br-crypto
Use Better Route 1.1 cryptographic helpers for secure random tokens, Hex/Base64/Base64URL encoding, strict Base64URL decoding, and constant-time secret comparison. Use when implementing nonces, state, PKCE, opaque tokens, or signature comparisons.
Install
npx skills add https://github.com/Lonsdale201/wp-agent-skills/tree/main/better-route/br-crypto
claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install lonsdale201-wp-agent-skills@llmmart
git clone https://github.com/Lonsdale201/wp-agent-skills.git
The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole lonsdale201/wp-agent-skills collection as a plugin from our marketplace. Git is the plain clone.
Skill manifest
Better Route crypto helpers
Use the library helpers instead of reimplementing small security primitives.
use BetterRoute\Support\Crypto;
use BetterRoute\Support\CryptoEncoding;
$state = Crypto::token(32); // Base64URL by default.
$nonce = Crypto::token(32, CryptoEncoding::Base64Url);
$hex = Crypto::tokenHex(32);
$encoded = Crypto::base64UrlEncode($raw);
$decoded = Crypto::base64UrlDecode($encoded);
if (!Crypto::equals($expected, $provided)) {
throw new \BetterRoute\Http\ApiException('Invalid token.', 401, 'invalid_token');
}
Rules
- Pass entropy in bytes, not output-character count. The default 32 bytes provides 256 bits before encoding.
Crypto::token()usesrandom_bytes()and acceptsCryptoEncoding::Hex,Base64, orBase64Url, including their lowercase string values.Crypto::base64UrlDecode()validates alphabet, padding placement, length, and decoder success; catchRuntimeExceptionat an input boundary if malformed input should become a client error.- Use
Crypto::equals()only with strings of the expected representation. Decode/normalize representations before comparing, but never perform lossy case normalization on secret material. - Use
br-single-use-tokenwhen a token must also be consumed atomically,br-hmac-signaturefor request signing, andbr-jwks-jwt-authfor JWTs.
Do not use these helpers as password hashing, encryption, key derivation, or a substitute for a protocol-specific verifier.
Source references: src/Support/Crypto.php, src/Support/CryptoEncoding.php.
References
- Official documentation: https://lonsdale201.github.io/better-docs/docs/better-route/agents
Files (wp-agent-skills)
-
agents
-
openai.yaml 219 B
interface: display_name: "Better Route Crypto" short_description: "Generate tokens and compare secrets safely." default_prompt: "Use better-route Crypto helpers for token generation and constant-time comparison."
-
-
SKILL.md 2.1 KB
--- name: br-crypto description: Use Better Route 1.1 cryptographic helpers for secure random tokens, Hex/Base64/Base64URL encoding, strict Base64URL decoding, and constant-time secret comparison. Use when implementing nonces, state, PKCE, opaque tokens, or signature comparisons. metadata: wp-skills-author: "Soczó Kristóf" wp-skills-contact: "mailto:lonsdale201@hotmail.com" wp-skills-plugin: "better-route" wp-skills-plugin-version-tested: "1.1.0" wp-skills-php-min: "8.1" wp-skills-last-updated: "2026-07-13" --- # Better Route crypto helpers Use the library helpers instead of reimplementing small security primitives. ```php use BetterRoute\Support\Crypto; use BetterRoute\Support\CryptoEncoding; $state = Crypto::token(32); // Base64URL by default. $nonce = Crypto::token(32, CryptoEncoding::Base64Url); $hex = Crypto::tokenHex(32); $encoded = Crypto::base64UrlEncode($raw); $decoded = Crypto::base64UrlDecode($encoded); if (!Crypto::equals($expected, $provided)) { throw new \BetterRoute\Http\ApiException('Invalid token.', 401, 'invalid_token'); } ``` ## Rules - Pass entropy in bytes, not output-character count. The default 32 bytes provides 256 bits before encoding. - `Crypto::token()` uses `random_bytes()` and accepts `CryptoEncoding::Hex`, `Base64`, or `Base64Url`, including their lowercase string values. - `Crypto::base64UrlDecode()` validates alphabet, padding placement, length, and decoder success; catch `RuntimeException` at an input boundary if malformed input should become a client error. - Use `Crypto::equals()` only with strings of the expected representation. Decode/normalize representations before comparing, but never perform lossy case normalization on secret material. - Use `br-single-use-token` when a token must also be consumed atomically, `br-hmac-signature` for request signing, and `br-jwks-jwt-auth` for JWTs. Do not use these helpers as password hashing, encryption, key derivation, or a substitute for a protocol-specific verifier. Source references: `src/Support/Crypto.php`, `src/Support/CryptoEncoding.php`. ## References - Official documentation: <https://lonsdale201.github.io/better-docs/docs/better-route/agents>
Comments (0)
Sign in to join the conversation.
Reviews (0)
No reviews yet.
No comments yet.