NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
pub.dev · #428 most downloaded on pub.dev
Cryptographic algorithms for encryption, digital signatures, key agreement, authentication, and hashing. AES, Chacha20, ED25519, and more. Cross-platform (mobile, desktop, JS, WASM).
Last release 10 months ago
21 Nov 2025
Ships unpredictably
gaps range from 8 days to 2.2 years
Nearly every release is documented
notes for 46 of 46 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
49 releases · first in 2019
Refactor SecureRandom by @terrier989 in #208
One column per quarter.
Merge pull request #207 from dint-dev/fix/various
Merge pull request #207 from dint-dev/fix/various
Refactoring
Merge pull request #201 from dint-dev/feature/wasm
Merge pull request #201 from dint-dev/feature/wasm
Implement dart2wasm support
Adds a cross-platform of Argon2id, a highly recommended algorithm for password hashing.
Fixes incorrect base class constraints.
Removes long-deprecated newSink() methods in HashAlgorithm and MacAlgorithm (so Blake2 classes can implement both interfaces).
newSink() methods in HashAlgorithm and MacAlgorithm (so Blake2
classes can implement both interfaces).Adds enough DER encoding/decoding support for us to use Apple's CryptoKit ECDH/ECDSA functions.
Fixes many issues found by adding more tests. Also improves documentation.
* Fixes some small issues. * Improves documentation.
Adds new elements and parameters in various classes, especially Dart implementations. This can be a breaking change if you extend those classes.
BrowserCryptography(random: myRandom).* Fixes small issues. * Improves documentation.
Improves performance of Blake2b/Blake2s.
DartAesGcm.with128bits.Fixes bugs in Xchacha20.poly1305.
Xchacha20.poly1305.Fixes an import of 'dart:io' that caused issues.
Updates dependency constraints and linting rules.
Fixes an issue in SecretBox.fromConcatenation.
* Documentation fixes.
Finishes null safety migration.
Renames a few identifiers in _package:cryptography_ for consistency. Adds deprecation warnings to the old identifiers.
SecretKey(bytes) factory that
just redirects to SecretKeyData(bytes).Re-introduces _package:crypto_ as dependency now that a null-safe version exists.
BREAKING CHANGES: Many breaking API changes that make the API easier to understand and use.
Improves Web Cryptography support internally.
Adds support for _cryptography_flutter_, which uses operating system implementations.
* Adds PBKDF2 and Blake2b. * Some internal refactoring.
* Fixes documentation issues.
BREAKING CHANGE: Recently added JwkSecretKey is now EcJwkSecretKey.
RsaPss and RsaPkcs1v15 (Web Cryptography only).JwkSecretKey is now EcJwkSecretKey.EcJwkSecretKey and EcJwkPublicKey.RsaJwkSecretKey and RsaJwkPublicKey.Small fixes to documentation and internal declarations.
BREAKING CHANGE: Cipher methods encrypt / encryptSync and decrypt / decryptSync now use return type Future / Uint8List instead of previous Future > /…
encrypt / encryptSync and decrypt / decryptSync now use
return type Future<Uint8List> / Uint8List instead of previous Future<List<int>> /
List<int>. We return instances of Uint8List anyway and we felt it's good to expose this
fact despite despite possibility that the change affects some developers. If you are affected by
this, you should see compile-time type warnings.Cipher has new getters nonceLengthMin and nonceLengthMax.JwkSecretKey.SecretKey and SecretKey now have property Map<Object,Object> cachedValues, which can
be used for caching objects needed for cryptographic operations (such as handles to Web
Cryptography API objects).Internal refactoring. Splits a number of large source files (such as Web Cryptography support) into more readable smaller files.
* Improves documentation.
Implements automatic use of Web Cryptography API when SHA1 or SHA2 is used in browsers. SHA2-512 becomes up to 100 times faster in browsers. ED25519 b
Implements ed25519.newKeyFromSeed(seed).
ed25519.newKeyFromSeed(seed).* A stable API.
When authenticated ciphers encounter incorrect MACs, they now throw MacValidationException (instead of returning null, which developers may ignore in
MacValidationException
(instead of returning null, which developers may ignore in some situations).Fixes a cipher.name issue and improves documentation.
cipher.name issue and improves documentation.Improves outputs of cipher.name.
cipher.name.* Improves documentation.
Eliminates AES-CBC and AES-CTR dependencies.
Breaking changes: Removes separate key generator classes. Many API changes designed to reduce chances of developers using the API incorrectly.
SecretKey / SecretKey property bytes is deprecated and replaced with extract() and extractSync() to better support implementations that protect the un…
bytes is deprecated and replaced with extract() and
extractSync() to better support implementations that protect the underlying bytes such as
Web Cryptography API.Adds AES for non-browser platforms.
* Improves documentation.
Improves documentation, clarity, test coverage.
Deprecates ConstantTimeBytesEquality in favor of constantTimeBytesEquality.
Improves documentation and stops exporting a few declarations.
Major refactoring and breaking API changes.
* Improved documentation
* Fixed example
* Initial version
Your coding agent can read these notes before it upgrades. Set up the MCP server →