age Encryption, in Your Browser
age is a small, modern file encryption format with a free command-line tool. This page opens and makes password-locked .age files in your browser, byte for byte compatible with the age app.
A locked message
This is what one looks like.
-----BEGIN AGE ENCRYPTED FILE----- YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IHNjcnlwdCBvdnlrTGlYUmtCaCtXV0pR RUdsWEpBIDE4CkJLVWtDZmxqOFQ5VVluUFdEVGpSanRERkZRaGRHT2dBcUVqakw5 YmMzaHMKLS0tIGN3TzBySW13NXdsOGlkenhnYU5OUnVpVGZlL0E3QXBHd2Q1UUdP MzlLdmsKxvSP5aQgEvXG2WMVZDdV8NCGe+QiUVcu5oLSGx2QTSI+mwZGPlKfHRoY tQD/Q6Qe6LytmIq6H9J1/scUYke8JbJKTyYydNEru9E= -----END AGE ENCRYPTED FILE-----
Made with the age app; it opens here too.
How this works: Method, 5 sources,
How this works
Method
Everything runs in your browser, in the open age format (v1) through typage, the official TypeScript age implementation. Your password is stretched with scrypt (N = 2^18, r = 8, p = 1, the age default) into a key that wraps a random 128-bit file key; the content is encrypted with ChaCha20-Poly1305 in 64 KiB chunks, so any change is detected. Files made here open with `age -d`; the tests use files made by the age command-line tool and the C2SP age test vectors.
Sources
Changes
- Pages for each job: encrypt text, encrypt a file, decrypt, and what age is, each opening the tool on that job.
- First published: text, photos and files, as a block, a file or a link, in the age format.
What age is
age (always lower case, said with a hard g) is a file encryption tool, format and Go library, described by its authors as simple, modern and secure, with small explicit keys and no config options. It does one job, encrypting files, one way, so there are no ciphers or settings to choose wrong.
A file can be locked to someone’s public key (an age1… recipient, or an SSH key) or to a passphrase. This page does the passphrase kind: it is what you want for sending something to a person who doesn’t use age, because all they need is the password and a browser.
Inside a .age file
An age file has a short text header and a binary payload. The header starts with the line age-encryption.org/v1, then one stanza per way to open it; a passphrase file has exactly one, beginning -> scrypt, with a random salt and the work factor. A check value (an HMAC) ends the header, so a changed header is caught before anything is decrypted.
The payload is encrypted with ChaCha20-Poly1305 in 64 KiB chunks under a key derived from the file’s own random 128-bit key. With a passphrase, scrypt with N = 2^18, r = 8 and p = 1 stretches the passphrase into the key that wraps the file key, which costs about 256 MiB of memory per guess. The text form, made with age -a, wraps it all in -----BEGIN AGE ENCRYPTED FILE----- lines.
The same file, on the command line
With age installed (brew install age, winget install --id FiloSottile.age, or apt install age), these are the commands for the files this page makes and opens:
age -p -o notes.txt.age notes.txt # lock with a passphrase age -d -o notes.txt notes.txt.age # unlock (asks for it) age -p -a notes.txt > notes.txt.asc # lock as a text block
Left empty, age -p offers to generate a passphrase of random words for you, the same idea as Suggest on this page.
Good to know
- age describes itself as a simple, modern and secure file encryption tool, format and Go library, with small explicit keys, post-quantum support and no config options. Source: age, the reference implementation (README)
- A passphrase file’s scrypt stanza must be the only stanza in its header, which keeps the implicit promise that only someone with the password made it. Source: The age file format, v1
- This page runs typage, the TypeScript implementation of age, in a background worker. Source: typage, the TypeScript implementation of age
Frequently Asked Questions
How do I open a .age file?
If it was locked with a passphrase, drop it on this page and type the passphrase; it opens in your browser with nothing to install. If it was locked to an age key or an SSH key, you need that key and the age app: age -d -i key.txt file.age.
Is age better than GPG?
They do different amounts. GPG (OpenPGP) also signs, manages keyrings and encrypts email, with many options. age only encrypts files, with no options and small keys. For a password-locked file to send someone, age is the simpler choice; for signatures or encrypted email, it isn’t meant to replace GPG.
Is age encryption secure?
It uses well-studied parts: ChaCha20-Poly1305 for the content, HKDF-SHA-256 for keys, and scrypt for passphrases, all named in its published specification, which has shared test vectors that independent implementations check against. As with any password-based scheme, a short or common password is the weak point.
Do files from this page work with rage and other age apps?
Yes. The format is the same, so a file locked here opens with age, rage (the Rust version) or any other implementation that supports passphrases, and the other way round. The tests for this page open files made by the age command-line tool and run the C2SP test vectors.