XXTEA Decrypt
Decrypt XXTEA ciphertext produced by XXTEA Encrypt.
Decrypt XXTEA (Corrected Block TEA) ciphertext in your browser. Free, offline, runs client-side. Read more Show less
What is XXTEA decryption?
XXTEA decryption reverses the encryption performed by XXTEA Encrypt. It reads a single Base64 (or hex) string containing the random salt and the ciphertext, derives the 128-bit XXTEA key from your password with PBKDF2-SHA-256, and decrypts.
XXTEA is a legacy cipher included for interoperability. See the encrypt page for the full discussion of trust and alternatives.
How to use
Paste the Base64 or hex ciphertext, enter the same password that was used to encrypt it, and press Decrypt. The output is the original plaintext.
Why does decryption fail?
Three common causes:
Wrong password. XXTEA has no authentication tag, so a wrong key may produce garbage plaintext rather than an error. This tool makes a plausibility check on the length word and reports an error if the decrypted data claims a length larger than the ciphertext.
Wrong ciphertext format. Base64 and hex produce different byte sequences from the same string.
Byte-order mismatch. Some XXTEA implementations use big-endian byte order. This tool uses little-endian, matching the reference C implementation by the original authors.
FAQ
Can I tell if the password is correct?
Not with XXTEA alone. It has no integrity check. If the output looks like readable text, the password is probably right. If it looks like random characters, the password is wrong - or the plaintext was binary.
Does the byte order matter?
Yes. XXTEA has multiple byte-order conventions in the wild. This tool uses little-endian, the NSA reference. Ciphertext from a big-endian implementation will not decrypt correctly.
Can I decrypt OpenSSL or GnuPG output?
No. Neither OpenSSL nor GnuPG supports XXTEA. This tool only decrypts data produced by XXTEA Encrypt on this site, or by another implementation using the same byte order and key derivation.
Is it safe to paste ciphertext into a browser tool?
This tool runs entirely client-side. Nothing is uploaded. Verify by opening your browser's Network tab and confirming no requests are sent after page load.
What is the maximum input size?
No hard limit. XXTEA on a modern browser runs at a few megabytes per second. Very large inputs (over 100 MB) may freeze the tab briefly.
Command line equivalent
# Python with xxtea
python3 -c '
import xxtea, base64
key = b"0123456789abcdef"
ct = base64.b64decode("BASE64_CIPHERTEXT")
print(xxtea.decrypt(ct, key).decode())
'
# Node with xxtea npm package
node -e '
const xxtea = require("xxtea");
console.log(xxtea.decryptToString("BASE64_CIPHERTEXT", "0123456789abcdef"));
'