store your secret bits safe from prying eyes
mongodb mongo
Go 100%

README.md

secretbits #

Store your secret bits safe from prying eyes

Transparently encrypt select MongoDB document fields before sending them to a remote cluster and decrypt on the back back in.

import(
  sb "tangled.org/softprops.tngl.sh/secretbits"
  "go.mongodb.org/mongo-driver/v2"
  "go.mongodb.org/mongo-driver/v2/bson"
  "go.mongodb.org/mongo-driver/v2/options"
)

type Example struct {
  Name   string    `bson:"_id"`
  Secret sb.String `bson:"secret"` // this field will be encrypted before sending to MongoDB cluster
}


func main() {
   reg, err := sb.NewRegistry(encryptionKey)
   if err {
     log.Fatal(err)
   }

  client, err := mongo.Connect(
    options.Client().ApplyURI(uri).SetRegistry(reg)
  )
	if err != nil {
		log.Fatal(err)
	}
 

  col := client.Database("simplebits").Collection("examples")

  // store document with encrypted field
  _ = col.InsertOne(
    context.TODO(),
    Example {
      Name: "exhibitA",
      Secret: sb.String("this will be encrypted"),
    }
  )

  // read document back and the encrypted field will be decrypted
  _ = col.FindOne(context.TODO(), bson.M{"_id":"exhibitA"})
}

How is this different from csfle?

  • It doesn't require Cgo. You can use Go proper.
  • It doesn't require register a schema definition with a MongoDB cluster. Your encrypted fields are defined by their type.
  • It isn't coupled to complicated key management. How you managed your keys is up to you and your application.
  • It's less of a mouthful

Technical Bits

This library uses a FIPS-compliant AEAD encryption cipher called AES-GCM which is encrypts select document fields before sending documents to the server and decrypts them when received on the way back using a bson Registry type Encoder/Decoder combination.

softprops 2026