Crypto related functions and helpers for Swift implemented in Swift. (#PureSwift)
Note: The main
branch follows the latest currently released version of Swift. If you need an earlier version for an older version of Swift, you can specify its version in your Podfile
or use the code on the branch for that version. Older branches are unsupported. Check versions for details.
Requirements | Features | Contribution | Installation | Swift versions | How-to | Author | License | Changelog
It takes some time to keep it all for your convenience, so maybe spare $1, so I can keep working on that. There are more than 8000 clones daily. If I'd get $1/month from each company that uses my work here, I'd say we're even. Hurry up, find the Sponsorship button, and fulfill your duty.
CryptoSwift isn't backed by any big company and is developer in my spare time that I also use to as a freelancer.
Good mood
- Easy to use
- Convenient extensions for String and Data
- Support for incremental updates (stream, ...)
- iOS, Android, macOS, AppleTV, watchOS, Linux support
Hash (Digest)
| SHA1
| SHA2-224
| SHA2-256
| SHA2-384
| SHA2-512
| SHA3
Cyclic Redundancy Check (CRC)
AES-128, AES-192, AES-256
| ChaCha20
| Rabbit
| Blowfish
Message authenticators
| HMAC (MD5, SHA1, SHA256)
Cipher mode of operation
- Electronic codebook (ECB)
- Cipher-block chaining (CBC)
- Propagating Cipher Block Chaining (PCBC)
- Cipher feedback (CFB)
- Output Feedback (OFB)
- Counter Mode (CTR)
- Galois/Counter Mode (GCM)
- Counter with Cipher Block Chaining-Message Authentication Code (CCM)
- OCB Authenticated-Encryption Algorithm (OCB)
Password-Based Key Derivation Function
- PBKDF1 (Password-Based Key Derivation Function 1)
- PBKDF2 (Password-Based Key Derivation Function 2)
- HKDF (HMAC-based Extract-and-Expand Key Derivation Function)
- Scrypt (The scrypt Password-Based Key Derivation Function)
Data padding
| PKCS#7
| Zero padding
| ISO78164
| ISO10126
| No padding
Authenticated Encryption with Associated Data (AEAD)
How do I get involved?
You want to help, great! Go ahead and fork our repo, make your changes and send us a pull request.
Check out for more information on how to help with CryptoSwift.
- If you found a bug, open an issue.
- If you have a feature request, open an issue.
Hardened Runtime (macOS) and Xcode
Binary CryptoSwift.xcframework (Used by Swift Package Manager package integration) won't load properly in your app if the app uses Sign to Run Locally Signing Certificate with Hardened Runtime enabled. It is possible to setup Xcode like this. To solve the problem you have two options:
- Use proper Signing Certificate, eg. Development <- this is the proper action
- Use
Disable Library Validation
Xcode Project
To install CryptoSwift, add it as a submodule to your project (on the top level project directory):
git submodule add
It is recommended to enable Whole-Module Optimization to gain better performance. Non-optimized build results in significantly worse performance.
Swift Package Manager
You can use Swift Package Manager and specify dependency in Package.swift
by adding this:
Notice: Swift Package Manager uses debug configuration for debug Xcode build, that may result in significant (up to x10000) worse performance. Performance characteristic is different in Release build. To overcome this prolem, consider embed CryptoSwift.xcframework
described below.
You can use CocoaPods.
Bear in mind that CocoaPods will build CryptoSwift without Whole-Module Optimization that may impact performance. You can change it manually after installation, or use cocoapods-wholemodule plugin.
You can use Carthage.
Specify in Cartfile:
Run carthage
to build the framework and drag the built CryptoSwift.framework into your Xcode project. Follow build instructions. Common issues.
XCFrameworks require Xcode 11 or later and they can be integrated similarly to how we’re used to integrating the .framework
Please use script scripts/ to generate binary CryptoSwift.xcframework
archive that you can use as a dependency in Xcode.
CryptoSwift.xcframework is a Release (Optimized) binary that offer best available Swift code performance.

