We use cookies.This website uses essential cookies to operate core features. With your consent, we also use analytics cookies to understand traffic and improve the service. For more details, see our .
Was this tool helpful to use?
Your feedback helps us make it better
A symmetric encryption and decryption tool based on the CAST-128 algorithm. Supports text and Base64 encoding conversion to ensure secure data transmission.
Block encryption/decryption passed RFC 2144 CAST-128 vectors at three key lengths and one RFC 2612 CAST-256 vector with a 128-bit key (2026-09-30). Limited tests, not a security audit. Key, IV and padding must be selected correctly; ECB/CBC do not authenticate ciphertext and ZeroPadding loses trailing zero bytes. Reference
CAST-128 (CAST5) algorithm, used in PGP and GPG.
Please enter content and click Encrypt/Decrypt.
Overview
Understand what the tool solves, how it works, and the boundaries of its data.
This page handles short text with either CAST-128 (also called CAST5) or CAST-256. They are related designs, but they are not interchangeable: CAST-128 operates on 64-bit blocks, while CAST-256 uses 128-bit blocks. Choose the variant that produced the ciphertext before trying to decrypt it. The RFC specifications also define different key-length sets for the two variants.
The page offers CAST-128 keys of 40, 80 or 128 bits. CAST-256 offers 128, 160, 192, 224 or 256 bits. A key’s bit length is its byte length multiplied by eight. For example, a 10-byte key is 80 bits. With a text key, count the encoded bytes rather than visible characters; non-ASCII characters may occupy more than one UTF-8 byte. Hex and Base64 key entries are decoded to bytes before their length is checked.
Choose ECB or CBC. CBC combines each plaintext block with the preceding ciphertext block and therefore needs an initialization vector (IV); the IV length follows the selected variant’s block size: 8 bytes for CAST-128 or 16 bytes for CAST-256. ECB has no IV. The available padding choices are PKCS7 and ZeroPadding. PKCS7 adds bytes to complete a block, while ZeroPadding adds zero bytes only when a block is incomplete.
The tool displays encrypted bytes in Base64 and hexadecimal. These are printable encodings, not additional encryption. Decryption accepts ciphertext in either encoding and displays the recovered text as well as encoded output fields. RFC 2144 and RFC 2612 provide cipher specifications and reference vectors; selected CAST test vectors were checked for this implementation, which does not establish compatibility for every external mode, padding, key format or ciphertext.
Guide
Follow the workflow and verify inputs and outputs with practical examples.
Choose CAST-128 or CAST-256 to match the source ciphertext. Confirm the key size is one of the options shown for that variant.
Choose Text, Hex or Base64 for the key. The decoded key must have exactly the selected byte length. The generate control can create a random key of that selected size; store it securely if you need to decrypt later.
Use the same mode and padding that were used during encryption. For CBC decryption, enter the original IV using its Hex or Base64 representation. During CBC encryption, the page can generate an IV and show the value used. ECB does not take an IV.
For encryption, enter plaintext as text. For decryption, paste ciphertext and choose Base64 or Hex to match its representation. After processing, copy the Base64 or hexadecimal ciphertext; for decryption, copy the displayed text if that is the intended output.
When recording an encrypted sample, keep the variant, key-size setting, key representation, mode, padding and (for CBC) IV together with the ciphertext. A mismatch in any of these can produce an error or unusable output.
Use cases
See how the tool fits into real work and everyday tasks.
If you have a CAST-encrypted text value and its parameters, reproduce the matching variant, key, mode, padding and IV to see whether the supplied text can be recovered. Treat the result as a compatibility check, not proof that a whole storage or communication system is secure.
For a lesson or test note, compare CAST-128’s 64-bit blocks with CAST-256’s 128-bit blocks and observe how changing the variant changes the parameter requirements. Use non-sensitive sample text and record the settings alongside each output.
When preparing a reproducible example for a colleague, share test data plus the variant, key encoding, mode, padding and CBC IV. The ciphertext string alone does not contain enough information to reconstruct those choices.
Q&A
Find concise answers to common questions and confusing cases.
No. This page offers 40-, 80- and 128-bit keys for CAST-128, and 128-, 160-, 192-, 224- and 256-bit keys for CAST-256. A decryption attempt must use the same variant and key bytes as encryption.
CBC uses an initialization vector for the first block. Supply the same IV used during encryption and encode it as Hex or Base64. Its byte length must match the variant’s block size: 8 bytes for CAST-128 or 16 for CAST-256.
No. Base64 and hexadecimal represent the same ciphertext bytes in printable forms. Select the form that matches the input; encoding does not conceal data or provide integrity protection.
No. On decryption, trailing zero bytes are removed, so the original ending cannot be distinguished from padding. Choose PKCS7 when both sides support it and you need unambiguous recovery of trailing zeros.
Notes
Review scope, result limitations, and important precautions before use.
CAST is a legacy cipher family. This page implements only ECB and CBC and provides no authentication tag or separate integrity check. NIST describes these as confidentiality modes; a plausible-looking decrypted string does not show that ciphertext was authentic or unchanged. Do not use this page alone to protect high-value or production secrets, and do not treat the selected-vector checks as a security audit or a guarantee of interoperability with every external implementation.
ZeroPadding cannot preserve trailing zero bytes. CBC requires the exact original IV as well as the matching cipher, key and padding. Keep keys and IVs confidential or managed according to your established process; do not paste sensitive production material into a tool unless its data handling is suitable for your requirements. For a new system, use a current, reviewed encryption design that includes authentication and key management.
Related
Discover related tools, collections, and available API capabilities.