Step 1 Make a pair
You are Sam. Press the button; your browser generates two matching halves of one real key pair.
Step 2 Encrypt a note to you
Maya wants to send you something private. She has your public half — the one you hand out — and nothing else. Write what she is sending and encrypt it.
A key this size encrypts at most 190 bytes at a time, so this is a note and not a letter. A byte is a unit of stored data; plain letters take one each, an accented letter takes two and an emoji four, which is why the counter can run ahead of the characters you typed. Real systems get around the limit by encrypting a key rather than a message — that is what HPKE Envelope is about.
Step 3 Open it — and see what opening proves
Three experiments. Guess before each one; being wrong is the fastest way to remember it.
Open it with your private half
Now try the wrong key
Predict first — optional
This makes a second, completely unrelated pair and hands its private half the same encrypted bytes.
And now the part nobody expects
Predict first — optional
Your public half is public, so let somebody else use it. This hands a stranger nothing but your public bytes from Step 1 and lets them encrypt a note of their own choosing. Then you open it with your private half.
Step 4 The same pair, a different job
Step 3 ended with a problem: a note that opens tells you nothing about who sent it. A signature is the answer — and it needs no new keys. Now you are the sender: you sign, and Maya checks.
Predict first — optional
Check it with the public half
Maya checks with your public bytes and nothing else — the same block you could have printed in a newspaper. Then change the note she is checking and watch what happens: edit the box yourself, or let the button change one character for you.
The signature and the signed note are untouched by this box. Editing it moves the document underneath the signature, which is what tampering actually looks like.
Quick check — which half did which job?
What each job does, and does not, establish
| Job | Key used | What it does NOT establish |
|---|---|---|
| Encrypt | The recipient’s public half | Who sent the note |
| Decrypt | The recipient’s private half | Who sent the note |
| Sign | The signer’s private half | Secrecy, or whether the note is true |
| Verify | The signer’s public half | Whose key it is, unless you already know |
Three questions
No score, and nothing is recorded. If one of these is awkward, the explanation is the point.
How this demo checks its own results
Everything above is this page agreeing with itself, which is not worth much alone: a build that got the maths wrong in both directions at once would look just as convincing. So the lab also runs a fixed set of cases published by somebody else, in your browser, on arrival.