00 The key, found by others
The sibling volume, Barb.lat. 6956, holds seventy ciphered sheets of the same nunciature for May to August 1628 (DECODE R215–R285 and R318). Its key was recovered in March 2018 by Norbert Biermann and, independently, Thomas Bosbach. Their two keys, a merged key and a sample decryption are filed on DECODE as documents attached to the first ciphertext record, R215, not as a key record. That is why this project's metadata harvest never saw them. DECODE still lists all twenty-eight 6960 records as “Non-decrypted”.
The system:
- Two-digit homophones for the letters: a = 00, 02, 20; e = 09, 30, 90; i = 05, 40, 50; o = 03, 07, 70; and so on.
- Two-digit groups for syllables and short words: 47 che, 52 con, 57 per, 69 di, 73 la, 93 to.
- Three-digit nomenclator groups from 200 to 999 for names and titles: 360 Duca di Mantova, 460 Imperatore, 670 Sua Maestà, 925 Spagna.
- The single digits 1 and 8 as nulls, mostly at word boundaries.
- Doubled letters are often written once, so 33 can stand for d or dd.
Applied to DECODE’s transcriptions of all twenty-eight 6960 records, dividing the digit stream into one-, two- and three-digit units by dynamic programming, the key gives running Italian in every record. R286 opens ho riceuto la risposta datami in scritto, the first words of Kiewning’s Nr. 153. About 2,000 nomenclator groups resolve from the 6956 key. About 1,750 three-digit groups do not appear in it; they are presumably names and titles particular to 1629, and they stay open. Some 200 digits fit no code, which is consistent with slips in the volunteer transcription. The unedited output is in the repository (pallotto1629/key6956/decrypt_6960.txt).
The key also explains why every attack below failed. A null or a three-digit group shifts the phase of every two-digit code after it, so no fixed-width alignment can survive more than a few words. That is where the first-pass crib match stopped: the 8 after ho had been taken as the first digit of a two-digit code. The long repeated digit strings that section 04 reports are the nomenclator and syllable groups, written the same way every time.
01 The volume and the twenty-eight ciphertexts
Barb.lat. 6960 is on DigiVatLib at digi.vatlib.it/view/MSS_Barb.lat.6960, 194 pages, with an IIIF manifest. It is an old bitonal microfilm scan and the image service’s own info.json gives a maximum of 748 × 1088 pixels per page; anything larger the server returns is an upscale of that. At that size a figure is about ten pixels wide. DECODE, however, holds its own scans of the same leaves at 1491 × 2066 (four times the pixel area) behind its login. Anyone transcribing this manuscript should work from those, not from DigiVatLib’s.
DECODE’s records R286–R313 are the twenty-eight ciphered passages; R315 is the volume as a whole, described there as “mixed ciphertext and cleartext”. Each record’s note gives its page range in the same DigiVatLib pagination, so DECODE page n is canvas n. The ranges run from pp. 5–6 to pp. 192–193, and the volume’s own title describes the ciphers of Pallotto dal 4 agosto al 29 settembre 1629, though the records carry dates as late as 29 November.
The cipher sheets are written across the full width of the page in a dense unbroken stream of figures, about thirty lines to the page and some sixty-six figures to the line. The clear pages are written quite differently, in a narrow column on the right of the leaf with a wide margin. The two alternate through the volume.
Transcriptions of all twenty-eight were made for DECODE by volunteers in 2019 and 2020 and are downloadable as DOC_R*.txt. They record the figures one digit at a time, so the manuscript’s (decorative and irregular) grouping is lost. Measured, they come to 112,805 digits; the shortest is R308 at 854, the longest R306 at 9,332, and R286, the one worked in detail here, has 3,573.
02 The contents, printed in 1897
The relevant edition is Hans Kiewning (ed.), Nuntiaturberichte aus Deutschland nebst ergänzenden Aktenstücken. Vierte Abteilung: 17. Jahrhundert, Band 2: Nuntiatur des Pallotto 1628–1630, 2: 1629 (Berlin 1897). It is on archive.org as item 4-2_20200807, in full text.
