Rabbit cipher

Encrypt or decrypt text with the Rabbit stream cipher (RFC 4503) — 128-bit key, optional 64-bit IV, text or encoded keys, hex or base64. Runs in your browser; nothing is uploaded.

Result

About this tool

Rabbit cipher encrypts and decrypts text with the Rabbit stream cipher (RFC 4503), one of the four software-portfolio finalists of the eSTREAM project. You supply a 128-bit key, an optional 64-bit IV, and pick the encoding — handy for interoperating with other Rabbit implementations, solving CTFs, testing against the spec, or learning how modern stream ciphers work.

About Rabbit

Rabbit is a fast, high-throughput stream cipher designed by Cryptico and published as RFC 4503. Its internal state combines eight 32-bit state variables and eight 32-bit counters driven by a counter-carry system; each iteration produces a 128-bit keystream block that is XORed with the data. This tool validates against the official RFC 4503 test vectors. As with any stream cipher, never reuse the same key + IV pair for two different messages.

Privacy

Everything runs in your browser via WebAssembly — your key and data never leave the device. Also available from the gizza CLI and in chat.

FAQ

Why must the key be exactly 16 characters (or 32 hex digits)?

Rabbit is defined over a fixed 128-bit key, so the tool needs exactly 16 bytes — either a 16-character text passphrase, or, with the key format set to encoded, 32 hex or 24 base64 characters. Shorter or longer keys are rejected rather than silently padded, because padding would break interop with other RFC 4503 implementations.

Do I have to use an IV?

No — the IV is optional, but when you give one it must be exactly 8 bytes (64 bits) and identical on encrypt and decrypt. The IV is what lets you reuse one key safely: the same key with a different IV yields a completely different keystream. Never encrypt two different messages with the same key + IV pair.

Decrypting with the wrong key gave gibberish instead of an error — why?

Because Rabbit is a plain XOR stream cipher with no built-in authentication: any 16-byte key produces some keystream, so a wrong key, wrong IV, or wrong encoding yields garbled output rather than a failure. If you need tamper detection, add a MAC (e.g. the hmac-generate tool) over the ciphertext.

Will the output match other Rabbit implementations and the RFC test vectors?

Yes. Keys and IVs are read most-significant-byte first, exactly as the hex strings are written in RFC 4503, and the implementation is validated against the official test vectors — so a hex key/IV pair from the spec or another conforming library produces identical ciphertext here.

Developer & Automation Access

Run it from the terminal

Same engine as this page, headless — via the gizza CLI:

gizza tool rabbit-cipher "Text to encrypt…" 'key=16-char passphrase, or encoded key'

New to the CLI? Get gizza →

Open it by URL

Pre-fill and auto-run this tool with query parameters — the names match the API/CLI:

https://gizza.ai/tools/rabbit-cipher/?data=Text%20to%20encrypt%E2%80%A6&operation=encrypt&key=16-char%20passphrase%2C%20or%20encoded%20key&iv=leave%20empty%20for%20no%20IV&key_format=text&format=hex

Machine-readable descriptor: tool.json — title + parameters JSON Schema for agents.