Skip to content

Scrypted Cloud 0.2.53: ERR_CRYPTO_ECDH_INVALID_PUBLIC_KEY in @eneris/push-receiver breaks Cloud/Alexa authentication #2143

Description

@Saschaa19

Environment

  • Scrypted Server: 0.145.0
  • Scrypted Cloud plugin: 0.2.53
  • Platform: Docker / Linux x64
  • Node.js: 22.21.0
  • Scrypted Cloudflare tunnel establishes successfully
  • Cloud connectivity pre-checks (DNS, UDP/QUIC, TCP/HTTP2, Cloudflare API) all PASS

Problem

Scrypted Cloud repeatedly throws:

Error: Public key is not valid for specified curve
code: ERR_CRYPTO_ECDH_INVALID_PUBLIC_KEY

The stack trace points to:

  • http_ece/ece.js
  • @eneris/push-receiver/dist/utils/decrypt.js
  • @eneris/push-receiver/dist/client.js

The Cloud plugin continues to show LOGIN. Alexa account linking also fails, while the Cloudflare tunnel itself is healthy.

Troubleshooting already performed

I inspected the Scrypted Cloud plugin's LevelDB storage.

The @scrypted/cloud PluginDevice record contains a persisted storage.config used by the push receiver, while storage.token_info is stored separately.

With Scrypted fully stopped, I:

  1. Created an offline backup of the LevelDB database.
  2. Created a working copy.
  3. Removed only storage.config from the @scrypted/cloud PluginDevice record.
  4. Preserved storage.token_info and all other fields.
  5. Replaced the database with the modified offline copy.
  6. Restarted Scrypted.

After restart, the Cloud plugin created and persisted a new storage.config, confirming that fresh push credentials/configuration were generated.

Despite this, ERR_CRYPTO_ECDH_INVALID_PUBLIC_KEY returned immediately after registration.

On the first fresh registration attempt I also saw:

Register request has failed with Error=PHONE_REGISTRATION_ERROR

On later restarts, PHONE_REGISTRATION_ERROR no longer appeared, but ERR_CRYPTO_ECDH_INVALID_PUBLIC_KEY continued consistently.

Bundled push-receiver code

I inspected the source map bundled with @scrypted/cloud.

It contains:

  • @eneris/push-receiver/dist/client.js
  • @eneris/push-receiver/dist/utils/decrypt.js

The bundled decrypt.js uses http_ece and:

crypto.createECDH('prime256v1')

The failure occurs in this decryption path.

A very similar ERR_CRYPTO_ECDH_INVALID_PUBLIC_KEY stack has been reported in other software using @eneris/push-receiver, where an upstream push-receiver fix was referenced.

Could @scrypted/cloud be bundling a push-receiver version affected by that issue?

Would it be possible to update the bundled @eneris/push-receiver, or is there another recommended fix for the Cloud plugin?

I can provide additional sanitized logs if needed.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions