Independent Decryption Guide

Your data is encrypted with open, standard algorithms that any computer can decrypt — without needing this app. This guide walks you through it step by step, even if you have never used a command-line tool before.

Estimated time: 5 – 10 minutes.

Before you start, you will need two things:

Windows — PowerShell 7.4 or newer

We will use PowerShell 7.4 or newer, a free command-line tool from Microsoft. It has everything needed built in — no extra downloads beyond PowerShell itself.

1

Install PowerShell 7.4 or newer

The easiest way is through the Microsoft Store — it takes about two minutes:

  1. Click the Start button (Windows logo in the bottom-left corner).
  2. Open the Microsoft Store (search for it if you can't find it).
  3. In the search bar at the top of the Store, type PowerShell and press Enter.
  4. Click the result that says PowerShell with "Microsoft Corporation" listed as the publisher.
  5. Click Get (or Install) and wait for it to finish.
Alternative — direct download: If you prefer not to use the Store, visit the official Microsoft installation guide at
learn.microsoft.com — Installing PowerShell on Windows
Download the file ending in -win-x64.msi and run it, clicking Next on each screen.
2

Open PowerShell 7.4 or newer

  1. Click the Start button.
  2. Type PowerShell 7.
  3. Click PowerShell 7 in the results. (It may also be listed as pwsh.)
  4. A dark window with a blinking cursor appears — this is your terminal. It will show something like PS C:\Users\YourName>.
Make sure you open PowerShell 7.4 or newer, not "Windows PowerShell" — the older one (version 5) will not work. PowerShell 7 usually has a black icon; the old one has a blue icon.
To paste text into PowerShell, right-click anywhere in the window. You can also press Ctrl+V.

Choose how you want to decrypt

Read directly in terminal

3

Keep this decryption out of saved command history

Run this first. It remembers your current PSReadLine history setting, then stops new commands from being saved to its persistent history file for the rest of this PowerShell session.

$previousHistoryStyle = (Get-PSReadLineOption).HistorySaveStyle; Set-PSReadLineOption -HistorySaveStyle SaveNothing
4

Paste and run the decryption code

Your encrypted text and password stay on your computer. Enter them only in PowerShell, not on this website.
  1. Click Copy code.
  2. Paste the command into PowerShell.
  3. Important — do not press Enter yet.
  4. In the pasted command, find TEXT TO DECRYPT.
  5. Replace it with the complete Base64 encrypted text you want to decrypt.
  6. Find PASSWORD and replace it with the password used to encrypt the message.
  7. Keep the single quote marks around both replacements.
  8. Make sure both placeholders have been replaced.
  9. Press Enter. The decrypted message appears in PowerShell.
[byte[]]$bytes=[Convert]::FromBase64String(('TEXT TO DECRYPT' -replace '\s','')); [byte[]]$salt=$bytes[0..15]; [byte[]]$iv=$bytes[16..27]; [byte[]]$ciphertext=$bytes[28..($bytes.Length-17)]; [byte[]]$tag=$bytes[($bytes.Length-16)..($bytes.Length-1)]; $pbkdf2=[System.Security.Cryptography.Rfc2898DeriveBytes]::new([System.Text.Encoding]::UTF8.GetBytes('PASSWORD'),$salt,100000,[System.Security.Cryptography.HashAlgorithmName]::SHA256); [byte[]]$key=$pbkdf2.GetBytes(32); $pbkdf2.Dispose(); $aesGcm=[System.Security.Cryptography.AesGcm]::new($key,16); [byte[]]$plaintext=New-Object byte[] $ciphertext.Length; $aesGcm.Decrypt($iv,$ciphertext,$tag,$plaintext); $aesGcm.Dispose(); Write-Host ([System.Text.Encoding]::UTF8.GetString($plaintext))
Before pressing Enter: make sure you replaced both TEXT TO DECRYPT and PASSWORD.
A single quote in either value? Write it as two single quotes. For example, the password it's ready becomes 'it''s ready'. Spaces, dollar signs, and other punctuation need no other change inside PowerShell single quotes.
5

Clean up after reading

Run the following after you have finished reading or copying the message. It clears the variables, clears PowerShell's session history and PSReadLine's in-memory recall list, clears the clipboard, restores your earlier history setting, and clears the visible screen.

$bytes=$null; $salt=$null; $iv=$null; $ciphertext=$null; $tag=$null; $key=$null; $plaintext=$null; Clear-History; [Microsoft.PowerShell.PSConsoleReadLine]::ClearHistory(); Set-Clipboard -Value ''; Set-PSReadLineOption -HistorySaveStyle $previousHistoryStyle; $previousHistoryStyle=$null; Clear-Host
Important: clearing variables does not guarantee secure erasure from memory, and Clear-Host does not guarantee that every terminal application has discarded its scrollback. In Windows Terminal, open the command palette with Ctrl+Shift+P, run Clear Buffer, then close the tab when finished.
About PowerShell history: Clear-History clears every command from the current PowerShell session history, not only the decryption command. It does not delete the persistent PSReadLine history file. The separate PSReadLine in-memory recall list is cleared before history saving is restored, so unrelated history saved before this session is preserved.
Optional full-history deletion: You normally do not need this. Remove-Item (Get-PSReadLineOption).HistorySavePath -Force deletes ALL saved PowerShell command history, not only this decryption session.

Mac — Python 3

We will use Python 3 and a free helper package called cryptography. The setup takes about 5 minutes and only needs to be done once.

1

Open Terminal

Terminal is the command-line tool on Mac. You can find it two ways:

  • Spotlight (easiest): Press ⌘ Cmd+Space, type Terminal, press Enter.
  • Finder: Go to Applications → Utilities → Terminal.

A window opens with a prompt — this is your terminal. You type commands here and press Enter to run them.

2

Check that Python 3 is installed

Type the following and press Enter:

python3 --version
  • If you see Python 3.x.x — Python is installed. Go to Step 3.
  • If a popup appears asking to install developer tools — click Install and wait. Python 3 will be included.
  • If you see an error — go to python.org/downloads/macos, download the latest macOS installer, and run it. Then try the command above again.
3

Install the cryptography package

Type this and press Enter:

pip3 install cryptography

Wait until you see a line that says Successfully installed cryptography-.... This only needs to be done once ever.

If you see "pip3: command not found", try instead:
python3 -m pip install cryptography

Choose how you want to decrypt

Read directly in terminal

4

Start a private zsh history context

Modern macOS uses zsh by default. Run this first so the sensitive pasted command goes into a temporary history list instead of your normal saved history:

fc -p
If echo $SHELL does not end in /zsh, do not use this command. See the Linux section's Bash instructions if your shell is Bash.
5

Paste and run the decryption code

Your encrypted text and password stay on your computer. Enter them only in Terminal, not on this website.
  1. Click Copy code.
  2. Paste the entire Python block into Terminal.
  3. Important — do not press Enter yet. Python is the multiline exception, so make sure the whole block has appeared before editing it.
  4. Use the arrow keys to move through the pasted block and find TEXT TO DECRYPT.
  5. Replace it with the complete Base64 encrypted text you want to decrypt.
  6. Find PASSWORD and replace it with the password used to encrypt the message.
  7. Keep the double quote marks around both replacements.
  8. Make sure both placeholders have been replaced.
  9. Press Enter. The decrypted message appears in Terminal.
python3 - <<'PY'
import base64
from cryptography.hazmat.primitives import hashes
from cryptography.hazmat.primitives.kdf.pbkdf2 import PBKDF2HMAC
from cryptography.hazmat.primitives.ciphers.aead import AESGCM

encrypted_bytes = base64.b64decode("".join("TEXT TO DECRYPT".split()), validate=True)
salt = encrypted_bytes[:16]
iv = encrypted_bytes[16:28]
ciphertext_and_tag = encrypted_bytes[28:]

kdf = PBKDF2HMAC(algorithm=hashes.SHA256(), length=32, salt=salt, iterations=100000)
key = kdf.derive("PASSWORD".encode("utf-8"))

plaintext_bytes = AESGCM(key).decrypt(iv, ciphertext_and_tag, None)
print(plaintext_bytes.decode("utf-8"))
PY
Before pressing Enter: make sure you replaced both TEXT TO DECRYPT and PASSWORD.
Quotes or backslashes in the password? Inside the Python double quotes, write \" for a double quote and \\ for a backslash. Spaces, single quotes, Swedish characters, and emoji need no change.
6

Clean up after reading

The Python process has ended, so its password, encrypted input, key, and plaintext variables are no longer available in the shell. Run these commands individually:

pbcopy < /dev/null
fc -P
clear

pbcopy empties the macOS clipboard. fc -P discards the temporary zsh history context and restores your normal history. clear clears the visible screen.

Terminal scrollback: clear does not necessarily remove earlier output from scrollback. In Apple's Terminal app, press ⌘ Cmd+K to clear scrollback, then close the tab. Other terminal apps may use a menu item named Clear Scrollback or Clear Buffer. This does not guarantee secure memory erasure.

Linux / Python — Python 3

We will use Python 3 and the free cryptography package. Python 3 is pre-installed on most Linux distributions.

