Your country

Tools that support it use your country for local currency, number formats, units and paper size. Your choice is saved only in this browser.

Type a name or a two-letter code. Use the up and down arrow keys to move through the countries, Enter to choose one and Escape to close.

Vigenère Cipher Encoder & Decoder

Encrypt with a keyword, decrypt, or let Kasiski and Friedman find a lost key.

Security No upload Works offline Free, no sign-up

Nothing you type leaves your browser.

Key and cipher

Capitals and spaces do not matter; the key starts over when it runs out.

Cipher

Encrypted text

Type a message and a key.

Classical ciphers are for puzzles and learning: they do not protect real secrets. For those, use modern encryption such as the AES tool.

Next steps

About the Vigenère Cipher Encoder & Decoder

The Vigenère cipher encrypts a message with a keyword instead of a single shift. Each letter moves along the alphabet by the matching letter of the key: with the key LEMON, the first letter moves by L (11 places), the second by E (4), and so on, and after N the key starts over. One plain letter can therefore come out as several different cipher letters, which flattens the letter counts that give away a simple substitution, and the cipher was long considered unbreakable.

This page encrypts and decrypts with the Vigenère cipher, with its reciprocal cousin the Beaufort cipher, with variant Beaufort, and with an autokey that continues the key with the message itself. Use the normal A–Z alphabet, A–Z with digits, or your own alphabet, including a keyed one as on the Kryptos sculpture. If you have a ciphertext but no key, Find the key takes it apart the way Kasiski and Friedman did: repeated groups of letters and the index of coincidence suggest the key length, and letter counts in each column give away the key letters, step by step.

How to use it

  1. Choose Encrypt, Decrypt or Find the key, then type or paste your text. Try an example fills in a working message and key.
  2. To encrypt or decrypt, enter the key: a word or phrase. Capitals and spaces do not matter, and the key starts over when it runs out.
  3. Choose the cipher (Vigenère, Beaufort or Variant Beaufort) and tick Autokey if the key should continue with the message. Under the key you can change the alphabet, for digits, another language or a keyed alphabet, and how the result is laid out.
  4. Read the result, with the key written over the first letters of the message. The arrow buttons under it walk through the letters one at a time and show the sum and where it lands in the square of alphabets. Copy or download the result, or press Use as input to turn it back.
  5. To find a lost key, choose Find the key and paste the ciphertext. Read how the key length is found, check each key letter column by column (press an alternative letter to try it) and press Decrypt with this key.

Examples

Vigenère with the key LEMON
Input
Attack at dawn
Result
Lxfopv ef rnhr

A (0) + L (11) = 11 = L, T (19) + E (4) = 23 = X, and T (19) + M (12) = 31, which wraps round to 5 = F. The key moves on only at letters, so the spaces do not use up key letters.

Beaufort with the key RECIPROCAL
Input
C equals K minus P
Result
P amopgw S odekk T

Beaufort computes C = K − P, so the message describes its own cipher. Running the same step on the result gives the message back. This is the example in the American Cryptogram Association’s description of the cipher.

Autokey with the key KILT
Input
Meet at the fountain
Result
Wmpm mx xae yhbryoca

The key is KILT and then the message itself: KILTMEETATTHEFOUN. Turn on Autokey to reproduce it.

Kryptos K1: keyed alphabet KRYPTOS, key PALIMPSEST
Input
BETWEEN SUBTLE SHADING AND THE ABSENCE OF LIGHT LIES THE NUANCE OF IQLUSION
Result
EMUFPHZ LRFAXY USDJKZL DKR NSH GNFIVJY QT QUXQB QVYU VLL TREVJY QT MKYRDMFD

Choose the alphabet Keyed A–Z, from a word…, type KRYPTOS, and use the key PALIMPSEST. This is the first passage of the Kryptos sculpture; its last word, IQLUSION, is said to be an intentional misspelling of ILLUSION.

Find the key of a ciphertext
Input
Uhjt coties mouot sjnpri. Fadi lkxues pf zlf mftsgkf it nobie ampnm xie bmpneceu cy zlf anputx hiwfn hc uhf oedx meuuex sg a lfycssd, …
Result
Key length 7, key BABBAGE: “This cipher looks simple. Each letter of the message is moved along the alphabet by the amount given by the next letter of a keyword, …”

Choose Find the key and press Try an example to load the whole message. The average index of coincidence of the columns jumps from about 0.046 to 0.074 at length 7. The word keyword comes up again 385 letters after its first appearance, a multiple of 7, so both copies are enciphered the same way and the ciphertext repeats the group LFYCSSD at that distance.

