STEGO LAB
Hide secret text inside an ordinary PNG so completely that the picture looks untouched — no metadata, no visible change, nothing to see. Only someone who knows it's there (and has the password) can read it back.
Hide text in a picture
The download is a normal PNG. Post it, email it, host it — the secret rides along.
Read hidden text back
API: POST /api/steg/hide (image, text, password?, bits 1-3, spread) → PNG · POST /api/steg/extract (image, password?, bits?, spread?) → JSON
EXAMPLE FLOW — smuggle a passphrase through a photo wall
- you drop in a vacation photo — the meter says 1920×1080 holds ~777,600 hidden characters. Plenty.
- you type the wifi password
hunter2-sunset-2026, add passwordpeanut, spread randomized, hit Hide. - the site flips the least-significant bits of random pixels — the downloaded PNG looks pixel-for-pixel identical to the original.
- you post the photo publicly. It passes through phones, compressors, screenshots — it's just a picture.
- ally saves it, opens STEGO LAB, drops the file, types
peanut→ the words come back. - stranger drops the same file with no password → noise. Without the key, it's a photo of a beach.
HOW IT WORKS
- Every pixel's color is three numbers. Change the last binary digit of each — changes of ±1 in brightness — and no eye can tell.
- Depth 1 hides ~1 character per 2–3 pixels: invisible and robust. Depth 2–3 packs more but survives re-compression worse.
- Randomized spread scatters your bits across the whole image instead of the top rows — a cropped picture can still give the text back.
- A password encrypts the payload AND seeds the scatter pattern: wrong password yields pure noise, not garbage text.
- Extraction auto-reads the embedded settings — the file knows its own depth and spread. Just drop and go.
- Warning: posting to platforms that re-compress (Instagram, WhatsApp) can damage depth-1 edges — send the file itself, unmodified.
JARGON — hover any chip:
LSB depth spread carrier
FOR AGENTS ?
POST /api/steg/hide image=<png> text=hi [password= bits= spread=]curl -X POST https://dark0rbits.thetempleofdoom.com/api/steg/hide -F [email protected] -F text="wifi is hunter2" -F password=peanutExtract: POST /api/steg/extract (image, password?). Free, 20/min. · spec: /openapi.json · catalog: /llms.txt