
Ciphey v0.12.1
⚡ Automatically decrypt encryptions without knowing the key or cipher, decode encodings, and crack hashes ⚡
Ciphey
Paste in text that's been encoded or encrypted. Ciphey works out how and hands you the plaintext.
No key, no cipher name, no hints. Base64, hex, Caesar/ROT13, Vigenère, Morse code and 19 more, several layers deep.
Install ·
Quick start ·
Features ·
Library ·
MCP ·
Docs ·
Discord
▶ Watch the one-minute tour (MP4, 61 s)
Install
cargo install ciphey
Prebuilt binaries for Linux (x86_64), macOS (Intel and Apple silicon) and Windows (x86_64) are on the releases page, each with a .sha256 checksum.
To build from source, you need a Rust toolchain:
git clone https://github.com/bee-san/Ciphey
cd Ciphey
cargo build --release # the binary is target/release/ciphey
Or skip installing: join the Discord server, go to #bots and type $ciphey <your text> ($help lists the commands).
Quick start
$ ciphey -t 'aGVsbG8gdGhlcmUgZ2VuZXJhbA=='
🕵️ I think the plaintext is Words.
Possible plaintext: 'hello there general' (y/N):
y
🥳 ciphey has decoded 64 times.
The plaintext is:
hello there general
the decoder used is Base64
The first time you run it, a short setup asks for a colour theme, how you want results shown and whether to use a wordlist, and saves your answers to ~/.ciphey/config.toml.
ciphey -t 'NTA3NjYzNzU3MjZjMjA3NjY2MjA2OTcyNjU2YzIwNzM2ZTY2Njc=' # ROT13 → hex → Base64, nothing else needed
ciphey -f secret.txt # read the input from a file
ciphey -d -t '...' # no y/N prompt: take the first plaintext found (handy in scripts)
ciphey -c 15 -t '...' # keep searching for up to 15 seconds (the default is 5)
ciphey -r 'flag\{' -t '...' # only accept plaintext that matches a regex (a crib)
ciphey --wordlist words.txt -t '...' # also accept any exact match from a wordlist
ciphey --help lists every option.
Features
⚡ Fast
▶ Watch the clip (16 s)
Three layers (ROT13, then hex, then Base64) come off in 0.16 s, measured by bash's time in a real recording. Here is the same comparison for more inputs, against Python Ciphey 5.14, the version Ciphey replaces:
| Input | Ciphey | Python Ciphey 5.14 |
|---|---|---|
| Base64 | 0.11 s | 0.92 s |
| Hex → Base64 | 0.14 s | 1.02 s |
| ROT13 → Hex → Base64 | 0.19 s | no answer within 60 s |
| URL → Base64 → Hex | 0.24 s | 1.15 s |
| Base64 ×4 | 0.41 s | 0.78 s |
| Hex → Base32 → Base64 → Hex | 0.54 s | 0.72 s, wrong answer |
| ROT13 → Hex → Base64 → Base32 | 1.15 s | no answer within 60 s |
Wall-clock median of 10 runs per input (Python Ciphey: 3) on a shared 16-CPU Linux machine, Ciphey at 47bd16d6 with the y/N prompt off and a fresh $HOME per run so its cache can't help. Every run was capped at 60 s. The script and raw numbers are in media/tui-video/bench on the media/readme-videos branch.
Where both get the right answer, Ciphey is 1.9 to 8.6 times faster. Where does the speed come from?
- It's Rust.
- An A* search tries the most promising chains of decoders first.
- Every decoder runs in parallel with Rayon, on up to 10 candidate texts at a time.
- Answers are cached in
~/.ciphey/database.sqlite, so the same input a second time comes back in milliseconds.
🧅 Layer after layer, no key needed
Ciphey doesn't need to be told what it's looking at. It searches chains of decoders (Base64 inside hex inside ROT13, four layers of Base64, and so on) and stops at the first candidate that looks like plaintext. By default it shows you that candidate and asks before accepting it (-d turns this off). The clip at the top of this page shows a four-layer decode.
There is also a timer: if Ciphey hasn't found anything after 5 seconds, it stops and says so (-c changes the limit).
It knows 24 decoders and crackers:
| Kind | Decoders |
|---|---|
| Base encodings | Base64 (standard and URL-safe), Base32, Base58 (Bitcoin, Flickr, Monero, Ripple), Base91, Base65536, Z85 |
| Other encodings | Hexadecimal, binary, URL (percent-encoding), Morse code, Braille, A1Z26, Citrix CTX1 |
| Ciphers | Caesar (including ROT13), ROT47, Atbash, Vigenère (it works out the key itself), rail fence, reversed text |
| Oddities | Brainfuck (it runs the program), Morse or binary written with other symbols |
More are on the way: #1030 tracks 109 decoders that aren't in yet.
🕵️ Knows what it found
▶ Watch the clip (21 s)
Every candidate plaintext also goes through LemmeKnow, the Rust port of pyWhat, which recognises more than 120 formats. So Ciphey doesn't just decode the string, it tells you what it is: a password in a mount or sshpass command, a TOTP secret, a GitHub token or Stripe key, an IP or MAC address, an email address or URL, a card number, a crypto wallet, an AWS ARN or a CTF flag.


