# `SSL.Crypto.AEAD`
[🔗](https://github.com/gsmlg-dev/http_fetch/blob/v0.16.7/apps/ex_ssl/lib/ssl/crypto/aead.ex#L1)

Pure TLS 1.3 AEAD encryption and authenticated decryption.

The record nonce is derived from the supplied traffic state's static IV and
sequence number. Sequence advancement remains the caller's responsibility.

# `error_reason`

```elixir
@type error_reason() ::
  :authentication_failed
  | :encryption_failed
  | :decryption_failed
  | :invalid_traffic_state
  | {:unsupported_cipher_suite, term()}
  | {:unsupported_capability, SSL.Crypto.TrafficState.cipher_suite()}
  | {:invalid_key, :not_binary | :wrong_length}
  | {:invalid_iv, :not_binary | :wrong_length}
  | {:invalid_sequence, :out_of_range}
  | {:invalid_aad, :not_binary}
  | {:invalid_plaintext, :not_binary | :too_long}
  | {:invalid_ciphertext, :not_binary | :too_long}
  | {:invalid_tag, :not_binary | :wrong_length}
```

# `decrypt`

```elixir
@spec decrypt(SSL.Crypto.TrafficState.t(), term(), term(), term()) ::
  {:ok, binary()} | {:error, error_reason()}
```

# `encrypt`

```elixir
@spec encrypt(SSL.Crypto.TrafficState.t(), term(), term()) ::
  {:ok, binary(), binary()} | {:error, error_reason()}
```

# `supported?`

```elixir
@spec supported?(term()) :: boolean()
```

---

*Consult [api-reference.md](api-reference.md) for complete listing*
