Better Route crypto helpers

SkillCommerce & finance

Use Better Route 1.1 cryptographic helpers for secure random tokens, Hex/Base64/Base64URL encoding, strict Base64URL decoding, and constant-time secret comparison. Use when implementing nonces, state, PKCE, opaque tokens, or signature comparisons.

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the Better Route crypto helpers skill

What this skill tells your AI

The instructions your AI receives, as published by lonsdale201/wp-agent-skills in better-route/br-crypto/SKILL.md and read by ahel’s review.

Use the library helpers instead of reimplementing small security primitives.

use BetterRoute\Support\Crypto;
use BetterRoute\Support\CryptoEncoding;

$state = Crypto::token(32); // Base64URL by default.
$nonce = Crypto::token(32, CryptoEncoding::Base64Url);
$hex = Crypto::tokenHex(32);

$encoded = Crypto::base64UrlEncode($raw);
$decoded = Crypto::base64UrlDecode($encoded);

if (!Crypto::equals($expected, $provided)) {
    throw new \BetterRoute\Http\ApiException('Invalid token.', 401, 'invalid_token');
}

Rules

  • Pass entropy in bytes, not output-character count. The default 32 bytes provides 256 bits before encoding.
  • Crypto::token() uses random_bytes() and accepts CryptoEncoding::Hex, Base64, or Base64Url, including their lowercase string values.
  • Crypto::base64UrlDecode() validates alphabet, padding placement, length, and decoder success; catch RuntimeException at an input boundary if malformed input should become a client error.
  • Use Crypto::equals() only with strings of the expected representation. Decode/normalize representations before comparing, but never perform lossy case normalization on secret material.
  • Use br-single-use-token when a token must also be consumed atomically, br-hmac-signature for request signing, and br-jwks-jwt-auth for JWTs.

Do not use these helpers as password hashing, encryption, key derivation, or a substitute for a protocol-specific verifier.

Source references: src/Support/Crypto.php, src/Support/CryptoEncoding.php.

References

Signals

GitHub stars
22
Forks
2
Last commit
Sep 2026
Advanced
Catalog kind
skill
Gateway key
br-crypto
Source
github.com/lonsdale201/wp-agent-skills