Desktop toolkit · version 2.0.0
The app
cryptoKit is a free desktop application (and command-line tool) for encrypting, decrypting, hashing and signing with the 44 algorithms of this site, from Caesar and Enigma to AES-GCM, Argon2id, Ed25519 and post-quantum ML-KEM. Every algorithm carries a security badge and a link to the chapter that explains it.
In this chapter
The jar needs Java 21 or newer (any distribution: Temurin, Oracle, Microsoft, Ubuntu's OpenJDK…). Double-click it, or run java -jar cryptoKit-2.0.0.jar. The release page also has portable packages for Windows, macOS and Linux that include their own Java.



What's new in 2.0
Version 1.0 (2022) was a small Swing window with fifteen algorithms. Version 2 is a rewrite that keeps its spirit and its compatibility:
- 44 algorithms in eight families, each with a security badge (recommended, legacy, broken, historical, encoding), a description and a How it works link to this site.
- New: classical ciphers (Caesar, Vigenère, Playfair, Enigma I), Base32, Base58 and Base64URL, BLAKE2b, BLAKE3 and RIPEMD-160, HMAC, password hashing (Argon2id, scrypt, bcrypt, PBKDF2), AES-CTR, ChaCha20-Poly1305, password-based AES-GCM with Argon2id, public-key encryption (RSA-OAEP, X25519 + AES-GCM, ML-KEM-768) and signatures (Ed25519, ECDSA P-256, RSA-PSS, ML-DSA-65).
- A modern interface: light and dark themes, English and Spanish, a searchable list, key and IV generators, key-pair generation, input and output in text, hex or Base64, loading and saving files, and a use the result button that sends a ciphertext back to be decrypted or a digest to be verified.
- Safer defaults: leave the IV or nonce empty and a random one is generated and prepended; authenticated modes reject tampered data; verifications compare in constant time; errors are explained instead of printed as results.
- A command-line tool in the same jar, for scripts.
- Tested: 89 automated tests with official vectors (NIST, RFC) and with ciphertexts produced by the real 1.0 jar.
The 44 algorithms
| Family | Algorithms |
|---|---|
| Classical ciphers | Caesar Vigenère Playfair Enigma I |
| Encodings | Hexadecimal Base32 Base58 Base64 Base64URL |
| Hash functions | SHA-256 SHA-512 SHA3-256 SHA3-512 BLAKE2b-512 BLAKE3 RIPEMD-160 SHA-1 MD5 |
| Message authentication | HMAC-SHA256 HMAC-SHA512 HMAC-SHA3-256 |
| Password hashing | Argon2id scrypt bcrypt PBKDF2-HMAC-SHA256 |
| Symmetric encryption | AES-GCM ChaCha20-Poly1305 AES-GCM + Argon2id AES-CTR AES-CBC AES-ECB Triple DES-CBC Blowfish-CBC Blowfish-ECB DES-CBC DES-ECB PBE AES-256 (Jasypt) |
| Public-key encryption | ML-KEM-768 + AES-GCM X25519 + AES-GCM RSA-OAEP |
| Digital signatures | ML-DSA-65 Ed25519 ECDSA P-256 RSA-PSS |
recommended legacy broken historical encoding (not encryption)
From the command line
The same jar is a command-line tool when it receives arguments. The text comes from the last argument or from standard input; options are the algorithm's parameters; verifications return exit status 1 when they fail.
java -jar cryptoKit-2.0.0.jar list
java -jar cryptoKit-2.0.0.jar sha256 hash "hello"
java -jar cryptoKit-2.0.0.jar aes-gcm encrypt --key=00112233445566778899aabbccddeeff --key-format=hex "attack at dawn"
java -jar cryptoKit-2.0.0.jar argon2id hash "correct horse battery staple"
java -jar cryptoKit-2.0.0.jar keygen ed25519 > keys.pem
java -jar cryptoKit-2.0.0.jar ed25519 sign --private=@keys.pem "I owe you 10 euros"
java -jar cryptoKit-2.0.0.jar enigma encrypt --rotors="IV II V" --positions="B L A" "WETTERBERICHT"
java -jar cryptoKit-2.0.0.jar info ml-kem-768
Compatible with version 1.0
Ciphertexts made with cryptoKit 1.0 still decrypt: DES, AES and Blowfish in ECB and CBC, AES-GCM and Jasypt PBE, with keys and IVs typed as text exactly as before (version 1 printed “(hexadecimal)” after the result; just leave it out). The test suite checks this against output of the real 1.0 jar. Version 1.0 itself is still available from its release page and the repository's legacy branch.
Security notes
- The app is a tool for learning and for everyday tasks, not an audited product. Its algorithms come from the Java platform and from Bouncy Castle, both widely reviewed; the app composes them carefully, but has not been independently audited.
- Keys typed as text (as in version 1) are weak unless they are long and random: prefer the dice, which generates random keys in hex, or use the password-based AES-GCM + Argon2id.
- Nothing is sent over the network; nothing is stored except your theme, language and last algorithm.
Building from source
git clone https://github.com/toniferr/cryptoKit.git
cd cryptoKit
mvn verify # compiles, runs the tests, builds target/cryptoKit-2.0.0.jar
java -jar target/cryptoKit-2.0.0.jar
Requirements: JDK 21 or newer and Maven 3.8 or newer. The portal you are reading lives in the same repository, in site/, and is built with python site/build.py.
History of the project
- 2017: first version, an Eclipse project with symmetric ciphers, hashes and Base64 on Bouncy Castle 1.57.
- 2020: Java 11, Maven, SHA-2 and SHA-3, AES-GCM and Blowfish, continuous integration and a wiki in Spanish.
- 2022: version 1.0.0, a runnable jar with dependencies and password-based encryption with Jasypt.
- 2026: version 2.0.0, rewritten from the core, with this portal.