On this page
Overview
libsodium is a cryptography library for adding encryption, decryption, digital signatures, password hashing, and related operations to applications. It extends NaCl while retaining API compatibility and offers consistent algorithms and formats across environments including Windows, iOS, Android, JavaScript, and WebAssembly. It is designed for developers who prefer purpose-specific high-level APIs over assembling low-level primitives.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Provide purpose-specific APIs for encryption, signatures, and key management
The library covers secret-key and public-key encryption, digital signatures, secure random data, password hashing, key exchange, and key derivation. Its quickstart requires sodium_init() before other calls and recommends authenticated high-level APIs such as crypto_secretbox, crypto_aead, and crypto_secretstream.
Keep algorithms and data formats consistent across supported platforms
libsodium supports Windows, iOS, Android, JavaScript, WebAssembly, and other environments while keeping algorithms and input/output formats consistent. Release 1.0.22 also adds ML-KEM768, the X-Wing hybrid of ML-KEM768 and X25519, plus one-shot and streaming SHA-3 APIs.
Best fit
Fits applications that want safer interfaces instead of custom cryptographic constructions
It is a candidate for encrypting stored or transmitted data, signing content, storing passwords, and establishing shared keys across several platforms. Language bindings can also provide access to the same constructions and formats when a project is not written in C.
Before adoption
Initialization, return values, keys, and nonces remain application responsibilities
Applications must call sodium_init() first, check error and verification results, and protect unpredictable secret keys. Some constructions require a unique key-and-nonce pair; reusing one can destroy confidentiality, so protocol design and state management still matter.
The documentation warns that the low-level crypto_stream() interface does not authenticate ciphertext and should not be used as a complete encryption scheme. Manual builds require an appropriate C toolchain and Autotools, and teams should verify distribution archives, run tests, and account for platform linker setup. The project uses the ISC license.
Official sources
- [1]jedisct1/libsodium — README at 1.0.22(2026-10-04)
- [2]libsodium quickstart and FAQ at observed documentation commit(2026-10-04)
- [3]libsodium installation guide at observed documentation commit(2026-10-04)
- [4]jedisct1/libsodium — ISC LICENSE at 1.0.22(2026-10-04)
- [5]libsodium 1.0.22 release(2026-10-04)
Supplemental curator note
Algorithm coverage is only part of the decision: the application must still manage keys, nonces, and error handling correctly. Prefer this library when the team can follow its high-level APIs and purpose-specific guidance instead of designing custom constructions.
Try it in 3 steps
- 1
Download the 1.0.22 source distribution
The same release also publishes .sig and .minisig files. For adoption, separately obtain a trusted key and matching tool to verify archive integrity and provenance.
curl -LO https://github.com/jedisct1/libsodium/releases/download/1.0.22-RELEASE/libsodium-1.0.22.tar.gz - 2
Extract and configure the build
This follows the official Autotools flow for a POSIX-like environment with a C compiler.
tar xzf libsodium-1.0.22.tar.gz cd libsodium-1.0.22 ./configure - 3
Build and run the test suite
Confirm the bundled tests pass before any system-wide installation.
make -j2 && make check
Growth
Growth trends · Last 30 days
13,973 Stars
Trend data is still being collected.
Development activity
Last 90 days · weekly
- Commits (last 30 days)
- 4
- Open PRs
- 0
Development activity is still being collected.
Built with
Categories and tags
Categories
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- crypto
- cryptography
- c
- zig-package
- Stars
- 13,973
- Forks
- 1,887
- Watchers
- 377
- Open issues
- 1
- Contributors
- 128
- Owner type
- User
- Primary language
- C
- License
- Not determined
- Repository last updated
- Sep 28, 2026
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- NGINX31,787 Stars
2 shared tag(s) · Same language
run web delivery, reverse proxying, and load balancing while choosing between mainline and stable streams
C - ImageMagick17,593 Stars
2 shared tag(s) · Same language
turn image conversion, editing, and composition into reproducible CLI/API pipelines
C - Fluent Bit8,131 Stars
2 shared tag(s) · Same language
collect, transform, buffer, and route logs, metrics, and traces
C - GIMP6,470 Stars
2 shared tag(s) · Same language
open-source raster editing with expanded non-destructive workflows in the 3.2 series
C - Bitcoin Core90,305 Stars
2 shared tag(s)
Fully validate Bitcoin peer-to-peer blocks and transactions yourself while optionally running wallet and RPC services on the same node
C++ - BoringSSL2,280 Stars
3 shared tag(s) · 2 shared category(s)
use Google's OpenSSL fork for TLS and cryptography in projects that explicitly track BoringSSL
C++
Report incorrect information
Tell us if any listing information is incorrect or outdated.