Four-square cipher encoder and decoder
This four-square cipher tool encrypts or decrypts text with the classical digraph substitution invented by Félix Delastelle.
Run — free
Two keywords fill the upper-right and lower-left 5×5 squares while the upper-left and lower-right squares hold a fixed twenty-five letter alphabet where J is mapped to I. Plaintext is processed in letter pairs: the first letter of each digraph is located in the upper-left square and the second in the lower-right square; ciphertext letters are read from the keyed squares at the complementary row and column, so the mapping depends on both keywords at once rather than a single repeating stream. Non-letter characters are stripped before pairing, an odd letter count is padded with X, and the result is returned as continuous uppercase letters together with the four flattened squares for inspection. The engine is fully deterministic with no network calls, no random salts, and no date-dependent shortcuts, so classroom goldens and CTF fixtures stay bitwise stable. Use it free in the browser for history-of-crypto lessons, digraph puzzle design, and reversible worksheet keys, or call the API at $0.002 per successful request when pipelines need reproducible four-square transforms without re-implementing the square layout.
How to use it
Enter your values in the form above. The tool checks them before calculating and shows the result on the same page.
Check your inputs
Use the labels and units shown next to each field. If something is missing or outside the allowed range, the page points to the field to fix.
Use it again or automate it
Use the browser tool for individual checks and the API when you need the same capability in an automated workflow.
What you can do with it
Get an answer now
Enter one set of values and see the result without building a spreadsheet or script.
Compare scenarios
Change one value at a time and rerun the calculation to understand what affects the result.
Automate repeated work
Use the API when the same calculation needs to run inside your product or workflow.
FAQ
How do I use this capability?
Complete the fields above and run it on this page. The form highlights anything that needs attention.
For developers — API access
Everything on this page is available programmatically. This section is for teams who want to wire it into their own systems; everyone else can just use the tool above.
API endpoint
Prefer to automate it? One authenticated POST creates the task; the result comes back by webhook or a signed link. The same capability also runs here on the web, by email and from Telegram — and soon from our app too.
Call it from your stack
curl -X POST https://api.kit.forhosting.com/enc/four-square \
-H "Authorization: Bearer $KIT_KEY" \
-H "Content-Type: application/json" \
-d '{"text":"HELPME","key1":"EXAMPLE","key2":"KEYWORD"}'const res = await fetch("https://api.kit.forhosting.com/enc/four-square", {
method: "POST",
headers: {
"Authorization": `Bearer ${process.env.KIT_KEY}`,
"Content-Type": "application/json"
},
body: JSON.stringify({
"text": "HELPME",
"key1": "EXAMPLE",
"key2": "KEYWORD"
})
});
const { task_id } = await res.json();import os, requests
res = requests.post(
"https://api.kit.forhosting.com/enc/four-square",
headers={"Authorization": f"Bearer {os.environ['KIT_KEY']}"},
json={
"text": "HELPME",
"key1": "EXAMPLE",
"key2": "KEYWORD"
},
)
task_id = res.json()["task_id"]<?php
$res = file_get_contents("https://api.kit.forhosting.com/enc/four-square", false, stream_context_create([
"http" => [
"method" => "POST",
"header" => "Authorization: Bearer " . getenv("KIT_KEY") . "\r\nContent-Type: application/json",
"content" => '{"text":"HELPME","key1":"EXAMPLE","key2":"KEYWORD"}',
],
]));
$task = json_decode($res, true);body := bytes.NewBufferString(`{"text":"HELPME","key1":"EXAMPLE","key2":"KEYWORD"}`)
req, _ := http.NewRequest("POST", "https://api.kit.forhosting.com/enc/four-square", body)
req.Header.Set("Authorization", "Bearer "+os.Getenv("KIT_KEY"))
req.Header.Set("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)Example request
{
"text": "HELPME",
"key1": "EXAMPLE",
"key2": "KEYWORD"
}Example response
{
"task_id": "tsk_a1b2c3d4e5f6a1b2c3d4e5f6",
"type": "enc.four_square",
"status": "queued",
"_links": {
"result": "/tasks/tsk_…/result"
}
}The API is asynchronous: the call returns a task_id immediately and the result arrives by webhook. Polling is capped at 1 req/s per task.
Pricing
Published price — no tokens, no invented credits. A failed task is never charged.
Errors
| HTTP | Code | Meaning |
|---|---|---|
401 | unauthorized | Missing or invalid API key. |
402 | insufficient_balance | Your balance doesn't cover the task price. |
404 | unknown_type | That task type doesn't exist. |
429 | rate_limited | Too many requests. Use the webhook instead of polling. |