Common uses

  • Solving puzzles, escape-room clues, geocaches, alternate-reality games and capture-the-flag challenges that use a keyword cipher, including the passages of the Kryptos sculpture.
  • Teaching and learning how a polyalphabetic cipher hides letter frequencies and how Kasiski and Friedman defeat it, with every step visible.
  • Checking homework on modular arithmetic, the Vigenère square and classical cryptanalysis.
  • Writing secret notes and clues for treasure hunts and games, with any alphabet you like.

How the cipher works

Number the letters from 0: A = 0, B = 1 … Z = 25. To encrypt, add the number of the key letter to the number of the plain letter and wrap round after Z: C = (P + K) mod 26. With the key LEMON under ATTACKATDAWN, A (0) + L (11) = 11 = L, T (19) + E (4) = 23 = X, and T (19) + M (12) = 31, which wraps round to 5 = F. To decrypt, subtract: P = (C − K) mod 26. The key is repeated as often as needed and moves on only at letters, so spaces and punctuation do not use up key letters.

The same sum can be read off a square of 26 alphabets, each shifted one place further than the one above (the tabula recta): the plain letter picks the column, the key letter picks the row, and the cell holds the cipher letter. Open The square of alphabets under the result to see where each step lands.

  • Vigenère: C = P + K.
  • Beaufort: C = K − P. The step is its own inverse, so the same operation encrypts and decrypts.
  • Variant Beaufort: C = P − K, the Vigenère cipher run backwards. For the same message the two need mirrored keys: each letter k of a Vigenère key becomes 26 − k in the variant Beaufort key (A stays A), so the Vigenère key BABBAGE matches the variant Beaufort key ZAZZAUW.
  • Autokey: the key is used once and the message itself then continues it. With the key QUEENLY, ATTACKATDAWN is enciphered with the key letters QUEENLYATTAC. Decrypting recovers the plain letters one at a time and uses them as the next key letters.

The formulas follow the American Cryptogram Association’s descriptions of the Vigenère, Beaufort, Variant and Autokey ciphers.

How Find the key works

1. How long is the key? Three signs are compared for every length from 1 to 30.

  • Repeats (Kasiski’s examination). If the same word meets the same part of the key twice, it is enciphered the same way twice, so a group of three or more letters that repeats in the ciphertext is usually a multiple of the key length apart. The tool lists the repeats, the distances between them and the lengths that divide those distances, and compares each length with chance: a length L divides about 1 in L of random distances, so only a count well above that points to it.
  • The index of coincidence. This is the chance that two letters picked from a text are the same, Σ f(f − 1) ÷ N(N − 1). English gives about 0.067 and uniformly random letters 1/26 ≈ 0.0385. Write the ciphertext in L columns: when L is the key length, or a multiple of it, every column is an ordinary English text with its letters shifted, so its index rises to about 0.067; for other lengths it stays near the flat value. Friedman’s formula (0.0667 − 0.0385) ÷ (IC − 0.0385) also turns the index of the whole text into a rough key length. It is a guide, not a result, and unreliable for short texts.
  • The fit of the best key. For every length the tool finds the best key (see step 2) and counts the bits needed to write the whole decryption with English letter frequencies. A longer key always fits a little better, simply by fitting chance, so every key letter is charged log₂ 26 ≈ 4.7 bits and the length with the lowest total wins.

A length is marked clear only when the gap to the next different key is wide, the columns look like English, the fit is far better than for random letters with the same number of key letters, and it passes the shuffle test. The shuffle test renames the 26 letters of the ciphertext at random (every A becomes some other letter, and so on): the counts stay as uneven as before, but any pattern of shifted alphabets is gone. A real Vigenère ciphertext fits many standard deviations better than its renamed copies; a simple substitution cipher, whose counts look like English without being a shift, looks the same renamed and scores about 0: in our trials of 2,500 such texts none was marked clear and only 2 were marked likely. Likely and unsure are the weaker cases. In our own trials on English prose, with random keys of 2 to 15 letters and texts of 50 to 2,500 letters, results marked clear had the right key length in at least 99 of 100 cases and the exact key in at least 94 of 100. When the ciphertext is Beaufort rather than Vigenère, the fit is poor for every length and, if there is enough text, the page says that Beaufort fits better.