Embedded Framework
Embedded frameworks require a minimum deployment target of iOS 9 or macOS Sierra (10.12). Drag the CryptoSwift.xcodeproj
file into your Xcode project, and add appropriate framework as a dependency to your target. Now select your App and choose the General tab for the app target. Find Embedded Binaries and press "+", then select CryptoSwift.framework
(iOS, macOS, watchOS or tvOS)
Sometimes "embedded framework" option is not available. In that case, you have to add new build phase for the target.
iOS, macOS, watchOS, tvOS
In the project, you'll find single scheme for all platforms:
- CryptoSwift
Swift versions support
- Swift 1.2: branch swift12 version <= 0.0.13
- Swift 2.1: branch swift21 version <= 0.2.3
- Swift 2.2, 2.3: branch swift2 version <= 0.5.2
- Swift 3.1, branch swift3 version <= 0.6.9
- Swift 3.2, branch swift32 version = 0.7.0
- Swift 4.0, branch swift4 version <= 0.12.0
- Swift 4.2, branch swift42 version <= 0.15.0
- Swift 5.0, branch swift5 version <= 1.2.0
- Swift 5.1, branch swift5 version <= 1.3.3
- Swift 5.3 and newer, branch main
- Basics (data types, conversion, ...)
- Digest (MD5, SHA...)
- Message authenticators (HMAC, CMAC...)
- Password-Based Key Derivation Function (PBKDF2, ...)
- HMAC-based Key Derivation Function (HKDF)
- Data Padding
- ChaCha20
- Rabbit
- Blowfish
- AES - Advanced Encryption Standard
- Authenticated Encryption with Associated Data (AEAD)
CryptoSwift uses array of bytes aka Array<UInt8>
as a base type for all operations. Every data may be converted to a stream of bytes. You will find convenience functions that accept String
or Data
, and it will be internally converted to the array of bytes.
Data types conversion
For your convenience, CryptoSwift provides two functions to easily convert an array of bytes to Data
or Data
to an array of bytes:
Data from bytes:
to Array<UInt8>
Hexadecimal encoding:
Build bytes out of String
Also... check out helpers that work with Base64 encoded data:
Calculate Digest
Hashing a data or array of bytes (aka Array<UInt8>
Hashing a String and printing result
Calculate CRC
Message authenticators
Password-Based Key Derivation Functions
HMAC-based Key Derivation Function
Data Padding
Some content-encryption algorithms assume the input length is a multiple of k
octets, where k
is greater than one. For such algorithms, the input shall be padded.
Working with Ciphers
Notice regarding padding: Manual padding of data is optional, and CryptoSwift is using PKCS7 padding by default. If you need to manually disable/enable padding, you can do this by setting parameter for AES class
Variant of AES encryption (AES-128, AES-192, AES-256) depends on given key length:
- AES-128 = 16 bytes
- AES-192 = 24 bytes
- AES-256 = 32 bytes
AES-256 example
Full example:
All at once
Incremental updates
Incremental operations use instance of Cryptor and encrypt/decrypt one part at a time, this way you can save on memory for large files.
AES Advanced usage
AES without data padding
Using convenience extensions
The result of Galois/Counter Mode (GCM) encryption is ciphertext and authentication tag, that is later used to decryption.
Note: GCM instance is not intended to be reused. So you can't use the same GCM
instance from encoding to also perform decoding.
The result of Counter with Cipher Block Chaining-Message Authentication Code encryption is ciphertext and authentication tag, that is later used to decryption.
Check documentation or CCM specification for valid parameters for CCM.
CryptoSwift is owned and maintained by Marcin Krzyżanowski
You can follow me on Twitter at @krzyzanowskim for project updates and releases.
Cryptography Notice
This distribution includes cryptographic software. The country in which you currently reside may have restrictions on the import, possession, use, and/or re-export to another country, of encryption software. BEFORE using any encryption software, please check your country's laws, regulations and policies concerning the import, possession, or use, and re-export of encryption software, to see if this is permitted. See for more information.
Copyright (C) 2014-2021 Marcin Krzyżanowski
This software is provided 'as-is', without any express or implied warranty.
In no event will the authors be held liable for any damages arising from the use of this software.
Permission is granted to anyone to use this software for any purpose, including commercial applications, and to alter it and redistribute it freely, subject to the following restrictions:
- The origin of this software must not be misrepresented; you must not claim that you wrote the original software. If you use this software in a product, an acknowledgment in the product documentation is required.
- Altered source versions must be plainly marked as such, and must not be misrepresented as being the original software.
- This notice may not be removed or altered from any source or binary distribution.
- Redistributions of any form whatsoever must retain the following acknowledgment: 'This product includes software developed by the "Marcin Krzyzanowski" ('