GOST Magma cipher

Encrypt or decrypt text with the GOST 28147-89 / GOST R 34.12-2015 Magma 64-bit block cipher — ECB or CBC, 256-bit key, hex or base64. Runs in your browser; nothing is uploaded.

Result

About this tool

GOST Magma cipher is a low-level encrypt/decrypt tool for the GOST 28147-89 / GOST R 34.12-2015 "Magma" block cipher (also specified in RFC 8891), the legacy 64-bit Russian standard symmetric cipher. You supply the raw key and IV, pick the mode, and get the result — handy for implementing or testing against the standard, debugging interop, or learning how the cipher works.

Privacy

Everything runs in your browser via WebAssembly — your key and data never leave the device. Also available from the gizza CLI and in chat.

Not sure which tool you want?

If you just want to protect a message with a passphrase (and have the salt, key derivation and nonce handled safely for you), use the text-encrypt tool instead — gost-magma-cipher is for when you already have a specific raw key, IV and mode. For the newer 128-bit GOST cipher, see gost-kuznyechik-cipher.

FAQ

What key and IV sizes does Magma require?

The key is always 32 bytes (256 bits) — Magma has no other key size. CBC mode additionally needs an 8-byte IV (one 64-bit block); ECB takes no IV at all. Supply both in the encoding you selected (hex or base64) — a 64-character hex string or 44-character base64 string for the key.

Why won't my ciphertext decrypt?

Magma-CBC/ECB has no built-in authentication, so a wrong key, wrong IV, wrong mode, or a hex/base64 mix-up usually surfaces as a PKCS7 padding error (or as mojibake if the padding happens to parse). Double-check that all four settings match the ones used to encrypt, including the encoding of the key and IV.

Which S-box does this implementation use?

The standard id-tc26-gost-28147-param-Z substitution set — the one fixed by GOST R 34.12-2015 and RFC 8891. If you're interoperating with an old GOST 28147-89 system that used a different regional S-box, the outputs will not match.

Is ECB mode safe to use?

No — ECB encrypts every 8-byte block independently, so repeated plaintext blocks produce repeated ciphertext blocks and patterns leak. It's included for testing and interop against the standard only; use CBC with a random IV (or a modern AEAD cipher) for anything real.

Developer & Automation Access

Run it from the terminal

Same engine as this page, headless — via the gizza CLI:

gizza tool gost-magma-cipher "Text to encrypt…" 'key=base64 or hex key'

New to the CLI? Get gizza →

Open it by URL

Pre-fill and auto-run this tool with query parameters — the names match the API/CLI:

https://gizza.ai/tools/gost-magma-cipher/?data=Text%20to%20encrypt%E2%80%A6&operation=encrypt&cipher=cbc&key=base64%20or%20hex%20key&iv=base64%20or%20hex%20iv&format=base64

Machine-readable descriptor: tool.json — title + parameters JSON Schema for agents.