ROT13 is a self-inverse text transform that rotates every ASCII uppercase letter A–Z and every ASCII lowercase letter a–z by exactly 13 positions in its own alphabet, leaving every other character in your input untouched. In a CyberChef-style workflow, the operation appears as a single recipe step that takes plain text on the left, applies the rotation, and emits the result on the right. A focused browser ROT13 decoder reproduces that behavior without the rest of the CyberChef stack, so paste, apply, and copy replace the recipe builder entirely, and feeding the result back through the same action returns the original string exactly. Because the ASCII alphabet has 26 letters, shifting by 13 is its own inverse: A maps to N, N maps to A, a maps to n, n maps to a, and so on through Z and z. The transform deliberately does nothing to digits, punctuation, spaces, line breaks, accented Latin letters, Greek, Cyrillic, Arabic, CJK characters, combining marks, or emoji, which is why a ROT13 stage can sit in a CyberChef recipe next to Base64, hex, or XOR without disturbing the surrounding steps.

rot13 decoder cyberchef
ROT13 Decoder Online: A CyberChef-Style Browser Tool

How to Apply and Reverse ROT13 in Your Browser

The fastest path from "I have some text" to "I have the ROT13 form of it" mirrors the way CyberChef users build a one-step recipe, but skips the recipe builder entirely. Open the ROT13 Encoder Decoder tool, paste your text, hit the action, and read the transformed output next to a count of the ASCII letters that were actually rotated.

  1. Paste text containing any mix of ASCII letters and other characters. You can include digits, punctuation, whitespace, accented characters, CJK strings, emoji, and the NUL byte; they all pass through exactly as written.
  2. Apply ROT13 and review the transformed output plus the count of changed ASCII letters. The count tells you how many A–Z or a–z code units were mapped, which is also the number of code-unit positions whose value changed.
  3. Copy the result, or apply ROT13 to that result again to recover the original text. Because the operation is its own inverse, running it a second time is exactly the way you "decode" ROT13 output.

Editing the source or running a new transform clears the previous result, any error message, the statistics, and any in-flight copy confirmation, so the displayed output always reflects the current input. If your paste buffer contains more than 1,000,000 UTF-16 code units, the tool refuses the input with an explicit message before any transformation runs, and empty input is rejected up front. Non-empty content that contains no ASCII letters is a perfectly valid transformation with a changed count of zero, which is the right answer when you are confirming that ROT13 had nothing to rotate.

From CyberChef's Recipe View to a Single-Purpose Tool

CyberChef earns its reputation by chaining many operations together: Base64, hex, regex, XOR brute force, JWT inspection, and ROT13, all inside one workflow pane. For a CTF challenge or a quick decode, that power is overkill when the only step you actually need is ROT13. A dedicated online ROT13 decoder collapses the recipe builder, the operation search box, and the output pane into a single page where paste, apply, and copy is the entire workflow. Nothing is sent over the network; the transform, the changed-letter count, and the clipboard preparation all happen in the current browser tab.

AspectCyberChef RecipeFocused Browser ROT13 Decoder
SetupOpen the recipe builder, search "ROT13," drag the operation into the chainOpen a single page with the ROT13 action ready
Input handlingAny string accepted by the active recipePaste any mix of ASCII letters and other Unicode; empty input is rejected
Mapping scopeASCII A–Z and a–z rotated by 13; everything else preservedIdentical: ASCII A–Z and a–z rotated by 13; everything else preserved
Changed-character feedbackOutput byte length visible in the output paneDedicated count of rotated ASCII letters next to the output
ReversingApply ROT13 again to the outputApply ROT13 again to the output
Network useLocal browser app, no upload of recipe dataLocal browser tab, no upload of input, output, or clipboard content
Best fitMulti-step decoding chains with Base64, hex, XOR, regexPure ROT13 work or a quick sanity check after a CyberChef step

The two approaches are not rivals; they are different points on the same spectrum. When a CTF chain ends at ROT13 and you want to confirm what CyberChef produced, a dedicated tool gives you the same alphabet mapping in a smaller surface area, which is also useful when you are on a phone, in a locked-down browser, or simply do not want to load a full CyberChef bundle for a single step.