Kiewning works from the copies received in Rome, ASV, Nunz. di Germania 119, and heads each ciphered despatch dechiffr. with the date the Roman office deciphered it: Nr. 153 is “Pallotto an Barberini, 1629 August 4, dechiffr. 22. August”. What he prints is therefore the contemporary decipherment. He gives the substantive passages in Italian verbatim and summarises the rest in German regesta, so the coverage is close to complete.
Two checks tie the register to the edition.
The 4 August despatch. The cipher on pp. 5–6 is headed Di Vienna 4 di Agosto, which is Nr. 153. The clear pages around it are the register’s own fair copy of the despatch, written apart from the cipher, and they run straight through the cipher sheet: p. 4 ends … non haver facoltà di accettar altro partito, che’l proposto in and p. 7 resumes nome del suo Rè. That sentence is Kiewning’s Nr. 153 word for word.
The enclosure. Page 13 is the paper Kiewning prints as Nr. 153, Beilage II, Propositione P. Valeriano per Sabran (his source: Bibl. Barber. LXIX 60 fol. 122). The manuscript reads, and the edition prints:
… il quale aggiunse di più, che fatta la pace, quando S. S.tà, come padre comune, proponga una lega et unione di questi eserciti, affine di abbatter il Turco commune nemico del nome christiano, che S. M.tà mandaria plenipotentiarii in Italia, acciò N. S.re potesse concludere così gran negotio, con che il demonio resteria ingannato e burlato.
What the ciphers hide, then, is the business of the Mantuan succession crisis in the second half of 1629: Pallotto’s attempts, working through the Capuchin P. Valeriano Magno and the imperial minister Eggenberg (Echembergh in the despatches), to mediate between the Emperor and the French envoy Sabran over Casale and Monferrato, the civil rather than armed possession of the duchies, the withdrawal of the French from Susa and the imperial troops from the Grisons, and, behind it, the fear that the real object was to humble Venice and restore imperial authority in Italy.
03 The attacks made before the key was known
The figures are numeric only, written without separators. Across all twenty-eight ciphertexts the digit frequencies are uneven (0 at 16.1 per cent, 4 at 4.8 per cent), and adjacent digits carry about 0.18 bits of mutual information, so the stream is structured. The attacks below did not find the structure.
The code width does not show. For a fixed-width numeric code one phase should stand out from the others. None does. Taking the twenty-eight ciphertexts together, the index of coincidence of two-digit codes is 0.01462 at phase 0 and 0.01466 at phase 1, and the digit distributions at even and odd positions agree to within 0.2 per cent at every digit. Three-digit codes behave the same way at all three phases.
A crib aligns for twenty-seven letters, then fails. With the plaintext of Nr. 153 in hand, the opening of R286 aligns exactly, as two-digit codes, for twenty-seven letters:
55 70 83 65 03 29 00 69 38 73 11 36 50 23 22 07 92 20 86 72 52 06 38 97 12 33 23
H O R I C E V U T A L A R I S P O S T A D A T A M I I
The assignments repeat: 38 occurs twice and is T both times, 23 occurs twice and is I both times, which by chance would happen about once in 180 tries. The twenty-eighth code conflicts, and from there nothing is consistent. A banded dynamic-programming aligner over the whole despatch, allowing two-digit codes plus one- and three-digit resynchronisation for transcription slips, and iterating the code table to convergence against a hand-corrected 3,359-letter crib, reached about 55 per cent code-to-letter consistency, above the 20 per cent a wrong alignment gives and below what a recovered key gives.
Ciphertext-only search fails. Fixed-multiset simulated annealing over the hundred two-digit codes, on 5,000 codes of text, scored by a space-free Italian five-gram model built for this from the repository’s clean Italian corpora (12.0 million characters), settles at −3.54 log-probability per character where real Italian of the period scores about −1.5. A syllabic model of the same codes (each two-digit group standing for one to four letters) was tested against the known plaintext and collapsed back to single letters for every well-attested code, so no syllable table was found.
