you are on the clearnet. the addresses listed here only open inside the tor network - download the tor browser here »
AlphaBay.Market
last update: 15 min ago 255 onions tracked
home / tools / pgp decrypt

pgp decrypt

someone sent you a block starting with -----BEGIN PGP MESSAGE-----? unlock it here - with your private key and its passphrase, or with just the shared password if the sender used one. when javascript runs, everything stays in your browser - your key never leaves this page.

1

paste the encrypted message

2

unlock with your private key

a public key cannot decrypt anything - it must say PRIVATE KEY BLOCK. need one? make a pair in the key generator. password-encrypted message instead? leave this empty and just fill in the passphrase below.

wrong passphrase is the #1 failure: watch caps lock, keyboard layout and trailing spaces when pasting. if the sender locked the message with a shared password instead of your key, type that password here and leave the key box empty.

3

read it

where should this run?

privacy note

this tool has two paths. with javascript enabled (preferred), decryption happens entirely in your browser - the plaintext, your key and the passphrase never leave your device, which is what you want for sensitive content. with javascript blocked, the same button submits this form and decryption runs on our server instead: everything is processed in memory for that one request, then discarded - nothing is logged or stored - but the plaintext does cross the network to reach us. if that ever bothers you, enable javascript. the server path also only supports rsa keys and password-locked messages.

faq

is my private key uploaded?
not when javascript is on: everything runs inside your browser tab - open dev tools and watch the network panel stay quiet when you click decrypt. when javascript is off, the browser-mode can't work, so the form posts to the server and we decrypt there, in memory, keeping nothing - but the message, key and passphrase do travel to us. that server fallback only handles rsa keys and password-locked messages; modern curve25519/ed25519 keys need javascript.
"wrong passphrase" but i'm sure it's right?
check trailing whitespace when pasting, caps lock, and keyboard layout changes. passphrases are case sensitive down to every character.
i get "message is not for me" or "session key decryption failed"
the message was encrypted to a different public key than the private key you pasted. make sure you use the key pair the sender actually encrypted to.
it says the message is signed - what does that mean?
a signature inside proves who wrote it (if their key checks out). copy the plaintext over to the verify tool together with the sender's public key to confirm.
i only have a password, not a private key
then the message was password-encrypted (symmetric). just paste the message and type that shared password into the passphrase field - leave the private key box empty.