Skip to content

Encrypt & Decrypt Text and Files

Lock a message, photo or file with a password, then share it as text, a file or a link. It all happens in your browser, in the open age format, so it opens with age on any computer too.

Example

A locked message

This is what one looks like.

-----BEGIN AGE ENCRYPTED FILE-----
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IHNjcnlwdCBvdnlrTGlYUmtCaCtXV0pR
RUdsWEpBIDE4CkJLVWtDZmxqOFQ5VVluUFdEVGpSanRERkZRaGRHT2dBcUVqakw5
YmMzaHMKLS0tIGN3TzBySW13NXdsOGlkenhnYU5OUnVpVGZlL0E3QXBHd2Q1UUdP
MzlLdmsKxvSP5aQgEvXG2WMVZDdV8NCGe+QiUVcu5oLSGx2QTSI+mwZGPlKfHRoY
tQD/Q6Qe6LytmIq6H9J1/scUYke8JbJKTyYydNEru9E=
-----END AGE ENCRYPTED FILE-----

Made with the age app; it opens here too.

How this works: Method, 4 sources, Checked against 7 worked examples,

How this works

Method

Everything runs in your browser, in the open age format (v1) through typage, the official TypeScript age implementation. Your password is stretched with scrypt (N = 2^18, r = 8, p = 1, the age default) into a key that wraps a random 128-bit file key; the content is encrypted with ChaCha20-Poly1305 in 64 KiB chunks, so any change is detected. Files made here open with `age -d`; the tests use files made by the age command-line tool and the C2SP age test vectors.

How it’s tested

7 worked examples for this page are checked by automated tests before every release: given the inputs, the tool must show the expected answer.

Changes

  • First published: text, photos and files, as a block, a file or a link, in the age format.

How we make toolsReport a mistake

Open it anywhere with age

Everything locked here is a standard age file. With the free age tool installed, this gives back the original file, asking for the password:

age -d -o photo.jpg photo.jpg.age

A copied block works the same way: save it as a file first. And the other way round, anything age locks with a password (age -p) opens on this page.

How it works

A random 128-bit key encrypts your content with ChaCha20-Poly1305, 64 KiB at a time, so a single changed byte is caught. That key is locked with your password, stretched by scrypt with N = 218, r = 8 and p = 1: every guess at the password costs the same second of work and 256 MB of memory. The code is typage, the official TypeScript version of age, running in a background worker of this page.

Frequently Asked Questions

Is anything uploaded?

No. Encrypting and decrypting happen in your browser, and nothing is saved. A share link keeps the locked message after the # sign, the part of a web address that browsers never send to a server, so not even this site sees it. Clear wipes the page, and so does leaving it.

What happens if I forget the password?

The content is gone. There is no reset, no recovery and no back door: the password is the only key, and we never see it. Keep it somewhere safe, such as a password manager.

Can I open it without this website?

Yes. It uses age, an open file format with a free command-line tool for Mac, Windows and Linux. Save the block or the .age file and run age -d on it; age asks for the password. Anything age locks with a password opens here too.

How strong does the password need to be?

scrypt makes every guess slow and memory-hungry (about a second and 256 MB on a laptop here), but a short or common password can still be guessed. A few random words, like the ones Suggest gives you, are strong and easy to read out.

Why can’t big files be shared as a link?

A link carries the whole locked message, so it grows with it. Links are offered up to 32,000 characters, short enough for chat apps and email to keep intact. Anything bigger downloads as a .age file to send instead, and files are read in chunks, so large ones work too.

What doesn’t it protect against?

It hides what is inside, not that a message exists or roughly how big it is. It can’t help if the password is weak, travels with the link, or if someone can see your screen or has malware on your device.