# encrypt

> **encrypt**(`options`): `ReadableWritablePair`\<[`Uint8Array`](https://developer.mozilla.org/docs/Web/JavaScript/Reference/Global_Objects/Uint8Array)\<`ArrayBufferLike`\>, [`Uint8Array`](https://developer.mozilla.org/docs/Web/JavaScript/Reference/Global_Objects/Uint8Array)\<`ArrayBufferLike`\>\>

Defined in: [packages/filecoin-encryption-envelope/src/aes-gcm-stream.ts:83](https://github.com/FilOzone/synapse-sdk/blob/ac45b247918d1482a4bd5f301722edb6f0a5b349/packages/filecoin-encryption-envelope/src/aes-gcm-stream.ts#L83)

Creates a streaming encryptor using scheme 2
(chunked AES-256-GCM STREAM) with a direct CEK.

The writable side accepts plaintext blocks. The readable side emits the
FEE envelope first, followed by one encrypted chunk at a time.

Validation that does not require cryptographic work is performed
synchronously. CEK import, recipient key wrapping, and any size checks that
depend on the final envelope are deferred until the readable side is first
pulled, but complete before any output is emitted.

Input buffers provided through `options` are borrowed and may be read until
the readable side closes or errors, so they must not be modified or cleared
during that time. Input blocks may be reused once their corresponding
`write()` resolves.

The base nonce is generated internally. The final encrypted chunk is emitted
only after the writable side closes. If the stream fails, any output already
consumed is incomplete and must be discarded.

## Parameters

| Parameter | Type |
| ------ | ------ |
| `options` | [`ChunkedEncryptOptions`](/reference/filoz/filecoin-encryption-envelope/interfaces/chunkedencryptoptions/) |

## Returns

`ReadableWritablePair`\<[`Uint8Array`](https://developer.mozilla.org/docs/Web/JavaScript/Reference/Global_Objects/Uint8Array)\<`ArrayBufferLike`\>, [`Uint8Array`](https://developer.mozilla.org/docs/Web/JavaScript/Reference/Global_Objects/Uint8Array)\<`ArrayBufferLike`\>\>