# Encryption middleware

> Keep selected event data, step results, and function output encrypted while Inngest coordinates runs.

Encrypt selected event data, step results, and function output before Inngest stores them. Your application holds the key and decrypts the data when a function needs it.

## Set up TypeScript v4

Install [`@inngest/middleware-encryption`](https://www.npmjs.com/package/@inngest/middleware-encryption). Keep the key in your application's secret store and provide it to every app process that sends or handles the encrypted data.

```bash
npm install @inngest/middleware-encryption
```

```typescript {{ title: "TypeScript" }}
import { Inngest } from "inngest";
import { encryptionMiddleware } from "@inngest/middleware-encryption";

const encryptionKey = process.env.MY_ENCRYPTION_KEY;
if (!encryptionKey) {
  throw new Error("MY_ENCRYPTION_KEY is required");
}

export const inngest = new Inngest({
  id: "my-app",
  middleware: [
    encryptionMiddleware({ key: encryptionKey }),
  ],
});
```

```python {{ title: "Python" }}
import os

import inngest
from inngest_encryption import EncryptionMiddleware

encryption_key = os.environ.get("MY_ENCRYPTION_KEY")
if not encryption_key:
    raise RuntimeError("MY_ENCRYPTION_KEY is required")

inngest_client = inngest.Inngest(
    app_id="my-app",
    middleware=[EncryptionMiddleware.factory(encryption_key)],
)
```

Encrypt sensitive values in your own code before you send them in events or return them from `step.Run`, and decrypt them inside your function.

Register the middleware on the client to apply it to that app's functions. You can also register it on one function.

## Know what it encrypts

By default, the middleware encrypts all step data and function output. For events, it encrypts only `event.data.encrypted`. Other event fields remain outside that encrypted field. Put sensitive event values inside `data.encrypted`, or set `eventEncryptionField` to a different field name. Check your event shape before sending real data.
The middleware can read data written with an older key when you configure `fallbackDecryptionKeys`. The `decryptOnly` option stops new encryption while still decrypting existing data. Plan key changes around runs and events that still need the old key.

## SDKs and next steps

TypeScript and Python encryption middleware can interoperate when configured with compatible keys and fields. The Go SDK supports middleware but has no encryption middleware yet.

- [Middleware](/docs-markdown/durable-execution/guides-and-advanced/middleware) explains the middleware lifecycle.
- [Creating middleware](/docs-markdown/durable-execution/guides-and-advanced/middleware/creating-middleware) covers custom middleware.