre license change - AUG 10 2023), powered by Bitwarden Secrets Manager, node:crypto, Web Crypto and runs completely on Cloudflare Workers.
Keep your own storage system and just pass-through encrypt/decrypt and stay up to date and compliant. No data is ever stored and only lives long enough to do the operation. Per request additional wrapping to counter MITM/TLS inspection is also available.
Note
Currently under development, see progress under the Projects tab.
Breaking api changes will use a new api version and a depreciation schedule for the previous respective version.
| Version | Status | Support |
|---|---|---|
v0 |
ALPHA |
From 2024-12-14 to ? |
ALPHA: Expect breaking changes at any timeBETA: Should no longer have breaking changes, but not fully stable yet.GA: Maintenance (bug/security fixes) changes only.DEPRECATED: Still maintenance only, but endpoints will be shutdown soon. Migrate to new endpoint by the corresponding date above.RETIRED: Shut down.
- Generative operations
- encryption
- signing
- hmac
- randomness
- Retreival operations
- decryption
- rewraps*
- verify
- hash
* counted as a generative operation for key usage reasons (key auto-rotate, in-use datakeys, etc) but as a retreival operation for billing purposes (always free)
Checkmarks below mean it's live and/or enforced.
- Free (community supported) managed version
- 10GB logging (operation metadata only)
- Bitwarden BYO key vault
-
Unlimitedseats and machine api keys -
TBAkeyrings -
TBAmonthly total operations. Upon hitting limit, only retreival operations will go through. - Automated key rotation (time & usage based) with webhook notifications
- Manual key rotation
- Up to the last
TBA(in-use: has been used for a generation op at least once) datakeys are stored per keyring. - PQC key generation - current NIST forerunner(s)
- PQC encryption - current NIST forerunner(s)
-
(paid version fully on indefinite hold$TBA/month) Paid (TBAsupport) managed version- Everything in free
-
TBAlogging (operation metadata only) -
Unlimited freeexternal log push - Other vendors BYO key vault
-
Unlimited freekeyrings - (
$TBA/million ops) monthly generative operations- Base price already includes
TBAmonthly generative operations
- Base price already includes
-
Unlimited freeretreival operations - Key rotations now include webhook customization and email notifications
- (
$TBA/TBAin-use datakeys) per keyring- Base price already includes
TBAdatakeys per keyring
- Base price already includes
We forever pledge that retreival operations will always be free and accessible. We never want to be in a situation where we're keeping your data hostage.

