pgp decrypt
someone sent you a block starting with -----BEGIN PGP MESSAGE-----? unlock it here - with your private key and its passphrase, or with just the shared password if the sender used one. when javascript runs, everything stays in your browser - your key never leaves this page.
privacy note
this tool has two paths. with javascript enabled (preferred), decryption happens entirely in your browser - the plaintext, your key and the passphrase never leave your device, which is what you want for sensitive content. with javascript blocked, the same button submits this form and decryption runs on our server instead: everything is processed in memory for that one request, then discarded - nothing is logged or stored - but the plaintext does cross the network to reach us. if that ever bothers you, enable javascript. the server path also only supports rsa keys and password-locked messages.
faq
- is my private key uploaded?
- not when javascript is on: everything runs inside your browser tab - open dev tools and watch the network panel stay quiet when you click decrypt. when javascript is off, the browser-mode can't work, so the form posts to the server and we decrypt there, in memory, keeping nothing - but the message, key and passphrase do travel to us. that server fallback only handles rsa keys and password-locked messages; modern curve25519/ed25519 keys need javascript.
- "wrong passphrase" but i'm sure it's right?
- check trailing whitespace when pasting, caps lock, and keyboard layout changes. passphrases are case sensitive down to every character.
- i get "message is not for me" or "session key decryption failed"
- the message was encrypted to a different public key than the private key you pasted. make sure you use the key pair the sender actually encrypted to.
- it says the message is signed - what does that mean?
- a signature inside proves who wrote it (if their key checks out). copy the plaintext over to the verify tool together with the sender's public key to confirm.
- i only have a password, not a private key
- then the message was password-encrypted (symmetric). just paste the message and type that shared password into the passphrase field - leave the private key box empty.