What the Web Crypto API means for privacy tools
Learn what browser cryptography can do, how hashing differs from encryption and signing, and what to verify before handling sensitive data.
September 29, 2026 · 2 min read
What Web Crypto provides
The browser’s Web Crypto API exposes cryptographic primitives through its crypto.subtle interface, including digest operations, key generation, signing, verification, and encryption for supported algorithms. It is designed for secure contexts such as HTTPS pages and gives web applications access to implementations provided by the browser.
A page can process an input locally with browser APIs, but that fact alone does not prove every part of a website is private. A tool may also call a remote service, load third-party scripts, or send information as part of another feature. Check the particular tool’s implementation and data flow.
Hashing is not encryption
A hash function produces a fixed-length digest from an input. It is useful for integrity checks and as a building block in protocols, but it is not reversible encryption and does not hide a low-entropy value from guessing. Never use a plain fast hash to store passwords; password storage requires a dedicated, salted password-hashing scheme with appropriate work factors.
For file integrity, compare a digest calculated from the file with a value obtained through a trusted, independent channel. A digest by itself does not establish who published the file.
Authentication requires keys and verification
HMAC combines a secret key with a message to produce an authentication tag. A receiver must calculate and compare the tag safely using the same key and encoding rules. Keep keys secret, restrict their permissions, and rotate them if they may have been exposed.
A digital signature uses a private key to sign data and a public key to verify it. A JWT’s Base64URL-encoded header and payload can be decoded for inspection, but only a valid signature check with a trusted key can authenticate the token’s claims.
Use standard constructions, not homemade crypto
Select established algorithms for a documented purpose and use maintained platform libraries rather than inventing a cipher or protocol. Legacy digests such as MD5 and SHA-1 should not be used for collision-resistant signatures or security decisions. Even correct primitives can be undermined by key handling, protocol design, or implementation mistakes.
For production systems, review current standards and platform guidance, use a vetted library, and test the complete protocol—not only one digest call.