CipherTools
ToolsBlogsSnippets
ToolsBlogsSnippets
  • MD5 Text Hash
  • MD5 File Hash
  • BKDR Text Hash
  • BKDR File Hash
  • SHA-256 Text Hash
  • SHA-256 File Hash
  • SHA-512 Text Hash
  • SHA-512 File Hash
  • SHA-3 Text Hash
  • SHA-3 File Hash
  • SHAKE Text Hash
  • SHAKE File Hash
  • Argon2 Text Hash
  • Argon2 File Hash
  • CRC Text Checksum
  • CRC File Checksum
  • HMAC Text Generator
  • HMAC File Generator
  • BLAKE2 Text Hash
  • BLAKE2 File Hash
  • BLAKE3 Text Hash
  • BLAKE3 File Hash
  • CityHash Text Hash
  • CityHash File Hash
  • FarmHash Text Hash
  • FarmHash File Hash
  • xxHash Text Hash
  • xxHash File Hash
  • MurmurHash2 Text Hash
  • MurmurHash2 File Hash
  • MurmurHash3 Text Hash
  • MurmurHash3 File Hash
  • bcrypt Text Hash
  • bcrypt File Hash
  • scrypt Text Derivation
  • scrypt File Derivation
  • AES Encryption and Decryption
  • AES File Encryption
  • AES File Decryption
  • AES-GCM Encryption and Decryption
  • ChaCha20-Poly1305 Text
  • ChaCha20-Poly1305 File Encryption
  • ChaCha20-Poly1305 File Decryption
  • DES Encryption and Decryption
  • DES File Encryption
  • DES File Decryption
  • RSA Encryption and Decryption
  • RSA File Encryption
  • RSA File Decryption

Asymmetric encryption · RSA

RSA-OAEP File Decryption

Paste your PEM private key and decrypt RSA-OAEP ciphertexts entirely in the browser to validate integrations or unwrap session keys.

Upload a file

Click to browse or drag & drop files here

RSA-OAEP is best for small blobs or session keys. Large uploads will likely exceed the modulus limit.
Decrypted payloads will be available here when a valid RSA package is supplied.

Generated keys appear in the PEM editors below so you can experiment end-to-end.

Use the private key that pairs with the public key used during encryption to recover the bytes.

Usage notes

Use this RSA-OAEP view to validate ciphertexts from CI pipelines, penetration tests, or customer reports without leaving the browser. The tool automatically unwraps bundled payloads so larger files keep working, but the OpenSSL example below reflects the classic direct-RSA workflow, which only supports a few hundred bytes per block (e.g., ~214 bytes with a 2048-bit key and SHA-256). Guard the private key carefully and keep the tab open while the browser streams the bytes back into a downloadable plaintext file.

Equivalent OpenSSL workflow

Recreate the browser’s RSA path with a single openssl pkeyutl -decrypt invocation:

Unwrap & decrypt
# Decrypt a small RSA-OAEP ciphertext
openssl pkeyutl -decrypt -inkey private.pem \
  -pkeyopt rsa_padding_mode:oaep -pkeyopt rsa_oaep_md:sha256 \
  -in secret.bin.rsa -out secret.bin

# Optional: if you received Base64 text, decode first
base64 -d secret.bin.rsa.b64 > secret.bin.rsa
© 2026 CipherTools. All computations run locally in your browser.