Tooleux

ChaCha20 Encrypt

ChaCha20 (2)

Encrypt text with ChaCha20-Poly1305 or XChaCha20-Poly1305 using a password.

Runs in your browser. Nothing leaves your device.
Encrypt text with ChaCha20-Poly1305 or XChaCha20-Poly1305 in your browser. Free, offline. Read more Show less

What is ChaCha20-Poly1305?

ChaCha20-Poly1305 is an authenticated encryption with associated data (AEAD) cipher standardized in RFC 8439. It combines the ChaCha20 stream cipher with the Poly1305 message authentication code, so it protects both confidentiality and integrity in a single pass.

It was designed by Daniel J. Bernstein as a software-friendly alternative to AES. On devices without AES hardware acceleration - older phones, some IoT, many servers - ChaCha20 is significantly faster than AES. It is used by TLS 1.3, WireGuard, SSH, and Chrome's HTTPS stack.

It is not a password hash and does not replace key derivation. This tool derives a 256-bit key from your password with PBKDF2 (SHA-256, 100,000 iterations) plus a random 16-byte salt, so the same password produces a different key every time.

ChaCha20-Poly1305 vs XChaCha20-Poly1305

The standard variant uses a 12-byte nonce. It is safe if you never reuse a nonce with the same key. The extended variant, XChaCha20-Poly1305, uses a 24-byte nonce, which is large enough that you can safely generate it at random for every message without coordinating with other senders.

If you are encrypting messages between different parties who share a key, prefer XChaCha20-Poly1305. If you are matching a protocol that specifies ChaCha20-Poly1305 (TLS, WireGuard, SSH), choose that.

How to use

Enter your plaintext, enter a password, choose the variant, then press Encrypt. The output is a single Base64 string that contains everything needed to decrypt: the random salt, the random nonce, the ciphertext, and the authentication tag. Copy it, paste it into ChaCha20 Decrypt, and enter the same password.

Anyone who has the ciphertext but not the password cannot read the message. Anyone who modifies the ciphertext by even one bit will produce an authentication failure - the tool will refuse to decrypt it.

FAQ

Is ChaCha20 secure?

Yes. ChaCha20-Poly1305 has no practical attacks. It is one of two cipher suites mandated by TLS 1.3 (the other is AES-GCM).

Should I use a password or a raw key?

This tool takes a password and derives a 256-bit key with PBKDF2. If you have a raw 256-bit key from a key exchange (for example, from X25519 or HKDF), use a lower-level tool - ChaCha20 expects a uniformly random key, not a human password.

Why PBKDF2 and not Argon2?

PBKDF2 is universally available and adequate for interactive use. For long-term storage of user passwords, use Argon2id via the Argon2 tool instead.

Is the output format compatible with other tools?

No. The format base64(salt + nonce + ciphertext + tag) is specific to this site so that encrypt and decrypt round-trip cleanly. To interoperate with other software, use the raw primitives from a library like @noble/ciphers, libsodium, or OpenSSL.

Command line equivalent
# Node with @noble/ciphers
npm i @noble/ciphers
node --input-type=module -e '
import { chacha20poly1305, xchacha20poly1305 } from "@noble/ciphers/chacha";
const key = new Uint8Array(32);          // 256-bit key
const nonce = new Uint8Array(12);        // 12 for ChaCha, 24 for XChaCha
const c = chacha20poly1305(key, nonce);
const ct = c.encrypt(new TextEncoder().encode("hello"));
console.log(Buffer.from(ct).toString("base64"));
'

# OpenSSL 3
echo -n "hello" | openssl enc -chacha20-poly1305 -K <64-hex> -iv <24-hex> -base64
Loads a test value into the form
Plaintext
Ciphertext