Enter the keyword to build the 5×5 square, then encode or decode. Every pair is shown.
Playfair encrypts letters in pairs, not one at a time. That flattens the letter frequencies a simple substitution leaves behind, and it's why the British used it as a field cipher into the First World War. Charles Wheatstone invented it in 1854. It's named after Lord Playfair, who promoted it.
Write the keyword into a 5×5 grid, skipping any letter you've already used, then fill the rest of the grid with the remaining letters in order. There are only 25 cells, so I and J share one. The tool draws the square for your keyword and highlights the letters that came from it.
Break the message into two-letter pairs. If a pair would be a doubled letter, put an X between them: BALLOON becomes BA LX LO ON. If one letter is left over at the end, pad it with X.
Decoding runs the same rules backwards: left instead of right, up instead of down. Rectangles work the same both ways. The “Pair by pair” strip under the tool shows each step.
An even number of letters, no J anywhere, and no pair that's the same letter twice. Ciphertext is often written in pairs as well. Breaking Playfair without the keyword is much harder than breaking a Caesar or Vigenère cipher, so in a puzzle the keyword is usually hidden somewhere else. Look for it.
The keyword, followed by the rest of the alphabet, fills a 5×5 square with I and J sharing a cell. The message is split into pairs. Pairs on the same row shift right, pairs in the same column shift down, and anything else swaps to the other corners of its rectangle.
Playfair can't encode a pair of identical letters, so an X goes between them (BALLOON becomes BA LX LO ON), and another X pads an odd-length message. Read past the X's when you decode.
The square only has 25 cells, so J is merged with I. A decoded I may have been a J.
Even number of letters, no J, and no pair (letters 1–2, 3–4, …) made of the same letter twice. The cipher identifier checks for all three.