Have the keyword? Decode instantly. No keyword? Choose “Find the key” and we'll recover it.
Write a keyword under the message, repeating it as often as needed. Each key letter says how far to shift the letter above it: A is no shift, B is one, Z is twenty-five. It's a Caesar cipher with a different shift for each letter.
With the key LEMON, ATTACK AT DAWN lines up against LEMONL EM ONLE and encodes to LXFOPV EF RNHR. The two T's in ATTACK come out as X and F. That's the cipher's strength: one plaintext letter can turn into many different cipher letters.
It needs some text to work with. Ten letters of ciphertext per key letter is a good rule of thumb. If the top answer still looks wrong, the cipher may be a cousin like Beaufort or autokey, or not polyalphabetic at all. The cipher identifier can help you check.
Choose “Find the key”. The tool tests every key length up to 20, splits the message into that many columns, and works out each column's shift from its letter frequencies. It then ranks the candidate keys by how English each decryption reads.
As a rough rule, at least ten times the key length. A 5-letter key needs about 50 letters of ciphertext. Shorter messages can still crack, but the top guess is less reliable.
Not here, and not in most puzzles. The key only steps forward on letters, so spacing and punctuation pass through unchanged.
Each letter is shifted by a different amount depending on its position under the key, so the same plaintext letter becomes different ciphertext letters. That flattens the letter frequencies that give a Caesar or substitution cipher away.