Tooleux

Decrypt RSA-OAEP ciphertext with a private key (PKCS#8 PEM).

Runs in your browser. Nothing leaves your device.
Decrypt text with an RSA private key (RSA-OAEP SHA-256) in your browser. Free, offline, runs entirely client-side. Read more Show less

What is RSA decryption?

RSA decryption reverses the encryption performed with an RSA public key. Only the holder of the matching private key can decrypt a message that was encrypted with the public key. This is the asymmetry that makes RSA useful: anyone can encrypt, only one party can read.

This tool uses RSA-OAEP with SHA-256, matching the RSA Encrypt tool. If your ciphertext was created with PKCS#1 v1.5 padding, use a native library instead.

How to use

Paste the private key in PEM format (PKCS#8, BEGIN PRIVATE KEY), paste the Base64 or hex ciphertext, and press Decrypt. The plaintext appears in the output box.

If the ciphertext or the padding is invalid, decryption fails. OAEP padding is strict - even a single bit flip in the ciphertext produces a completely different result.

Why does the key need to be PKCS#8?

The Web Crypto API only accepts private keys in PKCS#8 format (BEGIN PRIVATE KEY). Older PEM files use PKCS#1 (BEGIN RSA PRIVATE KEY) and cannot be used directly. Convert with:

openssl pkcs8 -topk8 -nocrypt -in pkcs1.pem -out pkcs8.pem

Or generate a fresh PKCS#8 key with the RSA Key Generator.

FAQ

Is my private key uploaded?

No. The key is used only in your browser through the Web Crypto API. It is never sent anywhere.

What if decryption fails?

Three common causes: (1) the wrong private key; (2) the ciphertext was encrypted with PKCS#1 v1.5 instead of OAEP; (3) the ciphertext was altered during copy-paste. Check the encryption scheme first - mismatched padding is the most common cause.

Can I decrypt data from another tool?

Only if that tool used RSA-OAEP with SHA-256 and Base64 or hex output. Otherwise use a native library that supports the specific padding.

Why does my ciphertext look different every time I encrypt the same message?

OAEP uses a random seed during padding. The same plaintext produces a different ciphertext on every encryption. That is correct and desirable - it prevents an attacker from learning anything by comparing ciphertexts.

Does the key size matter for decryption?

No, as long as the key matches. A 2048-bit key decrypts data that was encrypted with a 2048-bit public key. Longer keys take proportionally longer to decrypt.

Command line equivalent
# OpenSSL
echo "BASE64_CIPHERTEXT" | base64 -d | openssl pkeyutl -decrypt -inkey private.pem -pkeyopt rsa_padding_mode:oaep -pkeyopt rsa_oaep_md:sha256

# Python with cryptography
python3 -c '
from cryptography.hazmat.primitives.asymmetric import padding
from cryptography.hazmat.primitives import hashes, serialization
import base64
priv = serialization.load_pem_private_key(open("private.pem","rb").read(), password=None)
ct = base64.b64decode("BASE64_CIPHERTEXT")
pt = priv.decrypt(ct, padding.OAEP(mgf=padding.MGF1(hashes.SHA256()), algorithm=hashes.SHA256(), label=None))
print(pt.decode())
'
Loads a test value into the form
Ciphertext
Plaintext