Classic Cipher Toolkit
Nine historic ciphers for puzzles and teaching, with the tools to break them.
Runs in your browser; nothing is uploaded.
Cipher and key
Atbash is its own inverse: the same step encrypts and decrypts.
For puzzles and teaching. These ciphers were broken long ago and do not protect real secrets — this page cracks Vigenère and Affine in a second.
Cracking the cipher
Most likely keys
| Key | Bits per letter | Decryption begins | Action |
|---|
Key length
Average index of coincidence of the columns for each key length (English ≈ 1.70 × 1/26, random letters 1.00), and how many Kasiski distances each length divides.
| Length | IoC × 26 | Kasiski |
|---|
Repeated sequences (Kasiski)
How it was enciphered
Letter frequencies
Show the numbers
| Letter | Count | Your text | English |
|---|
About the Classic Cipher Toolkit
Encrypt and decrypt nine classical ciphers — Vigenère (with Autokey and Beaufort), Atbash, Affine, keyword substitution, Rail Fence, Playfair, Bacon, the Polybius square and A1Z26 — for puzzles, escape rooms, geocaches, treasure hunts and the classroom. Capitals, spaces and punctuation stay where they are, and the page shows how each result was made: the key stream, the cipher alphabet, the 5×5 square or the zigzag of the rails.
If you have a Vigenère or Affine ciphertext but not the key, choose Crack: the page shows the key-length evidence from Kasiski’s examination and the index of coincidence, works out each key letter by comparing letter counts with English, and lists the most likely keys, best first. A letter-frequency chart against English helps with every other cipher. None of these ciphers protects real secrets — that is exactly why they can be cracked here.
How to use it
- Choose the cipher, then Encrypt, Decrypt or (for Vigenère and Affine) Crack.
- Type or paste your text, or press Load example.
- Set the key: a keyword, numbers a and b, the number of rails, or a key for the square. The result updates as you type.
- Copy or download the result, or press Use as input to reverse it. When cracking, press Use next to any key to decrypt with it.
Examples
ATTACKATDAWN, key LEMON
LXFOPVEFRNHR
ATTACKATDAWN, key QUEENLY
QNXEPVYTWTWP
The key is followed by the message itself, so the key never repeats.
AFFINE CIPHER
IHHWVC SWFRCP
KNOWLEDGEISPOWER
DGHVETPSTBMIHVTL
WE ARE DISCOVERED. RUN AT ONCE.
WECRUOERDSOEERNTNEAIVDAC
Hide the gold in the tree stump
BMODZBXDNABEKUDMUIXMMOUVIF
The doubled E of tree is split with an X before enciphering.
BACON
AAAAB AAAAA AAABA ABBAB ABBAA
Hello World
23 15 31 31 34 / 52 34 42 31 14 · 8-5-12-12-15 23-15-18-12-4
בבל (Babel)
ששך (Sheshach, Jeremiah 25:26)
Common uses
- Making and solving clues for escape rooms, scavenger hunts, geocaches and puzzle books.
- Teaching how encryption works — and why these ciphers fail — in maths, computing and history lessons.
- Checking homework and textbook exercises on classical ciphers and modular arithmetic.
- Cracking a Vigenère or Affine message from a puzzle, game or CTF challenge.
How the ciphers work
- Vigenère shifts each letter by the matching letter of a repeated key (A = 0 … Z = 25): c = (p + k) mod 26. Autokey continues the key with the message itself; Beaufort uses c = (k − p) mod 26, so the same step also decrypts.
- Atbash swaps the alphabet end to end (A ↔ Z, B ↔ Y). It comes from Hebrew (א ↔ ת): Sheshach in Jeremiah 25:26 is Atbash for Babel.
- Affine maps each letter x to (a·x + b) mod 26. a must share no factor with 26 (1, 3, 5, 7, 9, 11, 15, 17, 19, 21, 23 or 25), or two letters would become the same one.
- Keyword substitution writes the keyword (without repeated letters) and then the rest of the alphabet under A–Z, or uses any 26-letter alphabet you give.
- Rail fence writes the text in a zigzag over a number of rails and reads the rails one after another.
- Playfair (Charles Wheatstone, 1854) enciphers pairs of letters on a 5×5 square made from the key, with I and J sharing a cell: letters in the same row become the letters to their right, in the same column the letters below, and otherwise the opposite corners of their rectangle.
