CipherLayer Browse
All computation happens in your browser. Nothing is uploaded.

A cryptography workshop,
not a toy encoder.

35 working tools covering modern algorithms (AES-GCM, RSA-OAEP, ECDSA, Shamir secret sharing) and historical ciphers with real attack analysis (frequency analysis, Kasiski examination, Enigma simulation). Every tool runs against the Web Crypto API — when it says AES-GCM, it really is AES-GCM, not a renamed XOR.

# Quick sanity check — these values are real outputs:
// AES-GCM-256, key from passphrase "correct horse battery staple"
IV: 9c1f4a2b8d3e7f5a...
CT: 7a4f8c2d9e1b3a5f...
Tag: b2e7d4a9c3f81a6e...
// Frequency analysis on Caesar cipher
Top score: shift = 3 (English chi² = 245.7)
Recovered: "the quick brown fox jumps over the lazy dog"

Most online "encryption tools" are toys

They rename base64 as "encryption". They use ECB mode and call it AES. They show you a green checkmark even when the math is broken. We don't.

Real attacks, not just textbook descriptions

The Caesar tool actually runs chi-squared scoring against English. The Vigenère tool runs Kasiski examination and index of coincidence. The Enigma tool models rotors, reflectors, and plugboards — not a lookup table.

Browser-native, network-free

Every algorithm runs in your browser via the Web Crypto API or self-contained JavaScript. Open DevTools — you'll see no fetch requests to our servers. There are no servers.

Eight categories, 35 tools

Click any tool to open its dedicated page. Each page explains what the tool solves, who it's for, how to read the output, and where the math breaks down.

Modern Symmetric

AES in real authenticated modes.

5 tools

Asymmetric & Signatures

RSA, ECDSA, ECDH — with key generation.

5 tools

Hashing & KDF

SHA family, HMAC, PBKDF2, HKDF.

5 tools

Secret Sharing

Shamir, threshold reconstruction.

3 tools

Classical Ciphers

Caesar, Vigenère, Playfair, Enigma…

8 tools

Encodings

Base64/32/58, Hex, Morse, Braille.

5 tools

Steganography

Zero-width chars, homoglyphs, LSB.

3 tools

Analysis & Forensics

JWT, X.509, traffic pattern checks.

1 tool

All 35 tools

Every tool opens in a dedicated page with usage notes, FAQ, and limitations.

A short path through the site

If you're new to cryptography, here's a sensible order. If you already know what you want, ignore this and click a tool.

▶ Step 1 Start with hashing and you understand integrity
Open the SHA-256/384/512 tool. Hash the same input twice — same output. Change one character — completely different output. That's the bedrock property. Then try the HMAC tool to see how a shared secret turns hashing into authentication.
▶ Step 2 Move to symmetric encryption with AES-GCM
AES-GCM gives you confidentiality AND authentication in one operation. Notice the "Tag" output. Try changing one byte of the ciphertext — decryption fails because the tag won't verify. That single property is why GCM is the default mode in TLS 1.3.
▶ Step 3 Asymmetric crypto: RSA and ECDSA
Generate a 2048-bit RSA keypair in RSA-OAEP. Encrypt with the public key, decrypt with the private. Then move to ECDSA for signing — much smaller keys, same security level.
▶ Step 4 Try breaking classical ciphers to learn why modern ones work
The Caesar tool breaks its own cipher using chi-squared scoring. The Vigenère tool uses Kasiski examination. When you see classical ciphers fall to statistics in 30 seconds, you understand why a 256-bit key matters.
▶ Step 5 Finish with Shamir and steganography for the fun stuff
Shamir's Secret Sharing shows you how a secret can be split among 5 people such that any 3 can recover it but no 2 can. Zero-width steganography shows how messages hide in plain sight inside ordinary text.

About CipherLayer

Purpose. CipherLayer is a working cryptography workshop for people who want to understand what they're doing. We built it because the typical online "encryption tool" is either a black box or a renamed base64 encoder. Neither helps anyone actually learn.

Who it's for. Three audiences: students learning applied crypto (they need to see the math, not just click a button), engineers evaluating libraries (they need to know what mode they're using and why it matters), and curious people who want to know whether the tool they're about to trust is real or theater.

