Tooleux

RC4 Decrypt

RC4 (2)

Decrypt RC4 ciphertext. Legacy compatibility only.

Runs in your browser. Nothing leaves your device.
Decrypt RC4 ciphertext in your browser. Legacy compatibility only - RC4 is broken. Free, offline, runs entirely client-side. Read more Show less

What is RC4 decryption?

RC4 is symmetric - encrypting and decrypting are the same operation. This page takes ciphertext in (Base64 or hex), applies the RC4 keystream generated from your key, and produces the original plaintext.

RC4 is broken. It was deprecated by RFC 7465 in 2015 and banned from TLS 1.3. This tool exists for legacy data only. Never use RC4 for new systems.

How to use

Paste the ciphertext, enter the same key that was used to encrypt it, choose the matching ciphertext format (Base64 or hex), and press Decrypt. Output updates live.

The result is displayed as text if it decodes to valid UTF-8, otherwise as hex so you can inspect the raw bytes.

Why does decryption produce garbage?

Four common reasons:

Wrong key. RC4 has no integrity check - it will happily produce output with any key. If the key is wrong, the plaintext is random bytes.

Wrong ciphertext format. Base64 and hex are different; parsing the wrong way produces the wrong byte sequence.

Truncated ciphertext. RC4 is a stream cipher. Losing bytes at the end loses the corresponding plaintext.

The ciphertext was not produced by RC4. Some tools use RC4-drop (discard first N bytes). This tool uses standard RC4 without dropping.

FAQ

Can I tell if the key is correct?

Not by the cipher alone. RC4 has no integrity check. If the output is readable text, the key is probably right. If it looks like random characters, the key is wrong - or the data was binary to begin with.

Does this tool recover the key from ciphertext?

No. RC4 is not key-recoverable from ciphertext in any practical sense. Cryptanalysis of RC4 relies on statistical biases across many ciphertexts encrypted with the same key, and is not something a browser tool can do.

What is the maximum input size?

No limit built in, but for very large inputs the browser becomes slow. RC4 is fast - a few hundred megabytes per second even in JavaScript.

Is my key uploaded?

No. Everything runs in your browser. The key never leaves your device.

Command line equivalent
# Python
python3 -c '
from Crypto.Cipher import ARC4
import base64
key = bytes.fromhex("00112233445566778899aabbccddeeff")
ct = base64.b64decode("BASE64_CIPHERTEXT")
c = ARC4.new(key)
print(c.decrypt(ct).decode())
'

# Node with rc4 npm package
node -e '
const RC4 = require("rc4");
const c = new RC4("mykey");
console.log(c.update(Buffer.from("BASE64", "base64").toString("binary")));
'
Loads a test value into the form
Ciphertext
Plaintext