Your country

Tools that support it use your country for local currency, number formats, units and paper size. Your choice is saved only in this browser.

Type a name or a two-letter code. Use the up and down arrow keys to move through the countries, Enter to choose one and Escape to close.

Classic Cipher Toolkit

Nine historic ciphers for puzzles and teaching, with the tools to break them.

Text No upload Works offline Free, no sign-up

Runs in your browser; nothing is uploaded.

Cipher and key

Mode
Letters A–Z; spaces are ignored.

For puzzles and teaching. These ciphers were broken long ago and do not protect real secrets — this page cracks Vigenère and Affine in a second.

Next steps

About the Classic Cipher Toolkit

Encrypt and decrypt nine classical ciphers — Vigenère (with Autokey and Beaufort), Atbash, Affine, keyword substitution, Rail Fence, Playfair, Bacon, the Polybius square and A1Z26 — for puzzles, escape rooms, geocaches, treasure hunts and the classroom. Capitals, spaces and punctuation stay where they are, and the page shows how each result was made: the key stream, the cipher alphabet, the 5×5 square or the zigzag of the rails.

If you have a Vigenère or Affine ciphertext but not the key, choose Crack: the page shows the key-length evidence from Kasiski’s examination and the index of coincidence, works out each key letter by comparing letter counts with English, and lists the most likely keys, best first. A letter-frequency chart against English helps with every other cipher. None of these ciphers protects real secrets — that is exactly why they can be cracked here.

How to use it

  1. Choose the cipher, then Encrypt, Decrypt or (for Vigenère and Affine) Crack.
  2. Type or paste your text, or press Load example.
  3. Set the key: a keyword, numbers a and b, the number of rails, or a key for the square. The result updates as you type.
  4. Copy or download the result, or press Use as input to reverse it. When cracking, press Use next to any key to decrypt with it.

Examples

Vigenère
Input
ATTACKATDAWN, key LEMON
Result
LXFOPVEFRNHR
Autokey
Input
ATTACKATDAWN, key QUEENLY
Result
QNXEPVYTWTWP

The key is followed by the message itself, so the key never repeats.

Affine, a = 5 and b = 8
Input
AFFINE CIPHER
Result
IHHWVC SWFRCP
Keyword substitution, KRYPTOS
Input
KNOWLEDGEISPOWER
Result
DGHVETPSTBMIHVTL
Rail fence, 3 rails
Input
WE ARE DISCOVERED. RUN AT ONCE.
Result
WECRUOERDSOEERNTNEAIVDAC
Playfair, key “playfair example”
Input
Hide the gold in the tree stump
Result
BMODZBXDNABEKUDMUIXMMOUVIF

The doubled E of tree is split with an X before enciphering.

Bacon (24-letter alphabet)
Input
BACON
Result
AAAAB AAAAA AAABA ABBAB ABBAA
Polybius square and A1Z26
Input
Hello World
Result
23 15 31 31 34 / 52 34 42 31 14 · 8-5-12-12-15 23-15-18-12-4
Hebrew Atbash
Input
בבל (Babel)
Result
ששך (Sheshach, Jeremiah 25:26)

Common uses

  • Making and solving clues for escape rooms, scavenger hunts, geocaches and puzzle books.
  • Teaching how encryption works — and why these ciphers fail — in maths, computing and history lessons.
  • Checking homework and textbook exercises on classical ciphers and modular arithmetic.
  • Cracking a Vigenère or Affine message from a puzzle, game or CTF challenge.

How the ciphers work

  • Vigenère shifts each letter by the matching letter of a repeated key (A = 0 … Z = 25): c = (p + k) mod 26. Autokey continues the key with the message itself; Beaufort uses c = (k − p) mod 26, so the same step also decrypts.
  • Atbash swaps the alphabet end to end (A ↔ Z, B ↔ Y). It comes from Hebrew (א ↔ ת): Sheshach in Jeremiah 25:26 is Atbash for Babel.
  • Affine maps each letter x to (a·x + b) mod 26. a must share no factor with 26 (1, 3, 5, 7, 9, 11, 15, 17, 19, 21, 23 or 25), or two letters would become the same one.
  • Keyword substitution writes the keyword (without repeated letters) and then the rest of the alphabet under A–Z, or uses any 26-letter alphabet you give.
  • Rail fence writes the text in a zigzag over a number of rails and reads the rails one after another.
  • Playfair (Charles Wheatstone, 1854) enciphers pairs of letters on a 5×5 square made from the key, with I and J sharing a cell: letters in the same row become the letters to their right, in the same column the letters below, and otherwise the opposite corners of their rectangle.
  • Bacon (Francis Bacon, De Augmentis Scientiarum) writes each letter as five a/b symbols. In his 24-letter alphabet I = J and U = V. The a/b can also be hidden in an innocent text, here as small and capital letters.
  • Polybius square (described by the historian Polybius in the 2nd century BC) writes each letter as its row and column, and A1Z26 as its place in the alphabet.

