Open it without us
Last updated 26 September 2026
What's inside a capsule
- Network: drand quicknet, chain hash
52db9ba70e0cc0f6eaf7803dd07447a1f5477735fd3f661792ba94600c84e971 - Format: an
agefile whose key is timelocked with atlockstanza (-> tlock ROUND 52db9ba7…). - Link (v2):
/o#v2.LABEL.CIPHERTEXT.CHECK.LABELis the title and names.CIPHERTEXTis a compact encoding of the same age file: the round, the raw tlock IBE ciphertext of the file key, the age header MAC, and the age payload.CHECKis a 6-character checksum so a cut-off link is obvious. Links made before this (v1.LABEL.CIPHERTEXT) still open —CIPHERTEXTthere is the raw age file in base64url. - .seal file: JSON with an
armoredfield holding the standard armored age text (-----BEGIN AGE ENCRYPTED FILE-----). That text is whattleand Timevault decrypt. It does not use the compact link encoding. - After opening a current capsule you get raw deflate of
{"v":1,"body":"your letter","sealedAt":"2026-…Z"}. Inflate it (see below) and readbody. Capsules sealed before this change decrypt straight to that JSON.
Step 1 — get the armored text
From a .seal file: open it in any text editor and copy the armored value, or run:
jq -r .armored letter.seal > letter.ageFrom a link, paste it below. This converter runs entirely in your browser and makes no network requests.
A v1 link can also be turned into letter.age in a terminal (Python 3). Take the part after the last dot:
python3 -c "import base64,sys;s=sys.argv[1];open('letter.age','wb').write(base64.urlsafe_b64decode(s+'='*(-len(s)%4)))" CIPHERTEXTv2 links are shorter than that raw age file, so use the converter above for them. It rebuilds the age header exactly.
Step 2a — open with the tle command-line tool
tle is drand's reference implementation of tlock, written in Go. Install it:
go install github.com/drand/tlock/cmd/tle@latestOn or after the unlock date, decrypt (armored or binary input both work):
tle --decrypt --chain 52db9ba70e0cc0f6eaf7803dd07447a1f5477735fd3f661792ba94600c84e971 letter.ageIf the default relay is down, add --network with any of: https://api.drand.sh/, https://api2.drand.sh/, https://api3.drand.sh/, https://drand.cloudflare.com/. Before the date, tle refuses with “too early to decrypt” — the same answer Ripenote gives, for the same mathematical reason.
If the decrypted bytes start with {, that is the letter JSON. Otherwise they are raw deflate (no zlib header). Inflate them:
tle --decrypt --chain 52db9ba70e0cc0f6eaf7803dd07447a1f5477735fd3f661792ba94600c84e971 letter.age | python3 -c "import sys,zlib; sys.stdout.buffer.write(zlib.decompress(sys.stdin.buffer.read(), -15))"Step 2b — open with Timevault (in a browser)
Timevault is drand's open-source web app for timelock encryption, built on the same tlock-js library Ripenote uses. Paste the armored text (starting with -----BEGIN AGE ENCRYPTED FILE-----) into its decrypt box on or after the unlock date.
Step 2c — write your own
tlock has compatible implementations in Go (drand/tlock), TypeScript (drand/tlock-js) and Rust (tlock-rs). Point any of them at the quicknet chain hash above and decrypt the age file.
Why we publish this
A time capsule should outlive the company that made it. We'd rather you trust the maths than trust us, so we make sure you never have to.