aes-gcm

Pure Rust AES-GCM authenticated encryption with optional hardware acceleration

Library
Cargo
v0.11.1
967 stars
Apache-2.0 OR MIT

Repository Health

Pre-computed score based on development activity, maintenance, community, maturity, and trend momentum. How we score it →
72 /100 Good
Development Activity 72
Maintenance 44
Community 72
Maturity 60
Momentum 40

Technical Analysis

AI-assessed by reading the actual repository — architecture, code quality, innovation, and documentation. How we score it →
76 /100 Good
Architecture 80
Code Quality 82
Innovation 75
Learning Curve 65

aes-gcm is a pure-Rust implementation of AES-GCM (Galois/Counter Mode), an Authenticated Encryption with Associated Data (AEAD) cipher widely used for TLS, disk encryption, and secure messaging protocols. It is one of the flagship crates in the RustCrypto AEADs workspace, which also hosts related ciphers such as ChaCha20Poly1305, AES-SIV, and CCM behind a shared aead trait interface.

The crate implements the encryption/decryption traits defined by the aead crate, supports no_std environments for embedded use, and can take advantage of architecture-specific hardware acceleration (AES-NI on x86/x86_64, ARMv8 crypto extensions) via the underlying aes crate, falling back to a constant-time software implementation otherwise. It is downloaded well over 100 million times, making it one of the most widely used cryptography primitives in the Rust ecosystem.

What You Get

  • A pure-Rust AES-GCM implementation conforming to the shared aead crate’s Aead/AeadInPlace traits
  • Optional hardware acceleration (AES-NI, ARMv8 crypto extensions) via the underlying aes crate, with constant-time software fallback
  • no_std support for embedded and constrained environments
  • Optional zeroize integration for securely clearing key material from memory
  • Interoperability with sibling AEAD crates (ChaCha20Poly1305, AES-SIV, CCM, EAX) through a consistent API
  • Dual Apache-2.0/MIT licensing for flexible integration into both open-source and commercial projects

Common Use Cases

  • Encrypting data at rest (files, database fields) with authenticated encryption to detect tampering
  • Implementing custom secure transport or messaging protocols that need AEAD guarantees
  • Embedded and IoT applications requiring no_std cryptography with hardware-accelerated performance
  • Building higher-level cryptographic libraries or key-management systems on top of a vetted AEAD primitive

Under The Hood

Architecture - aes-gcm is one crate within the RustCrypto AEADs Cargo workspace, which groups a dozen related AEAD cipher implementations (aes-gcm, aes-gcm-siv, aes-siv, chacha20poly1305, ccm, eax, mgm, deoxys, ascon) under a shared workspace and a common aead trait crate maintained separately. The aes-gcm crate itself is compact (~390 lines in lib.rs), implementing the GCM authenticated-encryption mode over a generic block cipher parameter, with counter-mode encryption (via the ctr crate) combined with GHASH-based authentication (via the ghash crate). Tech Stack - Pure Rust with no_std support by default; optional dependencies gate in the aes crate for hardware-accelerated (AES-NI/ARMv8) or portable software implementations, and zeroize for secure memory clearing; edition 2024, MSRV 1.85. Code Quality - The core crate has no inline unit tests in src/, relying instead on the workspace’s tests/ directory (e.g. aes128gcm.rs, aes256gcm.rs, other_ivlen.rs) which exercises official NIST/RFC test vectors — a common and appropriate pattern for cryptography crates where correctness is verified against published test vectors rather than ad hoc unit tests; the crate is maintained by the RustCrypto organization with heavy scrutiny given its security-critical nature. API Design - The API surface is deliberately minimal and consistent with sibling AEAD crates via the shared aead trait, so switching between AES-GCM, ChaCha20Poly1305, or AES-SIV requires little code change; documentation links to docs.rs and the crate emphasizes correct nonce handling, a common pitfall for AEAD ciphers.

Used by 23 apps in this directory

Rust
98%

Stalwart

Collaboration

15,013

All-in-one secure mail and collaboration server covering IMAP, JMAP, SMTP, CalDAV, CardDAV, and WebDAV in a single memory-safe Rust binary.

View details
88
Repo Health
81
Technical
65
Dependency
Built with
Rust 98%
Updated 2 days ago
Rust
47%
MIT

Svix

Automation · Developer Tools

3,441

Open source, self-hostable webhook infrastructure that handles delivery, retries, HMAC signing, and multi-tenant event management so you never have to build a webhooks system from scratch.

View details
91
Repo Health
77
Technical
67
Dependency
Built with
Rust 47%
C# 16%
Updated yesterday
TypeScript
68%
Apache 2.0

tabularis

Databases · Developer Tools

5,146

Open-source desktop SQL workspace with built-in PostgreSQL, MySQL, and SQLite drivers, SQL notebooks, a visual query builder, and a built-in MCP server for AI agents like Claude and Cursor.

View details
84
Repo Health
89
Technical
69
Dependency
Built with
TypeScript 68%
Rust 32%
Updated yesterday
Rust
65%
Apache 2.0

Temps

Analytics · Devops · Monitoring

831

A self-hosted Rust PaaS that replaces Vercel, Sentry, PostHog, Pingdom, Resend, and E2B with one binary — plus 440+ CLI operations agents like Claude Code can drive directly.

View details
81
Repo Health
86
Technical
67
Dependency
Built with
Rust 65%
TypeScript 33%
Updated today
Rust
50%
Apache 2.0

Vibe Kanban

AI Agents · AI Code Assistants · Project Management

28,312

A kanban board for planning work and dispatching Claude Code, Codex, Gemini CLI, and eight other coding agents into isolated git worktrees, then reviewing and merging their diffs from one UI.

View details
74
Repo Health
75
Technical
64
Dependency
Built with
Rust 50%
TypeScript 46%
Updated 3 weeks ago

Join founders buildingwith open source

Opinionated takes, migration guides, cost-saving tips, and insights from the open source ecosystem.

Subscribe on Substack
Join 750+ subscribers