2. What is each key letter? With the length known, each column is a Caesar cipher, so counting letters solves it. For each of the 26 possible key letters the tool decrypts the column and asks how many bits it would take to write the result with the letter frequencies of English (Robert Lewand, Cryptological Mathematics): common letters cost few bits and rare ones many. The key letter with the fewest bits wins, and the gap to the runner-up tells you how sure it is: 8 bits or more is odds of 256 to 1.

A short history

The scheme was first described in 1553 by Giovan Battista Bellaso, who added a repeating keyword to Johannes Trithemius’s square of alphabets. In the 19th century it was wrongly credited to Blaise de Vigenère, whose own cipher of 1586 was an autokey. It was long considered unbreakable and was known as le chiffre indéchiffrable, the indecipherable cipher. Charles Babbage is known to have broken a variant of it as early as 1854 without publishing his work; in 1863 Friedrich Kasiski was the first to publish a general method, in his book Die Geheimschriften und die Dechiffrir-Kunst; and William Friedman’s index of coincidence, published in 1922 as The Index of Coincidence and Its Applications in Cryptography, put the attack on a statistical footing.

Sources: Vigenère cipher, Kasiski examination, index of coincidence, autokey cipher and Kryptos.

Keyed alphabets and Kryptos

A keyed alphabet puts a word first and the remaining letters after it: KRYPTOS gives KRYPTOSABCDEFGHIJLMNQUVWXZ. The Kryptos sculpture at the headquarters of the CIA has a Vigenère table built on that alphabet, and its first two passages (K1 and K2) are Vigenère ciphers with the keys PALIMPSEST and ABSCISSA. Choose Keyed A–Z, from a word… and type KRYPTOS: the plain letters, the key letters and the cipher letters are all taken in that alphabet, which reproduces K1 and the opening of K2. The alphabet can also be any list of characters you type, such as A–Z followed by 0–9 or the letters of another script, each character once.

Why it is not secure, and what to use instead

With enough text the Vigenère cipher falls to the steps above in a fraction of a second, which is what Find the key shows. A key that is as long as the message, random and never reused (a one-time pad) cannot be solved by counting letters, but it only moves the problem to sharing a key as long as the message. For anything that matters, use modern encryption such as AES.

Limitations

  • Only characters of the chosen alphabet are enciphered; spaces, punctuation and everything else are copied unchanged, and the key moves on only at enciphered characters. A puzzle that also moves the key on at spaces will not match.
  • Find the key works on the letters A–Z of English text with a repeating key of up to 30 letters. It needs roughly 30 letters of ciphertext per key letter to be reliable (about 150 for a 5-letter key): with less, it shows the most likely key and the alternatives for every letter, and the decryption may be partly wrong. Other languages written with A–Z often work too, because their common letters are similar: in our trials, ciphertexts of 300 to 1,500 letters with keys of 3 to 10 letters in German, Spanish, French, Italian, Dutch, Portuguese, Swedish, Danish and Norwegian (accents left out) nearly always came out clear with the right key length, while Croatian, whose letter frequencies are further from English, mostly came out unsure. The frequencies it compares with are English.
  • An autokey has no repeating key, so Kasiski’s examination and the index of coincidence do not apply, and Find the key cannot solve an autokey ciphertext. It decrypts one when you know the key.
  • A general substitution cipher, the kind in newspaper cryptograms where each letter stands for another fixed letter in no particular order, is not a shift and not a repeating key, and Find the key does not solve it. It tells you when the letter counts look like one alphabet, so that you do not go on looking for a key.
  • Find the key ignores a chosen alphabet: it reads only the letters A–Z of the text. Ciphertexts made with a keyed alphabet, digits or another script are not solved by it.
  • A text of more than 20,000 letters is analysed on its first 20,000 letters; the whole text is still decrypted with the key found.
  • Some sources define Beaufort with a reversed table, as C = 51 − K − P on Wikipedia’s Beaufort cipher page. That is this Beaufort cipher with every key letter mirrored (A ↔ Z, B ↔ Y … M ↔ N); the tool follows the American Cryptogram Association’s C = K − P.

Privacy

Everything happens in your browser. What you enter or open here is not uploaded or stored by MySmartCoPilot.

