(Dokümantasyon İngilizcedir)
What it does
This tool encrypts and decrypts files with a passphrase, following the philosophy of age (age-encryption.org/v1) — the modern file-encryption format built as a deliberate answer to PGP’s complexity. age’s core idea: small, explicit, authenticated encryption with no key-signature webs, no expired key packets, no algorithm negotiation you didn’t ask for. Pick a passphrase, get an encrypted file. That’s the whole interface.
The output is a self-describing envelope starting with the cosmodev-age-v1 magic header, followed by a fresh random 16-byte
saltsaltRandom data mixed into each password before hashing, so identical passwords produce different digests and precomputed tables become useless.
, a 12-byte IV, and the file sealed with AES-256-GCM authenticated encryption. The 256-bit key is stretched from your passphrase with PBKDF2-SHA256 (100,000 iterations) so brute-forcing a stolen file is expensive. Everything runs 100% client-side via the browser’s Web Crypto API — the file and the passphrase never leave your machine. (Note: this is the age style of encryption on Web Crypto primitives; the officialage CLI uses scrypt + ChaCha20-Poly1305 and cannot read these files.)
Why people switched from PGP to age:
| age | PGP/GPG | |
|---|---|---|
| Scope | File encryption, nothing else | Email, keys, signatures, identity — a whole PKI |
| Keys | One small recipient key or just a passphrase | Keyring management, expiration, trust levels |
| Output | Compact binary or ASCII-armored text | Large packets with version + algorithm metadata |
| Algorithms | One explicit modern suite (AEAD) | Negotiated suites, some decades old |
| Failure mode | Loud auth-tag error | Historic parser quirks, “untrusted but shown” walls |
How to use it
- Pick Encrypt or Decrypt with the toggle.
- Drag a file into the drop zone (or click it to browse). Any file type works.
- Type a passphrase. Use the eye button to show or hide it.
- Press Encrypt file / Decrypt file. The result downloads automatically, with the original and output sizes compared so you can see the 59-byte overhead (header 15 B +
saltsaltRandom data mixed into each password before hashing, so identical passwords produce different digests and precomputed tables become useless.
16 B + IV 12 B + GCM tag 16 B).
Examples
Encrypt a backup:
secrets.tar (48.0 KB) + passphrase blue heron circles midnight → secrets.tar.age (48.1 KB, +59 B)
Decrypt it back:
secrets.tar.age + the same passphrase → secrets.tar, byte-for-byte identical to the original
Wrong passphrase:
secrets.tar.age + any other passphrase → Decryption failed: wrong passphrase or corrupted file. - the GCM tag check fails and nothing is written.
Good to know
- Zero server contact: everything runs via the browser’s Web Crypto API. No uploads, no logs, no accounts. You can disconnect from the network and the tool still works.
- Why authenticated encryption? AES-256-GCM’s 16-byte tag proves the file was not modified after encryption. Tampering with any byte - header, ciphertext, IV, or
saltsaltRandom data mixed into each password before hashing, so identical passwords produce different digests and precomputed tables become useless.
- makes decryption fail loudly instead of returning corrupted data. - The header is a feature. age-style files announce themselves: the tool detects the
cosmodev-age-v1magic prefix and refuses to decrypt anything else, so you never accidentally “decrypt” a plain file into garbage. - Passphrase strength is the whole security model. There is no key recovery, no escrow, no reset. If you forget the passphrase, the file is unrecoverable - by design.
- The same file encrypted twice produces different output every time, because the
saltsaltRandom data mixed into each password before hashing, so identical passwords produce different digests and precomputed tables become useless.
and IV are freshly random per encryption. - Related tools: Passphrase Generator (pick a strong passphrase), File Encryptor (same crypto without the age framing), Text Encryptor (encrypt snippets instead of files).