The 55 per cent is not a partial key. A held-out test shows this. Learn the table on the first 55 per cent of R286 against the crib, freeze it, then align the remaining digits to the remaining crib and count confirmations (cases where the code was already in the table and agrees). Against eight controls that keep the table but shuffle the letters among the codes:
| confirmations per letter | DP score | |
|---|---|---|
| key learned from the first half | 0.355 | −3266 |
| shuffled controls (mean of eight) | 0.359 | −3313 |
No separation. The same test on a “two-digit codes plus nulls, no digit slips” model gives 0.440 against a control mean of 0.431, again no separation. The consistency figure is the aligner fitting the crib, and any partial key read off it would have been an artefact.
The positive control. Encipher the same crib with a random two-digit homophonic key, damage the digit stream with single-digit insertions and deletions at a chosen rate, and run the identical learner. The fraction of the true key it recovers:
| digit error rate | key recovered |
|---|---|
| 0 % | 100 / 100 |
| 0.5 % | 87 / 100 |
| 1.7 % | 7 / 100 |
| 4 % | 19 / 100 |
The method works on synthetic text; it needs a transcription accurate to better than about half a per cent of digits. Above roughly one per cent a two-digit key cannot be recovered from this much text even with the plaintext in hand, because every inserted or dropped digit flips the code phase for everything after it. That also explains why no phase preference shows in the statistics above: slips scattered through thirty lines randomise the phase across the corpus.
The run-length test. A crib aligner can fake a fit, because a fresh code may always be given a fresh letter. What cannot be faked is a long consistent run: inside one window a repeated code must carry the same letter and the mapping must stay a function, so a false run dies at its first repeat conflict. Scanning every pairing of digit offset against crib offset and extending each run while it stays consistent:
| longest consistent run | |
|---|---|
| real cipher against the plaintext of Nr. 153 | 39 letters |
| control: plaintext letters shuffled (five runs) | 39, 39, 36, 38, 36 |
| control: cipher reversed | 39 |
| synthetic two-digit cipher, same text, 1.7 % digit noise | 207 letters |
| synthetic two-digit cipher, clean transcription | 2705 letters |
The real material sits on its own chance baseline, while a two-digit cipher at the same transcription noise runs five times further. The tool works: on that noisy synthetic text this method recovers 81 of 100 key codes, where the dynamic-programming learner managed 7. And because chance runs here reach 36 to 39 letters, the twenty-seven-letter opening match quoted at the top of this page is below the baseline. It is not evidence, and the one-in-180 figure given for it above is wrong.
So transcription noise is no longer a sufficient explanation. On this evidence the cipher sheet is not a fixed-width two-digit encipherment of the text Kiewning prints as Nr. 153. The next test widened that to the whole volume.
The corpus search. The run-length test compares one ciphertext with one crib. This compares four ciphertexts with the entire edition at once, exactly. For a substitution, equal codes force equal letters, so take a window of the cipher, list every pair of positions inside it holding the same code, and require the plaintext to repeat at precisely those offsets. That condition is checked across all 1,161,303 letters of Kiewning in one pass, with a bitmask per gap.
Calibrated by planting the true plaintext in the corpus and enciphering it with a random key:
| windows hitting the true position | false positives | |
|---|---|---|
| synthetic, clean transcription | 253 / 254 | 0 |
| synthetic, 1.7 % digit noise | 16 / 254 | 0 |
So even at the real noise level about six per cent of windows still give an exact hit, and the method never fires falsely. Applied to four of the ciphertexts at three code widths:
| record | width 2 | width 3 | width 4 |
|---|---|---|---|
| R286 | 0 / 266 | 1 / 261 | 0 / 256 |
| R292 | 0 / 460 | 0 / 456 | 0 / 452 |
| R306 | 0 / 710 | 2 / 705 | 0 / 700 |
| R311 | 0 / 510 | 1 / 505 | 0 / 500 |
The four apparent width-three hits are artefacts: every one lands in the edition’s index of Roman numerals (XIUXXUXXUIXXUIIXXUIII…), a degenerate stretch of corpus where any repeat pattern matches. There are no genuine hits. Under the hypothesis, R286 alone should have produced of the order of eight, so the probability of seeing none is around e−8.