Frequently asked questions

How do I decode a Vigenère cipher without the key?

Choose Find the key, paste the ciphertext and press Try an example first if you want to see it work. The page estimates the key length from repeated groups of letters and from the index of coincidence, works out each key letter from letter counts, and decrypts with the result. A few hundred letters of English are usually enough for a key of up to about ten letters; the page tells you how sure it is.

What is the key of a Vigenère cipher?

A word or phrase whose letters say how far to shift each letter of the message. The letter A shifts by 0, B by 1 and so on up to Z, 25. A key of a single letter is a Caesar shift, and a key made only of the letter A changes nothing.

What is the difference between Vigenère, Beaufort and variant Beaufort?

They differ only in the sum. Vigenère adds the key letter to the plain letter (C = P + K), Beaufort subtracts the plain letter from the key letter (C = K − P) and variant Beaufort subtracts the key letter from the plain letter (C = P − K). Beaufort is its own inverse; the other two are each other’s inverse.

What is an autokey cipher?

A Vigenère cipher whose key is used once and then continued with the message itself, so the key never repeats. Blaise de Vigenère described it in 1586. Because there is no repeating key, Kasiski’s examination and the index of coincidence do not find it; attackers instead guess common words and see what key they imply.

Does the key move on at spaces and punctuation?

No. Only characters of the alphabet are enciphered and only they use up key letters, so the same message gives the same ciphertext whatever its spacing. Spaces and punctuation are copied as they are, and Result layout can remove them or group the letters in fives.

Can I use digits, accents or another alphabet?

Yes. Under the key, choose A–Z then 0–9, or Custom alphabet… and type the characters in the order you want, each once: for example the letters of Greek or Cyrillic. Characters outside the alphabet are copied unchanged. In an alphabet that mixes letters and digits, a capital letter that is enciphered to a digit loses its case, because digits have none.

Can I use a sentence, or a passage from a book, as the key?

Yes. The key can have up to 5,000 characters, and spaces and punctuation in it are ignored. A key as long as the message never repeats, which is called a running-key cipher; it is harder to break than a short keyword, but it is not secure either, because both the message and the key are ordinary text. Find the key looks for a repeating key, so it does not solve a running key.

My cipher is a cryptogram where every letter stands for another letter. Will Find the key solve it?

No. A cryptogram is a simple substitution: each letter is always replaced by the same other letter, in no particular order. It is not a Vigenère cipher and it has no key to find. Find the key notices it, because the counts of the whole text are as uneven as in ordinary writing (a Vigenère cipher evens them out) and yet no shift fits, and it says so instead of inventing a key. Such ciphers are solved by matching the most frequent letters to E, T and A and then guessing words. The Caesar cipher tool solves the special case where the alphabet is only shifted.

How much ciphertext do I need to find the key?

About 30 letters for every key letter to be safe: roughly 150 letters for a 5-letter key and 300 for a 10-letter key. With fewer, the key length is often still right but some key letters are uncertain, and the page marks which ones and offers the next best letter for each.

What do bits, “clear”, “likely” and “uncertain” mean?

The page measures how English a column looks by the bits needed to write it with English letter frequencies; fewer bits is more English. The gap between the best key letter and the runner-up is the evidence: 4 bits is odds of 16 to 1, 8 bits is 256 to 1. A letter is clear at 8 bits or more, likely at 4 to 8 and uncertain below 4, when you should try the alternatives and read the decryption.

Where can I find other classical ciphers?

The Caesar cipher tool shifts every letter by the same amount and cracks an unknown shift, ROT13 is the shift of 13, and the Classic Cipher Toolkit covers Playfair, Atbash, Affine, Rail Fence, Bacon, Polybius and more. A Vigenère key of one letter is a Caesar shift.

Is the Vigenère cipher secure?

No. It has been breakable by hand since the 19th century and this page does it in a fraction of a second. It is good for puzzles and for learning how cryptanalysis works. For real secrets use modern encryption such as AES.

Is my text sent anywhere?

No. Encrypting, decrypting and finding the key all run in your browser. The text, the key and the alphabet are not stored, not even in this browser; only your choice of mode, cipher, autokey, alphabet type and layout is remembered.

Quick answers and tool search

Type to search tools or to get a quick answer, for example 18% of 2500. Use the up and down arrow keys to move through the results, Enter to choose, and Escape to close.