| AuthenticationError | AEAD authentication failed. A wrong key and modified authenticated data are intentionally reported as the same error. |
| ChunkCountExceededError | A chunk count derived from a plaintext or ciphertext length exceeds MAX_CHUNK_COUNT. |
| CriticalHeaderError | A crit (label 2) listing was rejected — wrong bucket, wrong shape, or naming a label this profile does not understand or does not actually carry. |
| CryptoOperationError | A cryptographic runtime operation failed for a reason other than authentication. |
| EnvelopeError | Base class for every error raised by this package. |
| InvalidChunkSizeError | chunkSize is not an integer within [MIN_CHUNK_SIZE, MAX_CHUNK_SIZE]. |
| InvalidCiphertextLengthError | The ciphertext length cannot represent a valid object for the selected scheme. |
| InvalidKeyError | A CEK or KEK is not a 32-byte, non-zero AES-256 key. |
| InvalidNonceError | A base nonce, chunk index, or last-chunk flag is not valid for per-chunk nonce derivation. |
| InvalidPlaintextError | Plaintext supplied to an encryption operation is not a byte string. |
| InvalidPlaintextLengthError | plaintextLength is not a non-negative safe integer or exceeds the limit for the selected scheme or encoded layout. |
| MalformedEnvelopeError | The envelope, or a value destined for one, does not match this package’s wire profile. Raised on both paths: by encode when a caller’s input would produce bytes this package could not read back, and by decode on anything the profile forbids. |
| NoUsableRecipientError | No recipient in a valid envelope could provide a CEK. |
| RecipientAttemptLimitError | A recipient unwrapper reached its configured limit of key-unwrap attempts. |
| RecipientUnwrapError | A recipient unwrapper failed instead of declining the available recipients. |
| UnsupportedSchemeError | The protected header’s alg is not one of the schemes this package implements (ALG_AES_256_GCM or ALG_CHUNKED_AES_256_GCM_STREAM). |