Security

One-Time Pad Generator

Generate a random one-time pad and encrypt a message with it using letter addition. The only provably unbreakable cipher when used correctly.

Last reviewed by the Radiatus Cloud team

Generate a random one-time pad and encrypt a message with it.

Need this handled by experts?

Radiatus runs VAPT, managed SOC & security engineering for regulated teams.

Book a free security consult

Generate a one-time pad

The one-time pad is the only cipher proven to be unbreakable, provided its key is truly random, as long as the message, kept completely secret, and never reused. This tool generates a random key, the pad, exactly as long as your letters-only message, and encrypts by adding each pad letter to the corresponding message letter modulo twenty-six. The result is a ciphertext that, without the pad, reveals nothing about the message because every possible plaintext is equally likely.

To decrypt, the recipient subtracts the same pad from the ciphertext, recovering the original message.

Why the rules matter

The one-time pad perfect secrecy depends entirely on following its rules. The key must be generated from genuine randomness, must be at least as long as the message, must be shared only between the two parties, and must be used once and then destroyed. Break any rule, especially reusing a pad, and the security collapses, which is exactly how historically real one-time-pad systems were broken.

This tool demonstrates the principle for learning and short messages, using the browser random generator where available. Distributing a truly secret pad to the recipient is the practical challenge that limits real-world use. All processing happens locally in your browser.

Related tools

  • Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
  • Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
  • Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
  • Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.

Frequently Asked Questions

Why is the one-time pad unbreakable?

With a truly random key as long as the message and used only once, every possible plaintext is equally likely, so the ciphertext reveals nothing.

How do I decrypt the message?

Subtract each pad letter from the corresponding ciphertext letter modulo twenty-six, using the same pad, to recover the original message.

Why must the pad never be reused?

Reusing a pad lets an attacker combine two ciphertexts and recover the messages. One-time use is essential to the pad security.

What is the practical limitation?

Securely sharing a truly random pad as long as every message, and never reusing it, is difficult, which is why one-time pads are rare in practice.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Enter a message to generate a matching random pad and ciphertext.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.