Hybrid encryption in a single HTML file. No server, no dependency, no network call — the browser's own crypto engine and nothing else.

A 4096-bit RSA-OAEP key can encrypt about 446 bytes. That's a sentence, not a document. So RSA never touches the message at all — it encrypts a key, and that key encrypts the message.
New random key per message. It exists for one encryption and is never reused, so a compromised message compromises nothing else.
Fast, handles any size, and GCM is authenticated — tampering is detected on decrypt rather than silently producing garbage.
256 bytes of key material, comfortably inside RSA's limit. This is the only thing the asymmetric layer ever sees.
The wrapped key, the IV, and the ciphertext travel as one blob. Only the private key holder can unwrap step three and therefore step two.
The console above does all four steps for real, in your browser, using crypto.subtle. The ciphertext it prints is the actual output — not a stand-in.
Every design decision follows from a single rule: someone should be able to read the whole thing before using it, and verify there's nothing else in it.
No npm tree, no CDN, no crypto library to audit. Web Crypto is the browser's, already reviewed by people better at this than either of us.
Nothing is fetched and nothing is posted. Open devtools, watch the network tab stay empty, and you've verified the core claim yourself.
Keys live in memory for the tab's lifetime. Close it and they're gone — which is a feature and an obvious footgun at the same time.
One file you can scroll to the bottom of. That's the entire security argument, and it only works if it stays small.
Getting a public key to the other person safely is the actual hard problem in all of cryptography, and this file doesn't touch it.
Encryption proves nobody else can read it. It does not prove who sent it. That needs signatures, which is a separate mechanism.
If the page is served over the network, whoever serves it can change it. Local file or nothing.
For anything that genuinely matters, use age or GPG. This is a working demonstration of the primitives, not audited infrastructure.
A crypto tool that overstates itself is worse than no tool. The limits above belong in the interface, not in a README nobody opens.