1

Open a Terminal

How to open a terminal depends on your desktop:

  • Ubuntu / GNOME: Press Ctrl+Alt+T, or search "Terminal" in the Activities overview.
  • KDE Plasma: Right-click the desktop and choose Open Terminal, or press Alt+F2 and type konsole.
  • Any desktop: Search for "Terminal" or "Console" in your application menu.
2

Check Python 3 and install if needed

Type this and press Enter:

python3 --version

If you see Python 3.x.x — skip to Step 3. If not, install it:

  • Ubuntu / Debian / Linux Mint:
    sudo apt update && sudo apt install python3 python3-pip
  • Fedora / RHEL:
    sudo dnf install python3 python3-pip
  • Arch / Manjaro:
    sudo pacman -S python python-pip

You will be asked for your system password — type it and press Enter. Note: the password will not appear as you type. That is normal.

3

Install the cryptography package

pip3 install cryptography

Wait until you see Successfully installed cryptography-.... This only needs to be done once.

If you see a permissions error, try:
pip3 install --user cryptography

Choose how you want to decrypt

Read directly in terminal

4

Keep this decryption out of normal shell history

First check your shell:

basename "$SHELL"

If it says bash, run:

OLD_HISTCONTROL=$HISTCONTROL; HISTCONTROL=ignorespace

The decryption code below deliberately begins with one space. Bash's ignorespace setting keeps that pasted command out of its history. Your earlier setting is restored during cleanup.

If it says zsh, run:

fc -p

This pushes an empty temporary zsh history context, which is discarded during cleanup.

5

Paste and run the decryption code

Your encrypted text and password stay on your computer. Enter them only in Terminal, not on this website.
  1. Click Copy code.
  2. Paste the entire Python block into Terminal.
  3. Important — do not press Enter yet. Python is the multiline exception, so make sure the whole block has appeared before editing it.
  4. Use the arrow keys to move through the pasted block and find TEXT TO DECRYPT.
  5. Replace it with the complete Base64 encrypted text you want to decrypt.
  6. Find PASSWORD and replace it with the password used to encrypt the message.
  7. Keep the double quote marks around both replacements.
  8. Make sure both placeholders have been replaced.
  9. Press Enter. The decrypted message appears in Terminal.
 python3 - <<'PY'
import base64
from cryptography.hazmat.primitives import hashes
from cryptography.hazmat.primitives.kdf.pbkdf2 import PBKDF2HMAC
from cryptography.hazmat.primitives.ciphers.aead import AESGCM

encrypted_bytes = base64.b64decode("".join("TEXT TO DECRYPT".split()), validate=True)
salt = encrypted_bytes[:16]
iv = encrypted_bytes[16:28]
ciphertext_and_tag = encrypted_bytes[28:]

kdf = PBKDF2HMAC(algorithm=hashes.SHA256(), length=32, salt=salt, iterations=100000)
key = kdf.derive("PASSWORD".encode("utf-8"))

plaintext_bytes = AESGCM(key).decrypt(iv, ciphertext_and_tag, None)
print(plaintext_bytes.decode("utf-8"))
PY
Before pressing Enter: confirm that TEXT TO DECRYPT and PASSWORD are no longer visible. If either placeholder remains, do not run the code. If you use Bash, keep the space before python3.
Quotes or backslashes in the password? Inside the Python double quotes, write \" for a double quote and \\ for a backslash. Spaces, single quotes, Swedish characters, and emoji need no change.
6

Clean up after reading

The Python subprocess has ended, so its password, encrypted input, key, and plaintext variables are no longer available in the shell.

If you use Bash, run:

HISTCONTROL=$OLD_HISTCONTROL; unset OLD_HISTCONTROL; clear

If you use zsh, run:

fc -P; clear

To clear the clipboard, use the command matching your desktop:

  • Wayland: wl-copy --clear (requires the optional wl-clipboard package).
  • X11: printf '' | xclip -selection clipboard (requires the optional xclip package).
  • If neither command is installed, copy some harmless text or use your desktop's clipboard manager to remove the entry.
Terminal scrollback: clear only clears the visible screen in many terminal applications. Use your terminal's Clear Scrollback or Clear Buffer action, then close the tab. These cleanup steps reduce exposure but do not guarantee secure memory erasure.

Why this works without the app

This tool encrypts using only open, standardised algorithms — any implementation that follows the same format will produce the same result:

BytesLengthContents
0 – 1516 bytesRandom salt (for PBKDF2 key derivation)
16 – 2712 bytesRandom IV / nonce (for AES-GCM)
28 – (end−17)variableCiphertext
last 1616 bytesGCM authentication tag

PBKDF2-SHA256 (100,000 iterations) — open standard, defined in RFC 8018.
AES-256-GCM — NIST standard, available in .NET, Python, OpenSSL, Go, Rust, and more.