How it's built. Modern tools use the browser's Web Crypto API — the same primitive implementations that ship in Chrome and Firefox. Historical ciphers are implemented in self-contained JavaScript so you can read them line by line. There is no server. Open DevTools, watch the network tab, and notice the absence of requests.

What it does not do. It does not replace OpenSSL, libsodium, or a HSM. It does not generate keys it keeps on disk. It does not pretend a 56-bit DES key is a reasonable choice. It does not claim that encoding is encryption.

Limitations you should know. A browser is not a hardened crypto device. Side-channel attacks (cache timing, power analysis) are not mitigated. If your threat model includes a determined adversary with physical access to your machine, use a dedicated tool. For everything else — learning, prototyping, low-stakes message scrambling — this site is fine and explicit about its scope.

Maintenance. Tools are reviewed when browser APIs change. Algorithms are not silently downgraded. If a tool's behavior changes, the page says so.

Privacy Policy

Last updated:

Summary. CipherLayer does not collect, store, or transmit any personal data. All cryptographic operations run locally in your browser. We do not have a backend that receives your inputs.

What we do not collect

  • Your plaintext inputs
  • Your ciphertext outputs
  • Your keys, passphrases, or passwords
  • Your IP address, beyond standard server logs (hosting provider level)
  • Cookies set by us

Google AdSense and third-party advertising

This site may display ads served by Google AdSense or other third-party advertising networks. These networks use cookies to serve ads based on a user's prior visits to this site or other sites. Google's use of advertising cookies enables it and its partners to serve ads based on the visit to this site and/or other sites on the Internet.

  • Third-party vendors, including Google, use cookies to serve ads based on a user's prior visits to our website.
  • Users may opt out of personalized advertising by visiting Google Ads Settings.
  • Users may opt out of some third-party vendors' use of cookies for personalized advertising by visiting www.aboutads.info.

Cookies

Cookies are small text files placed on your device. CipherLayer itself does not set cookies. Third-party advertising networks (such as Google AdSense) may set cookies when they serve ads. You can control cookies through your browser settings.

Data you provide

When you use a tool on this site, the input you type stays in your browser. The page does not make a network request with your input. We have no way to read what you typed. We have no logs that contain it.

Hosting-level logs

Our hosting provider may record standard HTTP request metadata (your IP address, requested URL, user agent, response code) for operational and security purposes. This is hosting infrastructure-level logging, not application logging, and is outside our control.

Children's privacy

This site is not directed at children under 13. We do not knowingly collect information from children under 13.

Changes to this policy

We may update this policy. The "last updated" date at the top will reflect the change. Material changes will be visible on this page.

Contact

Questions about this policy should be directed through the contact mechanism provided by the site operator. We respond to legitimate privacy inquiries.

Disclaimer

For reference and educational use only. The tools on this site are provided for educational, prototyping, and reference purposes. They are not a substitute for professional cryptography advice and must not be used as the sole safeguard for information that requires real protection.

Not professional advice

CipherLayer does not provide legal, compliance, financial, or security consulting services. The presence of a tool on this site does not constitute a recommendation that the algorithm it implements is appropriate for your use case. Choosing cryptography is a context-dependent decision that should involve a qualified professional when stakes are non-trivial.

No warranty

The tools are provided "as is" without warranty of any kind, express or implied. We do not warrant that the tools are error-free, that defects will be corrected, or that they will meet your requirements. Implementations of cryptographic algorithms may contain bugs. Side-channel resistance is not guaranteed.

Browser-only execution is a feature, not a shield

All computation happens in your browser. This means the tool operator cannot see your data. It does not mean the tool is invulnerable to attacks against your browser, your machine, or your network. Malicious browser extensions, compromised devices, and network observers remain threats.

Not for high-stakes use

Do not use these tools to protect information where failure would cause significant harm (medical records, financial transactions, classified information, infrastructure access). Use established libraries (libsodium, OpenSSL, BoringSSL) integrated into audited systems for those purposes.

Algorithm choices are not endorsements

Some tools implement algorithms (such as classical ciphers) for educational reasons. Their presence on this site is not an endorsement of their use for protecting real information. The Caesar cipher has been broken since the 9th century. It is on this site because understanding why it fails is instructive.

Limitation of liability

To the maximum extent permitted by law, the site operator shall not be liable for any damages arising from use of, or inability to use, the tools provided.