How cracking works

Kasiski’s examination (F. W. Kasiski, 1863) looks for groups of letters that repeat in the ciphertext: when the same words meet the same part of the key, they encrypt the same way, so the distances between repeats are usually multiples of the key length.

The index of coincidence (W. F. Friedman, Riverbank Publication No. 22) is the chance that two letters picked from a text are the same. English letter frequencies give about 0.066 (1.70 × 1/26), random letters 1/26. The tool splits the ciphertext into columns for each key length from 1 to 20; at the right length every column is a simple shift of English and its index rises to the English level.

For each column, every shift is tried, and the one whose letters are the most likely in English — the highest log-likelihood with English letter frequencies (R. Lewand, Cryptological Mathematics) — gives that key letter. The keys of all lengths are then compared by minimum description length: the bits needed to write the whole decryption with those frequencies (about 4.2 per letter for English) plus log₂ 26 ≈ 4.7 bits for each key letter. A longer key always fits chance patterns a little better, but with enough ciphertext only the right length saves more bits than its extra letters cost, so an overfitted 20-letter guess does not beat a correct 5-letter key. The same likelihood ranks all 312 Affine keys.

Why these ciphers are not secure

Each of them keeps the patterns of the language underneath — letter frequencies, repeated words, word lengths — and has few enough keys to try them all or to work them out from those patterns, as this page does. Use them for games and teaching. To protect real information, use modern encryption such as AES, built into password managers, encrypted archives and messaging apps.

Limitations

  • Only the 26 letters A–Z are enciphered (and א–ת for Hebrew Atbash); letters with accents, digits and other scripts are copied unchanged. Polybius 6 × 6 also covers 0–9.
  • Cracking expects English. Vigenère needs more ciphertext for longer keys — as a rule of thumb about 25 letters per key letter (100 letters for a 4-letter key, 500 for a 20-letter key); with less, or a key longer than 20 letters, the best guess may be wrong, so check the list of keys and the decryption.
  • Crack mode covers the plain Vigenère and Affine ciphers. Autokey, Beaufort, Playfair and keyword substitution ciphertexts can be decrypted with their key, and the frequency chart helps solve substitutions by hand.
  • Playfair loses J (written as I) and adds fillers — X, or Q after an X; decrypted text keeps them unless you tick Remove filler X, which can also remove a real X that stands between two equal letters or at the end.
  • Bacon hidden in letter case needs five letters of cover text for each letter of the message, and five more when the message ends in A: those are written as a mark (bbaba) that tells the reader where the message stops, because the lower-case letters after it would otherwise read as more A’s.

Privacy

Everything happens in your browser. What you enter or open here is not uploaded or stored by MySmartCoPilot.

Frequently asked questions

How do I decode a Vigenère cipher without the key?

Choose Vigenère and Crack, then paste the ciphertext. The most likely key and its decryption appear at once, with other candidate keys below. With about 25 letters of ciphertext per key letter — a few hundred letters for most keys — the key is found reliably; for shorter texts, try the other keys in the list.

What is the key in a Playfair cipher?

A word or phrase. Its letters, without repeats and with J written as I, fill the 5 × 5 square first, followed by the rest of the alphabet. The square is shown under the result.

Why does my decrypted Playfair text contain extra X letters?

Playfair cannot encipher a pair of equal letters, so an X is put between them (tree → TR EX E…), and an X is added if the message has an odd number of letters. Tick Remove filler X to take them out.

What does A1Z26 mean?

A = 1, B = 2 … Z = 26: each letter is replaced by its place in the alphabet, with hyphens between the letters of a word. Hello is 8-5-12-12-15.

Can I use these ciphers to keep a message secret?

Only from someone who does not try. All of them can be broken with pencil and paper, and Vigenère and Affine are cracked by this page in a second. For real secrets use modern encryption such as AES.

Is my text sent anywhere?

No. Encryption, decryption and cracking all run in your browser, and nothing you type leaves your device.

Quick answers and tool search

Type to search tools or to get a quick answer, for example 18% of 2500. Use the up and down arrow keys to move through the results, Enter to choose, and Escape to close.