Caesar, ROT13 and Vigenère ciphers
Transformed in your browser · nothing is uploaded
Four classical ciphers in one box. A Caesar shift moves each letter a fixed distance along the alphabet — a shift of 3 turns A into D, and there are only 25 keys. ROT13 is the shift of 13 that is its own inverse, Atbash maps A to Z, and Vigenère varies the shift letter by letter from a keyword.
How to use the caesar, rot13 and vigenère ciphers
A Caesar cipher has 25 possible keys, so breaking it by trying all of them takes seconds by hand. It is a puzzle and a teaching tool, not security, and the page says so because people do occasionally reach for it in earnest. Non-letters pass through untouched in every cipher here, which incidentally leaks word lengths and punctuation to anyone looking at the output. If you do not know the shift, letter frequency gets you there faster than exhaustion: the commonest letter in the ciphertext is probably E.
Two shifts have their own names because they are self-inverse. ROT13 is a shift of 13, and 13 is half of 26, so applying it twice returns the original — one function both encodes and decodes, which is exactly why it caught on for spoilers and punchlines on Usenet, where it made reading a deliberate act and any newsreader could implement it in a line. It leaves digits and punctuation alone; ROT47 is the variant that scrambles those too. Atbash maps the alphabet onto its reverse, A to Z and B to Y, and is self-inverse for the same structural reason.
Vigenère is the one that is genuinely different. Instead of a single shift it takes a keyword and uses each of its letters as a shift in turn, repeating the keyword across the message, so the same plaintext letter encodes to different ciphertext letters in different positions. That defeats plain frequency analysis, and it is why the cipher held a reputation as unbreakable for roughly three centuries. The key advances only on letters here, which is the detail poorly written implementations get wrong: if punctuation and spaces advance the key, text with spaces in it will not decode. Kasiski broke it in 1863 by finding repeated sequences in the ciphertext and deducing the key length from the distances between them; once the key length is known the message is no more than several interleaved Caesar shifts, each solvable by frequency. A long keyword with no internal repetition resists that longer than a short one, but the method still works, so this belongs with the others: a puzzle, not protection.
What people use it for
- Decoding a ROT13 spoiler or punchline from a forum post
- Working a Vigenère keyword cipher for a puzzle or a class
- Shifting a message by three the way Caesar did, and shifting it back again
- Breaking a Caesar you have no key for by running all twenty-five shifts
- Reading an Atbash line out of a crossword or an escape room
- Showing a class why a shift that varies defeats counting the letters
Questions
No. There are 25 keys and trying them all takes seconds. It is a puzzle, not protection, and the same goes for everything else on this page.
A Caesar shift of 13. Because 13 is half of 26, applying it twice returns the original, so one operation both encodes and decodes.
Apply ROT13 again. A ROT13 decoder and a ROT13 encoder are the same button, because a shift of thirteen is its own inverse.
Because it is half of twenty-six, which is exactly what makes encoding twice return the original.
For spoilers and punchlines. It made reading a deliberate act, and any client could implement it trivially.
Try all 25, or look at letter frequency. The commonest letter in the ciphertext is probably E.
The alphabet mapped onto its reverse: A becomes Z, B becomes Y. Like ROT13 it is its own inverse.
The shift varies letter by letter with the keyword, so plain frequency analysis fails; E does not map to one symbol.
No. Kasiski broke it in 1863 by deducing the key length from repeated sequences. After that it is several Caesar shifts.
A long one with no repeated pattern. A short key repeats often, which is precisely what Kasiski analysis looks for.
It should not, and here it does not — the key advances only on letters. Tools that get this wrong fail to decode text containing spaces.
No, they pass through unchanged in every cipher here, which does leak the word lengths.
No. ROT47 is the variant that scrambles digits and punctuation as well.
You can, and it wraps: −3 is treated as a shift of 23, which is the same thing as decoding a shift of 3. The decode option says it more plainly, so use that.
No. Every cipher runs in this tab.