Your country

Tools that support it use your country for local currency, number formats, units and paper size. Your choice is saved only in this browser.

Type a name or a two-letter code. Use the up and down arrow keys to move through the countries, Enter to choose one and Escape to close.

PGP Encrypt / Decrypt

OpenPGP encryption, decryption, signatures and key details — nothing leaves your device.

Security No upload Works offline Free, no sign-up

Encrypt

Paste one or more public keys, or load .asc / .gpg key files.
    What to encrypt

    Next steps

    About the PGP Encrypt / Decrypt

    Use OpenPGP — the standard behind PGP and GnuPG — without installing anything. Encrypt a message or a file to one or more people’s public keys, optionally signed with your own key; decrypt messages and .gpg files with your private key and passphrase (or the password of a gpg --symmetric message) and see whether the signature is good; and inspect any key to check its fingerprint, user IDs, subkeys, algorithms and expiry.

    Everything runs in your browser with OpenPGP.js in a background worker: keys, passphrases and messages never leave your device, and the page keeps working offline once loaded. Tested with GnuPG 2.5.22: messages encrypted here decrypt in GnuPG with a good signature, and GnuPG’s messages — including its newer OCB-encrypted ones — decrypt here (the automated tests use messages made by GnuPG).

    How to use it

    1. Encrypt: paste the recipients’ public keys (or load their key files) and check the names and fingerprints that appear. Type the message or choose a file, tick Sign to add your own key if you want, then press Encrypt and copy or download the result.
    2. Decrypt: paste the message (“-----BEGIN PGP MESSAGE-----”) or open the .gpg/.asc file, paste your private key and enter its passphrase — or the password, for messages encrypted with one — and press Decrypt.
    3. To check who signed a message, add the sender’s public key under Sender’s public key before decrypting: the result says whether the signature is good.
    4. Inspect a key: paste a key or load a key file to see its fingerprint, key IDs, user IDs, subkeys, algorithms, expiry and whether it is valid, expired or revoked.

    Examples

    Sending an encrypted note
    Input
    Recipient: Ravi’s public key · message “The contract is attached.” · Sign with your key
    Result
    -----BEGIN PGP MESSAGE-----
    
    wV4D…
    -----END PGP MESSAGE-----

    Only Ravi’s private key can decrypt it; his software also shows that you signed it. Check the fingerprint the page shows against the one Ravi gave you — that is what guarantees it is really his key.

    Opening a .gpg file someone sent you
    Input
    report.pdf.gpg + your private key and passphrase
    Result
    Download report.pdf (the name stored in the message)
    A message encrypted with gpg --symmetric
    Input
    The message, and the password the sender told you
    Result
    The decrypted text — no key needed

    Common uses

    • Exchanging confidential messages or documents with people who use PGP or GnuPG, from any device.
    • Reading a PGP message or .gpg file on a computer where GnuPG is not installed.
    • Checking that a signed message or release note really comes from the expected key.
    • Looking up a key’s fingerprint and expiry before trusting it, or finding out which of your keys a message is encrypted for.

    How OpenPGP encryption works

    Each message gets a random session key; the content is encrypted with it (AES), and the session key is encrypted to every recipient’s public key — so each recipient decrypts with their own private key, and you can add your own public key to be able to read what you sent. A signature is made with the sender’s private key and checked with their public key: “good” means the message was signed with that key and not changed since. What makes it trustworthy is the fingerprint — compare it with the one the person gave you in person, by phone or on their website.

    Compatibility

    The page follows RFC 9580 and reads RFC 4880 data. Tested with GnuPG 2.5.22:

    • messages and files encrypted and signed here decrypt in GnuPG with “Good signature”;
    • GnuPG’s signed-and-encrypted messages decrypt here and their signatures verify — including the LibrePGP OCB packets GnuPG 2.5.22 wrote for a key it created itself;
    • gpg --symmetric messages decrypt here with the password.

    RFC 9580 v6 keys work here but not in GnuPG. Old messages without integrity protection are refused, because a changed message could not be detected.

    Open-source software used

    Encryption, decryption and key parsing use OpenPGP.js 6.3.2 (openpgpjs.org), which is licensed under the GNU Lesser General Public License v3.0 or later. It is loaded as its own, unmodified file — licence header included — and runs in a background worker; its source code is available from the link above.

    Limitations

    • Files up to 128 MB: they are encrypted and decrypted in memory. For larger files use GnuPG on your computer.
    • Detached signatures (.sig) and cleartext-signed messages (“BEGIN PGP SIGNED MESSAGE”) are not checked here; this tool handles encrypted messages and their signatures.
    • Keys are not fetched from key servers or Web Key Directories (nothing leaves your device): paste or load each key yourself.
    • Smartcards and security keys (such as YubiKey) cannot be used; the private key has to be pasted or loaded as a file.
    • Messages encrypted with obsolete methods without integrity protection (from very old PGP versions) are refused on purpose.

    Privacy

    Keys, passphrases, messages and files are processed only by OpenPGP.js in a background worker in this tab. Nothing is uploaded, logged or stored. Only your choice of output format is remembered on this device.

    Frequently asked questions

    Is it safe to paste my private key into a web page?

    On this page the key stays in your browser: it is never uploaded or stored, and the page works offline. Still, a private key is precious — prefer your own computer and browser, close the tab afterwards, and keep the key protected with a strong passphrase.

    Why does decryption say the message is for a different key?

    The page lists the key IDs the message was encrypted to and compares them with your private key’s IDs. If they do not match, the sender used another of your keys (or someone else’s). Use the matching private key, or ask the sender to encrypt to your current public key.

    What does “Good signature” mean — and why did it say “Not signed”?

    “Good signature” means the message was signed with the private key belonging to the public key you added, and nothing changed afterwards. “Not signed” means the sender did not sign: anyone who has your public key could have written it. “Signed by key ID …” means it is signed, but you have not added that sender’s public key to check it.

    Can GnuPG users read messages I encrypt here?

    Yes. Messages encrypted here use the standard OpenPGP format; in our tests GnuPG 2.5.22 decrypted them and verified their signatures. Use v4 keys (the default of the PGP Key Generator) for people who use GnuPG.

    What is the difference between this and the password-based encryption tools?

    PGP encrypts to a person’s public key, so no password has to be shared, and signatures prove who sent a message. The text and file encryption tools use a shared password instead — simpler when the other person has no PGP key.

    Quick answers and tool search

    Type to search tools or to get a quick answer, for example 18% of 2500. Use the up and down arrow keys to move through the results, Enter to choose, and Escape to close.