Skip to content
This page View Markdown Open in ChatGPT Open in Claude

Encrypt data

Encrypts a string, a number, an object or an array and answers the encrypted text. By default it uses encryptionAlgorithmFETransfer and secretFETransfer of the default secret : the key you share with your frontend or mobile app, so the two sides can exchange encrypted data.

Method POST
URL /api/system-api/admin/encrypt-data : admin is the user path of your account
Body { data, algorithm?, pass? }
Answer data : the encrypted string
From code g.sys.system.encrypt

The call

Body
{ "data": { "name": "Joseph", "card": "4111 1111 1111 1111" } }
Answer
{ "success": true, "statusCode": 200, "data": "U2FsdGVkX19iIBA3FQy3OgFXeE4B2cC8lAfaJjCbMmUllceqb58YwvQqU33PkQEQ" }
Key Meaning
data Required. Any JSON value. It is serialised before encryption, so decrypt gives the same type back.
algorithm AES (default from the secret), RC4 or TRIPLEDES.
pass Your own key, instead of secretFETransfer of the secret.
  • The keys come from the default secret of the account, unless the body gives its own algorithm and pass.

From code

const text = await g.sys.system.encrypt({ name: 'Joseph' });            // with the transfer key of the secret
const mine = await g.sys.system.encrypt('hello', T.EEncryptionAlgorithm.AES, 'my-own-key');

Good to know

  • Fields of a table are encrypted at rest with conversions: { encryption: true } in the schema, with the secret key of the secret, not this API.
  • To send an encrypted request body, see encrypted payloads ; to get an encrypted answer, the header x-am-get-encrypted-data.

Access and settings

  • Over HTTP, a system API answers once its settings give it apiAccessType: TOKEN_ACCESS (the token of an API user whose group grants this system API, in x-am-authorization) or IS_PUBLIC. Without settings it is NO_ACCESS : your code calls it through g.sys, the admin panel tests it, and an HTTP call is refused.
  • The settings can also cache the answer or require person tokens (authProviders) ; pre and post hooks run around it like around any API.
  • The request headers apply : x-am-response-case, x-am-content-type-response, x-am-internationalization, x-am-tenant-username…

Errors

Code When
400 The body is wrong : the message names the missing or invalid key, for example an unknown algorithm.
401 No valid API user token, or the API is NO_ACCESS : You are not authorized to access this API.
403 No group grants this system API.