CipherTools
ToolsBlogsSnippets
ToolsBlogsSnippets
  • MD5 Text Hash
  • MD5 File Hash
  • BKDR Text Hash
  • BKDR File Hash
  • SHA-256 Text Hash
  • SHA-256 File Hash
  • SHA-512 Text Hash
  • SHA-512 File Hash
  • SHA-3 Text Hash
  • SHA-3 File Hash
  • SHAKE Text Hash
  • SHAKE File Hash
  • Argon2 Text Hash
  • Argon2 File Hash
  • CRC Text Checksum
  • CRC File Checksum
  • HMAC Text Generator
  • HMAC File Generator
  • BLAKE2 Text Hash
  • BLAKE2 File Hash
  • BLAKE3 Text Hash
  • BLAKE3 File Hash
  • CityHash Text Hash
  • CityHash File Hash
  • FarmHash Text Hash
  • FarmHash File Hash
  • xxHash Text Hash
  • xxHash File Hash
  • MurmurHash2 Text Hash
  • MurmurHash2 File Hash
  • MurmurHash3 Text Hash
  • MurmurHash3 File Hash
  • bcrypt Text Hash
  • bcrypt File Hash
  • scrypt Text Derivation
  • scrypt File Derivation
  • AES Encryption and Decryption
  • AES File Encryption
  • AES File Decryption
  • AES-GCM Encryption and Decryption
  • ChaCha20-Poly1305 Text
  • ChaCha20-Poly1305 File Encryption
  • ChaCha20-Poly1305 File Decryption
  • DES Encryption and Decryption
  • DES File Encryption
  • DES File Decryption
  • RSA Encryption and Decryption
  • RSA File Encryption
  • RSA File Decryption

Asymmetric encryption · RSA

RSA-OAEP Text Encryption and Decryption Online

Convert plaintext to ciphertext (and back) with RSA-OAEP. Configure key sizes, hash algorithms, and output encodings—all in a single browser session.

Asymmetric encryption · RSA-OAEP

Encrypt or decrypt text with RSA-OAEP by supplying PEM-encoded keys. Generate modulus-sized key pairs with selectable hash algorithms, then copy ciphertext or plaintext back to your clipboard without external servers.

RSA-OAEP ciphertext is shown as Base64 depending on the encoding selection.

Keys export as PEM, ready for secure backend signatures or company-wide deployments.

Understanding RSA-OAEP

RSA-OAEP is just plain RSA wrapped with the Optimal Asymmetric Encryption Padding (OAEP) method, which adds a hash and mask-generation layer so reactions to repeated encryptions become indistinguishable. RSA without padding is deterministic and hard to secure, so OAEP is the standard choice for most encrypted messages today.

Quick OpenSSL reference

Below are the common commands for generating a RSA-OAEP key pair and for encrypting/decrypting small text payloads while piping Base64 so the ciphertext stays copy-friendly.

Generate keys

Key material
openssl genpkey -algorithm RSA -pkeyopt rsa_keygen_bits:2048 -out private.pem
openssl rsa -pubout -in private.pem -out public.pem

Encrypt & decrypt text

The snippet below echoes plaintext into openssl pkeyutl, encrypts with RSA-OAEP + SHA-256, Base64-encodes the ciphertext for easy transport, then decodes it back into a binary blob and decrypts with the private key to recover the original text.

OAEP workflow
echo "Encrypt me" | openssl pkeyutl -encrypt -inkey public.pem -pubin \
  -pkeyopt rsa_padding_mode:oaep -pkeyopt rsa_oaep_md:sha256 | base64 > cipher.base64
base64 -d cipher.base64 | openssl pkeyutl -decrypt -inkey private.pem \
  -pkeyopt rsa_padding_mode:oaep -pkeyopt rsa_oaep_md:sha256 > recovered.txt

Why ciphertext changes every time

RSA-OAEP purposely mixes randomness into every encryption via the mask generation function (MGF) and hash that compose the OAEP padding. Even if you encrypt the same plaintext with the same public key repeatedly, the random seed inside OAEP forces each ciphertext to look different. This property is essential for semantic security and prevents attackers from spotting repeated messages.

© 2026 CipherTools. All computations run locally in your browser.