What was left. The ciphertexts are not fixed-width substitutions of anything printed in the volume, of Nr. 153 or of any other despatch. Two possibilities remained. Either the system has variable-length groups, which no fixed-width alignment can match however good the transcription (the absence of phase preference points the same way), or the sheets encipher text that is not in the edition: Kiewning prints the substance in Italian but renders the rest as German regesta, and that Italian exists nowhere in print. The key (section 00) later confirmed the first. Both were testable, the first with a variable-length version of the same tool, the second by weighing a ciphertext’s length against the part of its despatch the edition only summarises.
How good is the transcription? Checked on DECODE’s larger scan, line 1 of p. 5 differs from DECODE’s transcription in two digits out of seventy-four, both substitutions, with no length difference (the transcription has 93 where the scan shows 73, and 30 where it shows 38). Line 2 differs by a digit or two and possibly in length. So the transcription is close, no length error is demonstrated at the point where the alignment breaks, and the break there is not a transcription artefact. Two explanations therefore remain open and cannot be separated from this material: the transcription carries enough length errors elsewhere to defeat recovery, or the cipher is not a fixed-width substitution of this plaintext at all.
04 What the cipher is
Every test above is negative. This one is not, and it constrains the system. Count repeated digit substrings across all twenty-eight ciphertexts (112,805 digits) against an independent control with the same digit frequencies:
| substring length | repeats in the cipher | independent control | ratio |
|---|---|---|---|
| 4 | 105,170 | 102,865 | 1.0× |
| 6 | 64,083 | 9,590 | 6.7× |
| 8 | 28,519 | 91 | 313× |
| 10 | 12,109 | 1 | 12,000× |
| 16 | 966 | 0 | — |
| 24 | 39 | 0 | — |
Thirty-nine repeated twenty-four-digit strings where chance gives none. A homophonic cipher used with care would not do that, since homophones exist to break repetition, and this hand repeats long runs constantly. What repeats like this is a code: a nomenclator in which a given word or syllable is written the same way every time. The key (section 00) has both: homophones for the letters, and fixed groups for syllables, words and names. The fixed groups of varying length explain why every fixed-width attack above failed. Segmenting the corpus by BPE gives 266 token types over 44,816 tokens, averaging 2.5 digits and spread over lengths one to seven: syllable-scale, and not a fixed width.
Two further hypotheses were tested and fail. The repeat spectrum of the first despatch matches its crib’s at roughly one digit per letter (3,570 digits against 3,359 letters), which for twenty-one letters over ten digits would mean a polyphonic cipher; there the constraint reverses, equal letters forcing equal digits. Longest consistent letter-to-digit run: 17 letters, against shuffled controls of 18, 19 and 18, which is chance level. And since encipherment preserves order, a repeated BPE token should land on the same plaintext word each time; 16 token types of 74 do, against controls of 13, 12 and 13. Not significant.
One correction. Section 03 above reports no phase preference at widths two and three. I first offered that as evidence against fixed-width codes, and that was too strong: at the observed digit error rate a single despatch carries some sixty slips, each flipping the phase for the rest of its line, which would wash out a real phase signal by itself. The phase test is inconclusive. The calibrated corpus search is the sound version of the claim, and it stands.
05 The annotations in DECODE’s transcriptions
DECODE’s transcriptions are annotated, and I had only skimmed the head of the first one. Across the twenty-eight files there are about 640 <CLEARTEXT> marks, and in five records <PLAINTEXT> lines, DECODE’s notation for a decipherment written on the document itself.
| record | clear-text marks | decipherment on the page |
|---|---|---|
| R298 | 68 | |
| R296 | 63 | |
| R305 | 54 | In un lungo discorso |
| R307 | 53 | |
| R292 | 51 | |
| R309 | 35 | Con l’ord(ina)rio passato intendo che fu scritto da S. M.tà à… |
| R308 | 22 | restati più contenti della risolutione |
| R313 | 14 | Nel particolare |
Most of these despatches are mixed letters: short ciphered runs set inside clear Italian, clause by clause. R308 has, on the leaf:
with, written above the figures: restati più contenti della risolutione
That is an exact crib with known boundaries, in the right register, and it is nowhere in Kiewning. It also explains why a crib from the printed edition could not match a record like this one: the ciphered passage is a single clause, and the edition prints the sense of the whole letter.
