function wgPubKey
wgPubKey(
privateKeyBase64: string,
): Promise<string>

Derives the x25519 public key for a base64-encoded private key.

Mimics WireGuard's wg pubkey command — pipe a base64 private key in, get a base64 public key out.

Examples

Derive public key from base64 string

import { assertEquals } from "@std/assert";
import { decodeBase64 } from "@std/encoding/base64";
import { wgGenKey, wgPubKey } from "@hertzg/wg-keys";

const privateKey = wgGenKey();
const publicKey = await wgPubKey(privateKey);

assertEquals(publicKey.length, 44);
assertEquals(decodeBase64(publicKey).length, 32);

Parameters

privateKeyBase64: string

Base64 encoded private key

optional
options: ImportPrivateKeyOptions

Configuration options for key import

Return Type

Promise<string>

Base64 encoded public key (44 characters)

wgPubKey(
privateKey: Uint8Array,
): Promise<Uint8Array>

Derives the x25519 public key for a raw 32-byte private key.

Examples

Derive public key from Uint8Array

import { assertEquals } from "@std/assert";
import { randomPrivateKeyBytes, wgPubKey } from "@hertzg/wg-keys";

const privateKeyBytes = randomPrivateKeyBytes();
const publicKeyBytes = await wgPubKey(privateKeyBytes);

assertEquals(publicKeyBytes.length, 32);

Derive public key with custom key usages

import { assertEquals } from "@std/assert";
import { randomPrivateKeyBytes, wgPubKey } from "@hertzg/wg-keys";

const privateKeyBytes = randomPrivateKeyBytes();
const publicKeyBytes = await wgPubKey(privateKeyBytes, {
  keyUsages: ["deriveBits"],
});

assertEquals(publicKeyBytes.length, 32);

Parameters

privateKey: Uint8Array

The 32-byte private key as Uint8Array

optional
options: ImportPrivateKeyOptions

Configuration options for key import

Return Type

Promise<Uint8Array>

The 32-byte public key as Uint8Array