Encrypt Text with a Password
Type or paste a message, choose a password, and get back a block of locked text or a link to send in any chat. Only someone with the password can read it, and the message never leaves your browser.
A locked message
This is what one looks like.
-----BEGIN AGE ENCRYPTED FILE----- YWdlLWVuY3J5cHRpb24ub3JnL3YxCi0+IHNjcnlwdCBvdnlrTGlYUmtCaCtXV0pR RUdsWEpBIDE4CkJLVWtDZmxqOFQ5VVluUFdEVGpSanRERkZRaGRHT2dBcUVqakw5 YmMzaHMKLS0tIGN3TzBySW13NXdsOGlkenhnYU5OUnVpVGZlL0E3QXBHd2Q1UUdP MzlLdmsKxvSP5aQgEvXG2WMVZDdV8NCGe+QiUVcu5oLSGx2QTSI+mwZGPlKfHRoY tQD/Q6Qe6LytmIq6H9J1/scUYke8JbJKTyYydNEru9E= -----END AGE ENCRYPTED FILE-----
Made with the age app; it opens here too.
How this works: Method, 5 sources, Checked against 1 worked example,
How this works
Method
Everything runs in your browser, in the open age format (v1) through typage, the official TypeScript age implementation. Your password is stretched with scrypt (N = 2^18, r = 8, p = 1, the age default) into a key that wraps a random 128-bit file key; the content is encrypted with ChaCha20-Poly1305 in 64 KiB chunks, so any change is detected. Files made here open with `age -d`; the tests use files made by the age command-line tool and the C2SP age test vectors.
Sources
How it’s tested
One worked example for this page is checked by automated tests before every release: given the inputs, the tool must show the expected answer.
Changes
- Pages for each job: encrypt text, encrypt a file, decrypt, and what age is, each opening the tool on that job.
- First published: text, photos and files, as a block, a file or a link, in the age format.
How to send a secret message
Type the message in the box, or paste it from wherever it lives: a Wi-Fi password for a guest, a door code, bank details for a relative, a note you want to keep but not leave lying around in plain text. Then pick a password. Suggest gives you five random words, which are easy to read out over the phone and slow to guess.
Press Encrypt (or Ctrl and Enter). The answer card offers three ways to send it: Copy link, Copy as text, or Download .age. A link is the easiest for the other person, because opening it lands them on the Decrypt side with the message already loaded; all they type is the password.
Send the password a different way from the message. If the link goes by email, say the password on a call or send it in another app. Anyone who gets both can read the message, so keeping them apart is what makes this worth doing.
Locked text or a link?
Copy as text gives a block that starts with -----BEGIN AGE ENCRYPTED FILE-----: the locked bytes written as base64 between two marker lines, a layout borrowed from the PEM format that keys and certificates use. It survives email, chat, notes apps and paper, and the age app on any computer can open it.
Copy link puts the same bytes after #age= at the end of a link to this tool. That part of a web address, the fragment, is handled only by the browser that opens it and is not sent to the server, so the locked message never reaches this site even when someone opens the link. Links are offered up to 32,000 characters, short enough that chat apps and email keep them whole; longer messages are shared as a block or a file instead.
Why the locked text is longer than your message
Locking adds a fixed amount. The example on this page, made with the age command-line tool, holds a 42-character message in 224 bytes: a 150-byte header that says how the key was wrapped (the scrypt salt and work factor and a check value), then a 16-byte random nonce, the text itself, and a 16-byte tag that detects any change. Written as base64 with its marker lines, that becomes a 373-character block. A long letter grows by about a third, because base64 spends four characters on every three bytes.
Good to know
- The fragment of a web address, the part after #, is dereferenced only by the browser (the user agent), never sent as part of the request. Source: RFC 3986: Uniform Resource Identifier (URI), §3.5 Fragment
- Text-armored age files use the strict PEM encoding with the label AGE ENCRYPTED FILE. Source: The age file format, v1
Frequently Asked Questions
Is it safe to encrypt text on a website?
Only if the text never reaches the website, which is the case here: the encryption runs in your browser, in a background worker of this page, and nothing you type is saved or sent. Your browser’s developer tools (the Network tab) show what a page sends, and your message is in none of it. A site that sends your text to its server to encrypt it could read it, whatever it promises.
Can the person I send it to open it on a phone?
Yes. A link opens this page on any phone browser, already on the Decrypt side; they type the password and read the message. A copied block works the same way: they paste it into the Decrypt box. No app or account is needed.
How is this different from an end-to-end encrypted chat?
An encrypted chat app protects messages between its own apps, and the chat history stays on both phones. A locked message protects the text itself, wherever you paste it: email, a shared document, a ticket, a note. It is useful when the channel isn’t encrypted, or when you want something to stay locked after it arrives.
Can I lock a message for myself, as a private note?
Yes. Lock it with a password you will remember, then keep the block in your notes or email. It opens here, or with age on a computer, whenever you need it. If you forget the password the note is gone for good: there is no reset.