# decrypt

> **decrypt**(`cek`): `ReadableWritablePair`\<[`Uint8Array`](https://developer.mozilla.org/docs/Web/JavaScript/Reference/Global_Objects/Uint8Array)\<`ArrayBufferLike`\>, [`Uint8Array`](https://developer.mozilla.org/docs/Web/JavaScript/Reference/Global_Objects/Uint8Array)\<`ArrayBufferLike`\>\>

Defined in: [packages/filecoin-encryption-envelope/src/aes-gcm-stream.ts:459](https://github.com/FilOzone/synapse-sdk/blob/ac45b247918d1482a4bd5f301722edb6f0a5b349/packages/filecoin-encryption-envelope/src/aes-gcm-stream.ts#L459)

Decrypt a scheme-2 (chunked AES-256-GCM STREAM) object using a direct CEK.

Write the encoded object to `writable`; `readable` yields each plaintext
chunk only after its authentication tag verifies. The pair can also be used
with `source.pipeThrough(decrypt(cek))`.

Keep `cek` unchanged until `readable` closes or errors. Input blocks may be
reused once their `write()` resolves. If decryption fails, discard earlier
plaintext: authentic chunks alone do not establish a complete object.

## Parameters

| Parameter | Type |
| ------ | ------ |
| `cek` | [`Uint8Array`](https://developer.mozilla.org/docs/Web/JavaScript/Reference/Global_Objects/Uint8Array) |

## Returns

`ReadableWritablePair`\<[`Uint8Array`](https://developer.mozilla.org/docs/Web/JavaScript/Reference/Global_Objects/Uint8Array)\<`ArrayBufferLike`\>, [`Uint8Array`](https://developer.mozilla.org/docs/Web/JavaScript/Reference/Global_Objects/Uint8Array)\<`ArrayBufferLike`\>\>