Exactly Which Characters Get Rotated

ROT13 is deliberately narrow, and that narrowness is the source of its predictability. The transform matches only ASCII uppercase A through Z and ASCII lowercase a through z. For every matched uppercase letter, the tool subtracts 65, adds 13 modulo 26, and adds 65 back; for every matched lowercase letter it subtracts 97, adds 13 modulo 26, and adds 97 back. The two alphabets are rotated independently, so uppercase input always yields uppercase output and lowercase input always yields lowercase output. A becomes N, N becomes A, Z becomes M, a becomes n, n maps to a, z becomes m, and every other matched letter follows the same pattern around the alphabet ring.

Everything else is preserved exactly. Digits, punctuation, spaces, tabs, line breaks, and the NUL byte appear in the output in the same position with the same value. Accented Latin letters such as é, ç, or ñ are not ASCII A–Z or a–z, so they pass through byte for byte. A combining sequence such as the lowercase letter e followed by U+0301 changes only the ASCII e, leaving the combining acute mark in place; the result is therefore p followed by U+0301, not "é rotated." The same logic preserves Greek, Cyrillic, Arabic, and CJK strings, and the same logic preserves emoji as complete surrogate pairs. As a concrete illustration, the string "café" becomes "pnsé" because c, a, and f are ASCII letters while é is not.

The output length always equals the input length in UTF-16 code units, because each rotated ASCII code unit is replaced by exactly one ASCII code unit and every other code unit is retained. The changed-letter count reported next to the output is therefore also the count of code-unit positions whose value changed, and an emoji surrogate pair contributes zero to that count because neither half is an ASCII letter.

ROT13 Is Reversible Encoding, Not Encryption

ROT13 has no key, applies the same public substitution to every input, and is reversed instantly by anyone who recognizes it. That makes it useful for the same casual reasons CyberChef users have relied on for years: hiding a plot spoiler behind a one-liner, preventing an accidental glance at a puzzle answer, or keeping a single line of text out of an automated scanner's keyword list. RFC 1855 places the transform in that casual-obfuscation category and notes it as a readability switch, not a confidentiality mechanism.

The Python standard library documents the same scope. The codecs documentation describes rot_13 as a string-to-string text transform, and the rot_13 codec source provides a direct alphabet-table cross-check that matches the two ASCII ranges handled by this tool. ROT13 is not password protection, not authentication, not integrity protection, not hashing, and not access control. If you need a configurable ASCII shift with case preserved, use a Caesar cipher tool; if you need actual confidentiality, use an audited cryptographic system such as AES with a real key.

Common CyberChef-Style Tasks You Can Do Online

A focused ROT13 decoder covers the everyday cases where CyberChef users reach for the ROT13 operation, without dragging in the rest of the toolbox. You can paste a spoiler-heavy paragraph and replace it with its ROT13 form so readers have to opt in to see the reveal. You can take the output of a Base64 or hex stage in a CyberChef recipe and run it through ROT13 as a quick sanity check before re-encoding. You can rotate a single word to confirm that the alphabet mapping looks the way you remember (A ↔ N, B ↔ O, and so on), and you can apply the transform twice to verify that the round trip is byte-for-byte stable even when the input contains digits, punctuation, accented letters, or emoji.

Because the operation is its own inverse, you can also use the same tool to decode ROT13 text by pasting it in and applying the action again; there is no separate "decode" button, and that matches the convention the CyberChef ROT13 operation uses. The changed-letter count next to the output tells you whether any rotation actually happened at all: a non-empty string made entirely of digits, punctuation, and emoji will report a count of zero, while a string with even a single ASCII letter will report one or more. That count is a cheap, reliable way to distinguish "ROT13 did something" from "ROT13 had nothing to do here," which is often the first question you ask when stepping through an unknown encoded blob.

For a deeper look, see How Do You Use a ROT47 Encoder Decoder Correctly?.

For a deeper look, see Strict UTF-8 Encoder / Decoder: Hex, Decimal, and Binary Bytes.