Private by design

Drop in a puzzle. Leave with an answer.

Runs on this device
Try a sample
What this browser solver can—and cannot—do

It tries: Caesar, Atbash, ROT13, affine, Trithemius, rail fence, single-byte XOR, periodic Vigenère-family ciphers, autokey, selected encoding layers (such as Base64, hex, binary, decimal ASCII, Morse, and reverse), and—only with 60+ A–Z letters—statistical substitution.

It does not: prove a decryption, cover every classical cipher, or break modern encryption such as AES or RSA. Its ranking model is tuned for English, so a high score is a lead to verify with the method, key, and source context—not a guarantee.

Short text, non-English plaintext, non-Latin or symbol alphabets, missing keys, and unsupported formats can all leave no high-confidence answer. When that happens, the result includes input-specific observations and suggested next checks; those observations are not a claim to know the exact cause.

No account. No upload. No stored text. The complete solver runs in your browser.

Why Vigenère resisted for 300 years

A Caesar cipher uses one shift for the whole message, so letter frequencies survive intact and betray it immediately. Vigenère uses a keyword: each letter of the keyword gives a shift, and the keyword repeats across the message. E no longer maps to a single letter, the frequency distribution flattens, and the technique that destroys Caesar simply stops working. It was called le chiffre indéchiffrable for a reason.

The crack: find the period first

The weakness is the repetition. If the key is four letters long, then every fourth letter of the ciphertext was encrypted with the same shift. Take positions 1, 5, 9, 13 and you have a pure Caesar cipher. The whole problem reduces to one question: how long is the key?

Index of coincidence

For each candidate length, the solver splits the ciphertext into that many cosets and measures the index of coincidence of each. When the guessed length matches the real one, every coset is monoalphabetic and its IC jumps toward the English value of 0.067. When the guess is wrong, the cosets stay mixed and the IC stays near random. The correct period announces itself.

Then solve each position

With the length known, each coset is attacked by chi-squared comparison against English letter frequencies, which gives a first guess at every key letter. That first guess is often one or two letters wrong on short texts, because a coset of twelve letters is a thin sample. So the solver runs a refinement pass: it re-picks each key letter by scoring the whole decryption with the trigram model, then a final pass that also counts real English words. That is what turns a nearly-right key into an exactly-right one.

Related ciphers

The same machinery handles the Beaufort and variant Beaufort ciphers, which differ only in the direction of the shift, and repeating-key XOR, which is Vigenère over bytes instead of letters and is extremely common in CTF challenges.

Frequently asked questions

Can a Vigenère cipher be broken without the key?

Yes. Because the key repeats, the ciphertext contains several interleaved Caesar ciphers. Find the key length and each of those can be solved independently by frequency analysis. This has been standard practice since Kasiski published the method in 1863.

How much ciphertext do I need?

As a rough rule you want at least 20 letters per key character, so a six-letter key wants 120 letters or more. Shorter texts leave each position with too few samples for the statistics to be reliable, though the trigram refinement pass on this page recovers many borderline cases.

What if the key is as long as the message?

Then it is a one-time pad and it is genuinely unbreakable, provided the key is random and never reused. No tool can help. In practice puzzle keys are short repeating words.

Why did it return a key that is a repeated word, like LAMPLAMP?

Any multiple of the true key length fits the ciphertext just as well. The solver penalises longer keys to prefer the shortest explanation, but on short texts a doubled key occasionally wins. The plaintext is still correct.

This tool is free and has no account, no upload, no tracking of your text

Everything runs in your browser. If it saved you time, keeping it alive costs nothing but a click.