[API reference](https://evolu.dev/docs/api-reference) › [@evolu/common](https://evolu.dev/docs/api-reference/common) › [local‑first/Protocol](https://evolu.dev/docs/api-reference/common/local-first/Protocol) › encodeAndEncryptDbChange

```ts
function encodeAndEncryptDbChange(
  deps: RandomBytesDep,
): (
  message: CrdtMessage,
  key: Uint8Array<ArrayBufferLike> &
    Brand<"Entropy"> &
    Brand<"Length32"> &
    Brand<"EncryptionKey">,
) => EncryptedDbChange;
```

Defined in: [packages/common/src/local-first/Protocol.ts:2338](https://github.com/evoluhq/evolu/blob/113517df8a8da4e4eed41363077878e657b22fca/packages/common/src/local-first/Protocol.ts#L2338)

Encodes and encrypts a [DbChange](https://evolu.dev/docs/api-reference/common/local-first/Storage/variables/DbChange) using the provided owner's encryption
key. Returns an encrypted binary representation as [EncryptedDbChange](https://evolu.dev/docs/api-reference/common/local-first/Storage/type-aliases/EncryptedDbChange).

The plaintext starts with the format version of the change, which is
independent of [protocolVersion](https://evolu.dev/docs/api-reference/common/local-first/Protocol/variables/protocolVersion), and the timestamp, which proves that
the change belongs to the timestamp it is sent with.
[decryptAndDecodeDbChange](https://evolu.dev/docs/api-reference/common/local-first/Protocol/functions/decryptAndDecodeDbChange) rejects a newer format version and accepts
older ones.