Join the Official Discord

Autokey cipher

Enter the primer word, or choose “Find the key” and we'll recover it.

Mode
Result

Likely keys

    How the autokey cipher works

    Autokey is Vigenère with a key that never repeats. You choose a short primer, and once that runs out the message itself becomes the key. With primer QUEEN, the message ATTACKATDAWN is encrypted with the key QUEENATTACKA: the primer, then the start of the message.

    Decoding works the same way in reverse. The primer decodes the first few letters, those letters decode the next stretch, and so on down the message. One wrong letter in the primer garbles every letter that depends on it, which is why a near-miss key reads as nonsense rather than nearly-English.

    Why it was stronger than Vigenère

    Blaise de Vigenère described this one himself in 1586. Because the key doesn't repeat, there's no period to find, so the Kasiski test and the index-of-coincidence trick that break ordinary Vigenère don't apply.

    Breaking it without the primer

    It still has a weak spot. If the primer is L letters long, every plaintext letter depends only on the ciphertext letter and the plaintext letter L places earlier. The message therefore splits into L separate chains, each controlled by one primer letter with just 26 possible values. “Find the key” solves each chain against English letter frequencies for every primer length up to 12, then polishes the best few against the full text.

    Step-by-step guide How to solve a Autokey Cipher by hand, with a worked example

    Questions

    How does the autokey cipher work?

    It's Vigenère, except the key doesn't repeat. A short primer word starts the key, and the message itself continues it. With primer QUEEN, ATTACKATDAWN is encrypted with the key QUEENATTACKA.

    Why is autokey harder to break than Vigenère?

    The key never repeats, so the repeated-chunk trick that breaks Vigenère doesn't work. It still has a weakness: each letter depends on the plaintext a fixed distance back, which is how the key finder here recovers the primer.

    How long can the primer be?

    Any length for encoding. The key finder tries primers up to 12 letters, which covers almost every puzzle.

    More cipher tools

    See all cipher tools →