RC4 cipher

Encrypt or decrypt text with RC4 — optional drop-N (RC4-drop), text or encoded keys, hex or base64. Runs in your browser; nothing is uploaded.

Result

About this tool

RC4 cipher encrypts and decrypts text with the classic RC4 stream cipher (also known as ARCFOUR). You supply the key, optionally a drop-N, and pick the encoding — handy for interoperating with legacy systems, solving CTFs, testing against a spec, or learning how stream ciphers work.

Security warning

RC4 is cryptographically broken — practical attacks recover plaintext, and it is banned from TLS. Do not use it to protect real secrets. This tool exists for interop, CTFs, legacy data and education only. For real encryption use the aes-cipher or text-encrypt tools instead.

Privacy

Everything runs in your browser via WebAssembly — your key and data never leave the device. Also available from the gizza CLI and in chat.

FAQ

Why does decrypting give me garbage instead of an error?

RC4 is a plain XOR stream cipher with no built-in integrity check, so any key "works" — a wrong key, a mismatched drop-N, or the wrong hex/base64 setting just XORs with the wrong keystream and yields mojibake. All three settings must match the ones used to encrypt exactly.

What does drop-N do, and what value should I use?

RC4's first keystream bytes are statistically biased, which enabled real attacks. RC4-drop[n] discards the first n bytes before encrypting; the conventional values are 768 or 3072. It must be identical on encrypt and decrypt — a message encrypted with drop 768 will not decrypt with drop 0. The default is 0 (plain RC4) for compatibility with legacy systems.

How do I enter a binary key?

Switch the key format from text to encoded: the key is then decoded from hex or base64 (whichever encoding you selected for the ciphertext) instead of being taken as a UTF-8 passphrase. Keys can be 1–256 bytes, per the RC4 spec.

Is RC4 safe to use for real data?

No. RC4 is cryptographically broken — practical attacks recover plaintext, and it has been banned from TLS since 2015. Use this tool for interop with legacy systems, CTFs, and learning; encrypt anything that matters with the aes-cipher or text-encrypt tools instead.

Developer & Automation Access

Run it from the terminal

Same engine as this page, headless — via the gizza CLI:

gizza tool rc4-cipher "Text to encrypt…" 'key=passphrase, or encoded key'

New to the CLI? Get gizza →

Open it by URL

Pre-fill and auto-run this tool with query parameters — the names match the API/CLI:

https://gizza.ai/tools/rc4-cipher/?data=Text%20to%20encrypt%E2%80%A6&operation=encrypt&key=passphrase%2C%20or%20encoded%20key&key_format=text&drop=0&format=hex

Machine-readable descriptor: tool.json — title + parameters JSON Schema for agents.