This article explains how to decrypt a previously encrypted field manually when a Mass Decryption is not available in the instance.


This procedure needs the admin user to create a new field in the table to copy the encrypted values. . Assuming the numbers of the records are unique, you can write a script to copy all the record numbers in the particular and encrypted field's display value(It will work only if you are logged in as a user with Encryption Context) to an EXCEL file. Once you do that, you can create a new string field for the table in the instance and copy the values to the new field using Import Sets ( 

Following is an example script that you can use to copy the field values to an Excel file. Please test and modify to your business requirements to copy and download the data. Please run and test the code properly preferably on an OOB instance before running this in your instances and seek help from your developers when you try the script. 

Sample Script

var output = "Number,Encrypted Field"; //header for csv file 
var table = "table_name"; 
var recordId = ""; //using for attachment file 
var gr = new GlideRecord(table); 
//gr.addEncodedQuery("sysID="); //Test if it works with a particular SysID 

var count = 0; 
while ( { 
output += "\n" + gr.number + "," + gr.ENCRYPTED_FIELD.getDisplayValue(); //Enter encrypted field name 
if (!recordId) { 
recordId = gr.sys_id; 


function writeAttachmentFile(data) { 
var attachment = new Attachment(); 
var attachmentRec = attachment.write(table, recordId, "exportEncrypted.csv", "text/csv", data); 

Once you run your script in the Scripts - Background, you can navigate to sys_attachment.list to download exportEncrypted.csv file. You can use import sets to Map and import the data to your instance(to your newly created String Field).

Applicable Versions

All available versions


Article Information

Last Updated:2019-08-02 20:49:57