PGP Encrypt / Decrypt
OpenPGP encryption, decryption, signatures and key details — nothing leaves your device.
Encrypted message
Decrypted
About the PGP Encrypt / Decrypt
Use OpenPGP — the standard behind PGP and GnuPG — without installing anything. Encrypt a message or a file to one or more people’s public keys, optionally signed with your own key; decrypt messages and .gpg files with your private key and passphrase (or the password of a gpg --symmetric message) and see whether the signature is good; and inspect any key to check its fingerprint, user IDs, subkeys, algorithms and expiry.
Everything runs in your browser with OpenPGP.js in a background worker: keys, passphrases and messages never leave your device, and the page keeps working offline once loaded. Tested with GnuPG 2.5.22: messages encrypted here decrypt in GnuPG with a good signature, and GnuPG’s messages — including its newer OCB-encrypted ones — decrypt here (the automated tests use messages made by GnuPG).
How to use it
- Encrypt: paste the recipients’ public keys (or load their key files) and check the names and fingerprints that appear. Type the message or choose a file, tick Sign to add your own key if you want, then press Encrypt and copy or download the result.
- Decrypt: paste the message (“-----BEGIN PGP MESSAGE-----”) or open the .gpg/.asc file, paste your private key and enter its passphrase — or the password, for messages encrypted with one — and press Decrypt.
- To check who signed a message, add the sender’s public key under Sender’s public key before decrypting: the result says whether the signature is good.
- Inspect a key: paste a key or load a key file to see its fingerprint, key IDs, user IDs, subkeys, algorithms, expiry and whether it is valid, expired or revoked.
Examples
Recipient: Ravi’s public key · message “The contract is attached.” · Sign with your key
-----BEGIN PGP MESSAGE----- wV4D… -----END PGP MESSAGE-----
Only Ravi’s private key can decrypt it; his software also shows that you signed it. Check the fingerprint the page shows against the one Ravi gave you — that is what guarantees it is really his key.
report.pdf.gpg + your private key and passphrase
Download report.pdf (the name stored in the message)
The message, and the password the sender told you
The decrypted text — no key needed
Common uses
- Exchanging confidential messages or documents with people who use PGP or GnuPG, from any device.
- Reading a PGP message or .gpg file on a computer where GnuPG is not installed.
- Checking that a signed message or release note really comes from the expected key.
- Looking up a key’s fingerprint and expiry before trusting it, or finding out which of your keys a message is encrypted for.
How OpenPGP encryption works
Each message gets a random session key; the content is encrypted with it (AES), and the session key is encrypted to every recipient’s public key — so each recipient decrypts with their own private key, and you can add your own public key to be able to read what you sent. A signature is made with the sender’s private key and checked with their public key: “good” means the message was signed with that key and not changed since. What makes it trustworthy is the fingerprint — compare it with the one the person gave you in person, by phone or on their website.
Compatibility
The page follows RFC 9580 and reads RFC 4880 data. Tested with GnuPG 2.5.22:
- messages and files encrypted and signed here decrypt in GnuPG with “Good signature”;
- GnuPG’s signed-and-encrypted messages decrypt here and their signatures verify — including the LibrePGP OCB packets GnuPG 2.5.22 wrote for a key it created itself;
gpg --symmetricmessages decrypt here with the password.
RFC 9580 v6 keys work here but not in GnuPG. Old messages without integrity protection are refused, because a changed message could not be detected.
Open-source software used
Encryption, decryption and key parsing use OpenPGP.js 6.3.2 (openpgpjs.org), which is licensed under the GNU Lesser General Public License v3.0 or later. It is loaded as its own, unmodified file — licence header included — and runs in a background worker; its source code is available from the link above.
Limitations
- Files up to 128 MB: they are encrypted and decrypted in memory. For larger files use GnuPG on your computer.
- Detached signatures (.sig) and cleartext-signed messages (“BEGIN PGP SIGNED MESSAGE”) are not checked here; this tool handles encrypted messages and their signatures.
- Keys are not fetched from key servers or Web Key Directories (nothing leaves your device): paste or load each key yourself.
- Smartcards and security keys (such as YubiKey) cannot be used; the private key has to be pasted or loaded as a file.
- Messages encrypted with obsolete methods without integrity protection (from very old PGP versions) are refused on purpose.
Privacy
Keys, passphrases, messages and files are processed only by OpenPGP.js in a background worker in this tab. Nothing is uploaded, logged or stored. Only your choice of output format is remembered on this device.
Frequently asked questions
Is it safe to paste my private key into a web page?
On this page the key stays in your browser: it is never uploaded or stored, and the page works offline. Still, a private key is precious — prefer your own computer and browser, close the tab afterwards, and keep the key protected with a strong passphrase.
Why does decryption say the message is for a different key?
The page lists the key IDs the message was encrypted to and compares them with your private key’s IDs. If they do not match, the sender used another of your keys (or someone else’s). Use the matching private key, or ask the sender to encrypt to your current public key.
What does “Good signature” mean — and why did it say “Not signed”?
“Good signature” means the message was signed with the private key belonging to the public key you added, and nothing changed afterwards. “Not signed” means the sender did not sign: anyone who has your public key could have written it. “Signed by key ID …” means it is signed, but you have not added that sender’s public key to check it.
Can GnuPG users read messages I encrypt here?
Yes. Messages encrypted here use the standard OpenPGP format; in our tests GnuPG 2.5.22 decrypted them and verified their signatures. Use v4 keys (the default of the PGP Key Generator) for people who use GnuPG.