Skip to content
Bluetape4k docs1.11

Google Tink Cryptography

Latest stable Based on Bluetape4k release 1.11.0

An idiomatic Kotlin wrapper around Google Tink cryptography library. This manual connects that purpose to the current build, source entry points, tests, configuration resources, and lifecycle evidence instead of duplicating the README feature list.

Use bluetape4k-tink when the application needs encoding boundaries, resource ownership, streaming, compatibility, and malformed input. Start with the source entry points below and confirm that their ownership and failure contracts match the calling component. Prefer a smaller standard-library or already-adopted module when it satisfies the same contract without another runtime boundary.

dependencies {
implementation(platform("io.github.bluetape4k:bluetape4k-dependencies:<version>"))
implementation("io.github.bluetape4k:bluetape4k-tink")
}

Gradle project path: :bluetape4k-tink. Source directory: io/tink.

The first source-level concepts to inspect are SecureRandomSupport, TinkSupport, TinkAead, TinkAeadExtensions, TinkAeads, TinkDaeads, TinkDeterministicAead, and TinkDigester. File names are navigation anchors; read each declaration and its tests before treating it as a public contract.

Add the coordinate above, refresh Gradle, and start from the smallest entry point that owns the required task. Open SecureRandomSupport first; it is a concrete source entry point for the module.

Entry pointWhat to verify
SecureRandomSupportInspect this declaration’s constructors, functions, and ownership contract.
TinkSupportInspect this declaration’s constructors, functions, and ownership contract.
TinkAeadInspect this declaration’s constructors, functions, and ownership contract.
TinkAeadExtensionsInspect this declaration’s constructors, functions, and ownership contract.
TinkAeadsInspect this declaration’s constructors, functions, and ownership contract.
TinkDaeadsInspect this declaration’s constructors, functions, and ownership contract.
TinkDeterministicAeadInspect this declaration’s constructors, functions, and ownership contract.
TinkDigesterInspect this declaration’s constructors, functions, and ownership contract.
TinkDigesterExtensionsInspect this declaration’s constructors, functions, and ownership contract.
TinkDigestersInspect this declaration’s constructors, functions, and ownership contract.

The README evidence is organized around Why Tink, Diagrams, TinkEncryptor Class Hierarchy, AEAD encrypt/decrypt Flow, Recommended Usage Scenarios, Anti-Patterns, Features, Dependencies, Quick Start, and AEAD — Authenticated Encryption (AES-256-GCM). Use those topics as a navigation map, then confirm behavior in source and tests. Keep adoption narrow and connect owned resources to the caller lifecycle.

The current build declares these integration edges:

api(project(":bluetape4k-core"))
compileOnly(libs.lettuce.core)
compileOnly(libs.redisson)
api(libs.tink)

Treat compileOnly edges as caller-provided capabilities and verify runtime availability before using their APIs.

No module-level configuration resource was found under src/main/resources. Configuration is supplied through constructors, builders, function arguments, or the integrating framework; confirm defaults in source.

Failure semantics are defined by the linked entry points and tests, not inferred from the artifact name. Keep cancellation and timeout signals intact, close owned resources, and translate backend exceptions only at a boundary that can add a stable domain contract. Use the test anchors below to verify the exact behavior before adding retries or fallbacks.

Track payload size, allocation, latency, malformed-input rate, resource closure, and protocol errors. Keep capacity, timeout, retry, and shutdown settings next to the component that owns the resource; avoid process-wide defaults that hide which caller accepted the trade-off.

Run the module test task:

Terminal window
./gradlew :bluetape4k-tink:test --no-configuration-cache

Representative test anchors:

No dedicated workshop path is registered in the manual manifest. Use the module README and the representative tests above as runnable evidence.

This page documents the repository state represented by the linked source and tests. It does not turn optional backends into application defaults or claim performance without a benchmark artifact. Re-check compatibility and lifecycle notes when the module version changes.

These diagrams are loaded directly from README assets published with the 1.11.0 release and pinned to its immutable commit. They describe this manual’s released structure and runtime flows, not later Snapshot changes. Select a preview to open the SVG at the same release commit.

TinkEncryptor Class Hierarchy diagram

Release README: io/tink/README.md

AEAD encrypt/decrypt Flow diagram

Release README: io/tink/README.md