k256

Pure Rust secp256k1 elliptic curve library for ECDSA, Schnorr, and ECDH cryptography

Library
Cargo
v0.14.0
876 stars
Apache-2.0 OR MIT

Repository Health

Pre-computed score based on development activity, maintenance, community, maturity, and trend momentum. How we score it →
82 /100 Excellent
Development Activity 92
Maintenance 52
Community 84
Maturity 60
Momentum 40

Technical Analysis

AI-assessed by reading the actual repository — architecture, code quality, innovation, and documentation. How we score it →
86 /100 Excellent
Architecture 90
Code Quality 92
Innovation 85
Learning Curve 78

k256 is a pure Rust implementation of the secp256k1 (K-256) elliptic curve, the curve used by Bitcoin, Ethereum, and most other cryptocurrencies. It provides constant-time scalar and point arithmetic, ECDSA signing and verification with public-key recovery, Taproot Schnorr signatures (BIP340), and Elliptic Curve Diffie-Hellman (ECDH) key agreement, all built on shared abstractions from the elliptic-curve crate maintained by the RustCrypto organization.

The crate is no_std by default, forbids unsafe code, and has been independently audited by NCC Group, making it suitable for embedded, WASM, and other constrained environments alongside conventional application use. It re-exports PKCS#8/SPKI encoding for reading and writing keys in DER or PEM, and its arithmetic is feature-gated so consumers pull in only the operations they need.

What You Get

  • Constant-time secp256k1 scalar and point arithmetic via projective/affine coordinate types with precomputed base-point tables
  • ECDSA signing, verification, and low-S-normalized (BIP0062) public-key recovery, as used by Ethereum
  • Taproot Schnorr signatures per BIP340, including tagged-hash and x-only-pubkey helpers
  • Elliptic Curve Diffie-Hellman (ECDH) key agreement gated behind the ecdh feature
  • PKCS#8/SPKI DER and PEM encoding for secret and public keys via the shared elliptic-curve traits

Common Use Cases

  • Verifying Bitcoin and Ethereum transaction signatures in a Rust node, wallet, or indexer
  • Implementing ECDSA public-key recovery for Ethereum-style address derivation
  • Building Taproot-compatible Schnorr signing/verification for BIP340 wallets
  • Deriving shared secrets over secp256k1 with ECDH in a no_std or embedded context

Under The Hood

Architecture — k256 is organized around a zero-sized Secp256k1 curve marker type implementing the elliptic-curve crate’s Curve/PrimeCurve traits, with feature-gated modules layered on top: src/arithmetic/ (affine/projective points, field and scalar math, precomputed tables), src/ecdsa.rs (SigningKey/VerifyingKey and recovery), src/schnorr.rs (BIP340 Taproot signatures with dedicated schnorr/ submodules), and src/ecdh.rs. This lets consumers pull in only SecretKey/PublicKey type aliases without the arithmetic backend, or opt into full scalar multiplication. Tech Stack — Pure Rust (edition 2024, MSRV 1.85), no_std by default with alloc/std as additive features, depending on sibling RustCrypto crates (elliptic-curve, primeorder, wnaf, hash2curve) rather than any C bindings, plus optional ecdsa/signature/serdect/sha2 for higher-level key types. Code Quality — High: #![forbid(unsafe_code)] at the crate root, tests/projective.rs plus doctested examples in ecdsa.rs/schnorr.rs, a dedicated benches/ suite (ecdsa, field, point, scalar, schnorr) under Criterion, proptest-regressions/ for property-test-found edge cases, and an extensive [lints.clippy] block enforcing unwrap_used, missing_docs, and numeric-cast safety. The crate has been independently audited by NCC Group, which found and fixed high-severity issues in both the ECDSA and Schnorr implementations. API Design — Ergonomic and consistent with sibling RustCrypto curve crates (p256, p384): SecretKey/PublicKey/NonZeroScalar type aliases are shared across the family, doctested usage examples exist for both signing and public-key recovery, and every public item carries rustdoc (enforced by missing_docs lint). Feature flags are numerous (arithmetic, ecdsa, schnorr, ecdh, serde, pem, std, etc.), which adds a real learning curve for newcomers deciding which combination they need.

Used by 5 apps in this directory

TypeScript
80%
GPL 3.0

Bramble

Authentication · Password Manager · Security

399

Local-first, end-to-end encrypted password manager that syncs your vault directly between your own devices over a private peer-to-peer mesh — no server, no account, no cloud in the middle.

View details
75
Repo Health
84
Technical
68
Dependency
Built with
TypeScript 80%
Updated 5 days ago
TypeScript
80%
GPL 3.0

Bramble

Authentication · Password Manager · Security

399

Local-first, end-to-end encrypted password manager that syncs your vault directly between your own devices over a private peer-to-peer mesh — no server, no account, no cloud in the middle.

View details
75
Repo Health
84
Technical
68
Dependency
Built with
TypeScript 80%
Updated 5 days ago
Rust
98%

Stalwart

Collaboration

14,848

All-in-one secure mail and collaboration server covering IMAP, JMAP, SMTP, CalDAV, CardDAV, and WebDAV in a single memory-safe Rust binary.

View details
89
Repo Health
81
Technical
65
Dependency
Built with
Rust 98%
Updated 5 days ago
Rust
98%

Stalwart

Collaboration

14,848

All-in-one secure mail and collaboration server covering IMAP, JMAP, SMTP, CalDAV, CardDAV, and WebDAV in a single memory-safe Rust binary.

View details
89
Repo Health
81
Technical
65
Dependency
Built with
Rust 98%
Updated 5 days ago
Rust
64%
Apache 2.0

Temps

Analytics · Devops · Monitoring

801

A self-hosted Rust PaaS that replaces Vercel, Sentry, PostHog, Pingdom, Resend, and E2B with one binary — plus 440+ CLI operations agents like Claude Code can drive directly.

View details
81
Repo Health
86
Technical
70
Dependency
Built with
Rust 64%
TypeScript 34%
Updated 4 days ago

Join founders buildingwith open source

Opinionated takes, migration guides, cost-saving tips, and insights from the open source ecosystem.

Subscribe on Substack
Join 750+ subscribers