This crib did not fit either. Forty-one digits for thirty-four letters, with the figures and the gloss both checked against DECODE’s 1523 × 2088 scan. Searched exhaustively, under the deterministic constraint that section 04 implies and again allowing homophones:
| model | result |
|---|---|
| fixed width 1, 2 or 3 | no fit (41 is not divisible by 2) |
| deterministic letter code, groups of 1–2 digits | 0 solutions (exact) |
| deterministic letter code, groups of 1–3 digits | 0 solutions (exact) |
| 2-digit groups, syllables of 1–3 letters | 0 solutions (exhaustive, 4.0 M nodes) |
| the same, homophones allowed | 0 solutions (exhaustive, 7.3 M nodes) |
So either the decipherer’s gloss does not align exactly to that run (he may have glossed only part of it, or run on into the next), or the system is more complex than any of these. That is where the work stood on 20 September.
06 What stays open
- The key is Biermann and Bosbach’s (2018), identified for 6960 by George Lasry. This project did not recover it. What remains open is the ~1,750 three-digit groups of 6960 that are missing from the 6956 key. Kiewning’s printed Italian could fill most of them by alignment, but that has not been done.
- The twenty-seven-letter alignment at the head of R286 is not evidence: the chance baseline for consistent runs on this material is 36 to 39 letters, so it is a run of luck shorter than average.
- Kiewning’s coverage is close to complete, and not literal: where he gives a German regest instead of the Italian, the exact wording is only in the cipher. Before the key was known this looked like the main difficulty. The volume’s clear pages do not contain the ciphered passage (pp. 3–4 and 7–9 run continuously through the cipher sheet), so the Italian of what pp. 5–6 encipher may survive only in ASV, Nunz. di Germania 119, which is not digitised. A crib drawn from the printed edition cannot fix those words.
- The sibling volume, catalogue entry 236 (BAV Barb.lat. 6956, DECODE R215–R285 and R318), was deciphered by others with the Biermann and Bosbach key and has been removed from the catalogue.
- Where the next attempt should start: extract every clear-text and decipherment annotation with the digit runs on either side, across all twenty-eight records. That yields hundreds of short ciphered clauses with their Italian context, and five with a contemporary decipherment attached. Check each gloss against the image before trusting its extent; the R308 gloss is the best-documented one and it still does not fit, which most likely means its extent is not what it looks like.
07 Sources
- Vatican City, Biblioteca Apostolica Vaticana, Barb.lat. 6960 — DigiVatLib, 194 pages. Cipher sheets at pp. 5–6, 10–12, 35–37, 40–42, 46–47, 55–57, 62–64, 68–70, 75–76, 80, 83–84, 90–91, 97–99, 105, 109–110, 113–114, 119–120, 124–125, 130–131, 135–136, 140–142, 146–147, 152, 155–156, 163–165, 174–176, 181–183, 192–193. Images © Biblioteca Apostolica Vaticana.
- DECODE record R215 (Barb.lat. 6956): Norbert Biermann’s and Thomas Bosbach’s keys (March 2018), their merged key and a decryption, as documents D1505–D1508. George Lasry, personal communication via Daniel Bourdeau, 21 September 2026: 6960 uses the same key.
- DECODE records R286–R313 (the ciphertexts, with 2019–20 transcriptions) and R315 (the volume).
- Hans Kiewning (ed.), Nuntiaturberichte aus Deutschland nebst ergänzenden Aktenstücken. Vierte Abteilung: 17. Jahrhundert, Band 2: Nuntiatur des Pallotto 1628–1630, 2: 1629 (Berlin 1897) — archive.org, item 4-2_20200807. Band 1 (1628) was published in 1895.
- Kiewning’s manuscript sources for the despatches: ASV, Nunz. di Germania 119 (the deciphered copies received in Rome) and Bibl. Barber. LXIX–LXX for the Barberini side.
Working files, the DECODE transcriptions, the crib, the aligners and the solver: pallotto1629/.

