RC4 Encrypt / Decrypt
Classic RC4 for legacy interoperability — computed locally, verified against the standard test vectors, and honestly labeled obsolete.
Legacy warning: RC4 is cryptographically broken and banned by all modern standards — use only to talk to old systems.
Privacy: everything runs in your browser; keys and text never leave this page.
How to use
- Enter the text; the key can be 1–256 characters — leave it empty and Encrypt generates a random 128-bit key for you (Show reveals it).
- Encrypt to get hex ciphertext; paste it back with the same key and Decrypt to reverse.
- For anything new, use AES-GCM instead — RC4 is compatibility-only.
Frequently asked questions
Why does this page warn me that RC4 is insecure?
RC4 is broken: its keystream is biased, and attacks on WEP, WPA-TKIP and TLS demonstrated practical breaks years ago. All standards have banned it. This tool is here for one reason — old file formats, protocols and systems still demand RC4 — not for protecting anything new.
What should I use instead?
AES-GCM, as implemented by every modern browser and platform. See the AES tool on this site: it authenticates your data and uses keys properly. Use RC4 only when the other side of the conversation gives you no choice.
Why do I have to keep the same key to decrypt?
RC4 is a stream cipher: the key expands into a keystream that is XORed with the text. Encryption and decryption are the identical operation, so both sides need the exact same key — and reusing a key across messages is one of the classic RC4 pitfalls.
Why does decryption fail with the wrong key?
A wrong key produces a wrong keystream, so the result is random bytes rather than text. The tool checks that the output is valid UTF-8 and refuses to show you noise.
Is my key or text uploaded?
No. RC4 runs locally in your browser; the key and message never leave the page.