Skip to content

Decrypt a Locked Message or File

Paste the locked text or link someone sent you, or drop the .age file, then type the password. It opens here in your browser, and what you unlock is never sent anywhere.

Example

A locked message

This is what one looks like.

-----BEGIN AGE ENCRYPTED FILE-----
YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IHNjcnlwdCBvdnlrTGlYUmtCaCtXV0pR
RUdsWEpBIDE4CkJLVWtDZmxqOFQ5VVluUFdEVGpSanRERkZRaGRHT2dBcUVqakw5
YmMzaHMKLS0tIGN3TzBySW13NXdsOGlkenhnYU5OUnVpVGZlL0E3QXBHd2Q1UUdP
MzlLdmsKxvSP5aQgEvXG2WMVZDdV8NCGe+QiUVcu5oLSGx2QTSI+mwZGPlKfHRoY
tQD/Q6Qe6LytmIq6H9J1/scUYke8JbJKTyYydNEru9E=
-----END AGE ENCRYPTED FILE-----

Made with the age app; it opens here too.

How this works: Method, 5 sources, Checked against 1 worked example,

How this works

Method

Everything runs in your browser, in the open age format (v1) through typage, the official TypeScript age implementation. Your password is stretched with scrypt (N = 2^18, r = 8, p = 1, the age default) into a key that wraps a random 128-bit file key; the content is encrypted with ChaCha20-Poly1305 in 64 KiB chunks, so any change is detected. Files made here open with `age -d`; the tests use files made by the age command-line tool and the C2SP age test vectors.

How it’s tested

One worked example for this page is checked by automated tests before every release: given the inputs, the tool must show the expected answer.

Changes

  • Pages for each job: encrypt text, encrypt a file, decrypt, and what age is, each opening the tool on that job.
  • First published: text, photos and files, as a block, a file or a link, in the age format.

How we make toolsReport a mistake

Three ways in

A link. If you were sent a link to this tool ending in #age= and a long string, just open it: the page lands on this side with the message loaded, and the password box is ready. Pasting such a link into the box, or into the address bar of a tab that has this page open, does the same.

A block of text. Copy everything from -----BEGIN AGE ENCRYPTED FILE----- to -----END AGE ENCRYPTED FILE----- and paste it into the box, or anywhere on the page outside a text field. Extra spaces or line breaks that email added are fine.

A file. Drop a file ending in .age on the page, or use Open a .age file. Small and large files both work: big ones are decrypted a chunk at a time, and the result keeps its original name, so report.pdf.age comes back as report.pdf.

When it won’t open

If the password is wrong, the page says so and keeps everything you entered, so you can try again; check capital letters, spaces and the separator between words. If the block was cut short or changed on the way, it reports it as damaged rather than showing half a message: ask the sender to send it again, ideally as a file.

Two kinds of age file don’t open here. One locked to an age key instead of a password (the page tells you) needs that key and the age app. And a file made with a very high scrypt work factor can ask for more memory than a browser tab is allowed; the age app opens those.

Try it with the example

The example on the Encrypt side is a real age file, made with the age command-line tool. Try unlocking it fills in the block and its password; press Decrypt to see the 42-character message it holds. It is the quickest way to see what a locked message looks like before you are sent one.

Good to know

Frequently Asked Questions

Can you decrypt something without the password?

No, and nobody else can either: that is the point. The password is stretched with scrypt into the key that unwraps the file’s own random key, and without it the content is noise. There is no back door, no reset and no recovery service.

Can this decrypt files from other encryption apps?

It opens anything in the age format that was locked with a password, from the age and rage command-line tools, this page, or other apps built on age. It doesn’t open ZIP, 7-Zip, PGP or BitLocker encryption, or messages scrambled with a classic cipher such as Caesar or Base64, which isn’t encryption at all.

Is what I decrypt saved anywhere?

No. The unlocked text or file exists only in this tab until you copy or download it. Clear wipes the page, and leaving it or closing the tab does the same. The locked link’s fragment never reaches a server, analytics included.

Why does unlocking take a second?

That pause is the password being stretched. scrypt makes each try cost about 256 MiB of memory and real time, on purpose, so that someone guessing passwords can try only a few a second instead of billions.