Creates a new EncryptedPouch instance.
PouchDB database instance
Encryption password (will be derived using PBKDF2 by default)
Optionallistener: PouchListenerOptional callbacks for document changes, deletions, etc.
Optionaloptions: EncryptedPouchOptionsOptional configuration (e.g., passphraseMode)
Loads all existing documents from the database and starts change detection.
This should be called once after creating the EncryptedStore instance. It will decrypt all documents, trigger onChange callbacks (batched by table), and set up real-time change listeners.
Creates or updates a document in the specified table.
If the document has no _id, one will be auto-generated.
If the document has an _id and _rev, it will be updated.
If the _rev doesn't match the current revision, a conflict error is thrown.
Document type/table (e.g., "expenses", "tasks")
Document to store. Include _rev for updates.
The saved document with _id and _rev populated
Writes multiple documents to a table in a single bulk operation.
Documents without an _id get one auto-generated. Documents with an _id
are upserted: include _rev to update an existing document, omit it to
create a new one (a stale or missing _rev on an existing document
surfaces as a write error via PouchListener.onError with
kind: "write", while the rest of the batch still succeeds).
Successful writes flow through the existing changes feed and are reported via PouchListener.onChange, batched per table.
Document table name
Documents to write
Retrieves a document by table and ID.
Document table name
Document ID within the table
The decrypted document, or null if not found
Deletes all documents from the local database only.
Automatically disconnects sync first to prevent deletions from propagating to remote. Use this when you want to clear local data without affecting the remote server.
Deletes all documents locally AND propagates deletions to remote server.
Waits for sync to complete before returning.
The remote connection must be established first with connectRemote().
Retrieves all documents, optionally filtered by table.
Optionaltable: stringOptional table name to filter by
Array of decrypted documents
Export every document (or a subset of tables) as a plaintext, re-loadable
BackupDump — decrypted, grouped by table, with _rev stripped. The
basis of a full backup; pair it with loadFromJSONBackup to restore.
Tables are discovered from the stored documents themselves (their table_id
ids), so a dump is complete without the caller enumerating table names — the
key reason backup belongs in the library. Design documents are skipped.
Decryption failures surface via onError (like getAll) and the
offending document is omitted.
Optionalopts: { tables?: string[] }Optionaltables?: string[]Restrict the dump to these tables (default: all).
Load a BackupDump into THIS store, which must be empty (a freshly
created database). Each table is written in one bulk putAll, then every
table's document count is re-read and compared against the dump — a mismatch
throws, so a per-document putAll failure can never silently lose data.
Restore is deliberately "create a fresh database, then load", never "wipe an
existing database, then load": deleteAllLocal leaves tombstones, and
re-putting a document with the same id but no _rev would 409 against the
tombstone. A pristine store makes that whole class of conflict impossible.
On a thrown count check the store may be left partially populated — the caller should destroy the fresh database rather than reuse it.
Permanently delete the underlying database and stop change detection.
Unlike deleteAllLocal (which tombstones every document, leaving
deleted leaves that could conflict with a later re-put), this removes the
database outright — no tombstones remain. Use it to discard a throwaway /
dry-run database, or to clean up the old database after restoring into a new
one. The instance is unusable afterward.
StaticverifyCheck whether password can decrypt an existing database, without opening a
persistent store or attaching a change feed — it reads at most one stored
document and attempts to decrypt it.
Returns true if a document decrypts, false if decryption fails (wrong
password). A database with no encrypted documents returns true: a
passphrase cannot be disproven against zero ciphertext. Intended as a
"confirm your passphrase before a destructive action" gate — the caller opens
a handle to the current database and passes it in.
Optionaloptions: EncryptedPouchOptionsOptions for configuring the EncryptedPouch
OptionalpassphraseMode?: "derive" | "raw"Key derivation mode for the passphrase.
"derive" (default): Use PBKDF2 with 100k iterations for user passphrases.
Recommended for production use. Provides strong protection against brute-force
and dictionary attacks. First unlock will take ~50-100ms.
"raw": Use SHA-256 only. For pre-derived keys or advanced users who handle
key derivation themselves. Allows full control over KDF algorithm, iterations,
and progress UI.
Connects to a remote CouchDB server for bidirectional sync.
Remote server configuration
// Continuous sync (live updates)
await store.connectRemote({
url: 'http://localhost:5984/mydb',
live: true,
retry: true
});
// One-time sync only (manual control)
await store.connectRemote({
url: 'http://localhost:5984/mydb',
live: false,
retry: false
});
await store.syncNow(); // Manually trigger sync
Disconnects from the remote sync server.
Stops continuous sync if it was enabled.
Trigger an immediate one-time sync with the remote. Requires that connectRemote() has been called first. Returns a promise that resolves when the sync completes.
Manually resolves a document conflict by choosing the winning version.
Document table name
Document ID within the table
The document version to keep (must include _rev)
// In onConflict callback
onConflict: async (conflicts) => {
for (const conflict of conflicts) {
// Pick the version with the latest timestamp
const latest = [conflict.winner, ...conflict.losers]
.sort((a, b) => b.timestamp - a.timestamp)[0];
await store.resolveConflict(conflict.table, conflict.id, latest);
}
}
Retrieves conflict information for a document without triggering the callback.
Document table name
Document ID within the table
Conflict information if conflicts exist, null otherwise
Encrypted document store with change detection and sync capabilities.
This class provides a simple API for storing encrypted documents in PouchDB with real-time change detection and optional sync to CouchDB servers.
Example