- Bacon (Francis Bacon, De Augmentis Scientiarum) writes each letter as five a/b symbols. In his 24-letter alphabet I = J and U = V. The a/b can also be hidden in an innocent text, here as small and capital letters.
- Polybius square (described by the historian Polybius in the 2nd century BC) writes each letter as its row and column, and A1Z26 as its place in the alphabet.
How cracking works
Kasiski’s examination (F. W. Kasiski, 1863) looks for groups of letters that repeat in the ciphertext: when the same words meet the same part of the key, they encrypt the same way, so the distances between repeats are usually multiples of the key length.
The index of coincidence (W. F. Friedman, Riverbank Publication No. 22) is the chance that two letters picked from a text are the same. English letter frequencies give about 0.066 (1.70 × 1/26), random letters 1/26. The tool splits the ciphertext into columns for each key length from 1 to 20; at the right length every column is a simple shift of English and its index rises to the English level.
For each column, every shift is tried, and the one whose letters are the most likely in English — the highest log-likelihood with English letter frequencies (R. Lewand, Cryptological Mathematics) — gives that key letter. The keys of all lengths are then compared by minimum description length: the bits needed to write the whole decryption with those frequencies (about 4.2 per letter for English) plus log₂ 26 ≈ 4.7 bits for each key letter. A longer key always fits chance patterns a little better, but with enough ciphertext only the right length saves more bits than its extra letters cost, so an overfitted 20-letter guess does not beat a correct 5-letter key. The same likelihood ranks all 312 Affine keys.
Why these ciphers are not secure
Each of them keeps the patterns of the language underneath — letter frequencies, repeated words, word lengths — and has few enough keys to try them all or to work them out from those patterns, as this page does. Use them for games and teaching. To protect real information, use modern encryption such as AES, built into password managers, encrypted archives and messaging apps.
Limitations
- Only the 26 letters A–Z are enciphered (and א–ת for Hebrew Atbash); letters with accents, digits and other scripts are copied unchanged. Polybius 6 × 6 also covers 0–9.
- Cracking expects English. Vigenère needs more ciphertext for longer keys — as a rule of thumb about 25 letters per key letter (100 letters for a 4-letter key, 500 for a 20-letter key); with less, or a key longer than 20 letters, the best guess may be wrong, so check the list of keys and the decryption.
- Crack mode covers the plain Vigenère and Affine ciphers. Autokey, Beaufort, Playfair and keyword substitution ciphertexts can be decrypted with their key, and the frequency chart helps solve substitutions by hand.
- Playfair loses J (written as I) and adds fillers — X, or Q after an X; decrypted text keeps them unless you tick Remove filler X, which can also remove a real X that stands between two equal letters or at the end.
- Bacon hidden in letter case needs five letters of cover text for each letter of the message, and five more when the message ends in A: those are written as a mark (bbaba) that tells the reader where the message stops, because the lower-case letters after it would otherwise read as more A’s.
Privacy
Everything happens in your browser. What you enter or open here is not uploaded or stored by MySmartCoPilot.
Frequently asked questions
How do I decode a Vigenère cipher without the key?
Choose Vigenère and Crack, then paste the ciphertext. The most likely key and its decryption appear at once, with other candidate keys below. With about 25 letters of ciphertext per key letter — a few hundred letters for most keys — the key is found reliably; for shorter texts, try the other keys in the list.
What is the key in a Playfair cipher?
A word or phrase. Its letters, without repeats and with J written as I, fill the 5 × 5 square first, followed by the rest of the alphabet. The square is shown under the result.
Why does my decrypted Playfair text contain extra X letters?
Playfair cannot encipher a pair of equal letters, so an X is put between them (tree → TR EX E…), and an X is added if the message has an odd number of letters. Tick Remove filler X to take them out.
What does A1Z26 mean?
A = 1, B = 2 … Z = 26: each letter is replaced by its place in the alphabet, with hyphens between the letters of a word. Hello is 8-5-12-12-15.
Can I use these ciphers to keep a message secret?
Only from someone who does not try. All of them can be broken with pencil and paper, and Vigenère and Affine are cracked by this page in a second. For real secrets use modern encryption such as AES.
Is my text sent anywhere?
No. Encryption, decryption and cracking all run in your browser, and nothing you type leaves your device.