XOR Cipher Encoder / Decoder
Encode or decode text with a repeating XOR key, the key as text or hex, the ciphertext as hex or Base64.
- Plain text
- Attack at dawn
- Key
- key "key", output as hex
- Encoded
- 2a110d0a06124b040d4b01181c0b
Other ciphers
How the XOR cipher works
XOR works on the bytes underneath the text, not on letters. Each byte of the message is combined with a byte of the key using exclusive or — a bit is set in the result where exactly one of the two inputs had it set — and the key repeats from its start when it runs out. XOR undoes itself: combining the ciphertext with the same key gives the message back.
The result is arbitrary bytes, most of them not printable, so they have to be written down somehow. That is what hex and Base64 are here: ways of writing bytes as text so they survive a copy and paste. They are not part of the cipher and they are not a second layer of anything.
A worked example
Attack at dawn with the key key becomes 2a110d0a06124b040d4b01181c0b in hex. Every character here, the text and the key alike, is one byte of UTF-8; an accented letter or emoji would be two to four, and XOR transforms all of them.
How it is broken
From one guessed letter. XOR is its own inverse, so ciphertext XOR plaintext is the key. If you can guess how the message starts, you have the key's first bytes: the first ciphertext byte above is 2a, a guessed capital A is 41, and 2a XOR 41 is 6b — the letter k, the first byte of the key. Messages that start "Hello", "Dear" or a file header give away a whole key's worth.
From the ciphertext alone. Find the key length first — guess lengths and keep the one where bytes a key-length apart look most alike, by Hamming distance or the index of coincidence. Then every key-length-th byte was XORed with the same key byte, so each column is a single-byte XOR with only 256 candidates, and the one that yields English-letter frequencies wins. This is the classic CTF warm-up exercise; the Cryptopals set 1 walks through it.
XOR is a real building block of cryptography only as a one-time pad: a truly random key as long as the message, used once. Shannon proved that unbreakable in 1949, and it is exactly the condition a repeating key violates. For anything that needs to stay private, use age or GnuPG.
Everything on this page runs in your browser — nothing you type is sent anywhere. The cipher encoder / decoder runs all five ciphers on one page, and the cipher buttons above switch this one too.
How do I decode XOR with a key?
Choose Decode, type the key (as text, or as hex if that is how you have it), pick the encoding the ciphertext is in — hex or Base64 — and paste it. A wrong key often still produces readable-looking nonsense rather than an error, so a plausible answer is not proof the key was right.
Is XOR encryption?
Not with a short repeating key: the key can be recovered from the ciphertext alone. XOR is only secure as a one-time pad — a truly random key as long as the message, never reused — which is not what this tool, or any repeating-key XOR, does. Use age or GnuPG for anything private.
Why is the output hex or Base64 instead of text?
Because XOR produces arbitrary bytes, most of which are not printable characters. Hex and Base64 are two ways of writing bytes down as text. Decoding needs to know which one the ciphertext is in.