Age encrypt
Create copy-pasteable age ciphertext locally from plaintext, a passphrase, or age1 recipient keys.
About this tool
Encrypt small text snippets into an ASCII-armored age file. The output starts with
-----BEGIN AGE ENCRYPTED FILE-----, so it can be copied into chat, tickets, or a
terminal and later decrypted by compatible age clients.
Use passphrase mode when the recipient already knows a shared secret. Use
recipients mode when you have one or more native age X25519 public keys beginning
with age1. Recipient mode accepts keys on separate lines, spaces, commas, or
semicolons, and ignores # comments in pasted recipient files.
Example passphrase run:
- Paste
Deploy key rotates at 17:00 UTC.as the plaintext. - Leave mode set to
passphrase. - Enter a strong passphrase and keep the work factor at
14. - Copy the armored age ciphertext from the result.
Limits and edge cases: this page encrypts text up to 1 MiB. Passphrase work factor is capped at 15 because higher scrypt settings exceed the wasm memory sandbox. The tool does not decrypt, generate identities, encrypt files, or accept SSH recipients; use the age CLI for those workflows.
FAQ
Can I decrypt the result on this page?
No. This tool only encrypts plaintext to age ciphertext. Decrypt with a compatible
age client using the same passphrase or a matching AGE-SECRET-KEY-1... identity.
What kind of recipient key does this accept?
Recipient mode accepts native age X25519 public recipients that start with
age1. It rejects private identities and SSH public keys so they are not pasted
into the wrong field by mistake.
Why is the work factor limited to 15?
The work factor controls scrypt memory use in passphrase mode. Higher values can be useful on a desktop age CLI, but they exceed the memory available to this wasm tool. The range 10-15 keeps encryption and later decryption practical here.
Why does the same input produce different ciphertext each time?
Age encryption uses fresh randomness for every file. Different ciphertext for the same plaintext and passphrase is expected and prevents repeated messages from looking identical.
Developer & Automation Access
Run it from the terminal
Same engine as this page, headless — via the gizza CLI:
gizza tool age-encrypt "Paste the message to encrypt" 'passphrase=Use a strong passphrase'New to the CLI? Get gizza →
Open it by URL
Pre-fill and auto-run this tool with query parameters — the names match the API/CLI:
https://gizza.ai/tools/age-encrypt/?text=Paste%20the%20message%20to%20encrypt&mode=passphrase&passphrase=Use%20a%20strong%20passphrase&recipients=age1...%20%28one%20per%20line%2C%20comma%2C%20or%20space%20separated%29&work_factor=14Machine-readable descriptor: tool.json — title + parameters JSON Schema for agents.
