age encrypt for YubiKey PIV

Encrypts one secret to the recipients you list below. This page cannot decrypt, makes no network requests and stores nothing.

Recipients

Secret

Output

Decrypt outside the browser: age -d -i IDENTITY-FILE LABEL.age

How this uses a YubiKey

There are two ways to encrypt with a YubiKey. This page does the first and not the second.

PIV, as used by age-plugin-yubikey (this page). The YubiKey holds a P-256 private key in one of its PIV slots. The plugin had the YubiKey generate that key on the device, and PIV has no command to read a private key back out, so it has never left the device. What you paste above, age1yubikey1..., is only the matching public key.

WebAuthn PRF, also called FIDO2 hmac-secret (not this page). Here the browser asks the YubiKey to derive a secret key from a credential, and the YubiKey hands that key to the web page. The page then encrypts and decrypts with it.