The message that carries its own key
The polyalphabetic cipher's chronic weakness is the keyword repeats. Use a short key, and the pattern cycles. Use a long one, and distribution becomes painful. The autokey idea, developed in its clearest form by Blaise de Vigenère in the sixteenth century (though Girolamo Cardano had sketched something similar earlier), attacks that problem directly: after the priming key runs out, the plaintext itself continues as the key.
The mechanics are straightforward. Suppose the primer is a single word — say, GOLD. The encipherer keys the first four letters against those four characters, then shifts each subsequent plaintext letter by the value of the plaintext letter that preceded it. Because natural language is effectively unlimited, the key never cycles. The repetition that frequency analysis exploits in short-keyword Vigenère simply does not arise.

That is the promise. The failure is subtler. Natural language is not random. English plaintext drifts toward certain letters — E, T, A — and that bias propagates directly into the key stream, because the key is the plaintext. An analyst who guesses the primer length can, with enough ciphertext, apply statistical methods to the key stream itself and recover the underlying text. The autokey cipher is harder to crack than a short repeating keyword, but it is not a different class of security. Its vulnerability is the non-randomness of the message it conscripts as a key.
A variant attributed more precisely to Vigenère runs the ciphertext back as the key rather than the plaintext. This ciphertext autokey has the advantage that errors do not propagate in the same way, but it offers no stronger statistical resistance: the ciphertext, derived from biased plaintext through a structured transformation, retains exploitable patterns.
Autokey schemes appear in various diplomatic and military contexts into the early twentieth century, generally in combination with other measures. They represent a genuine insight — the key and the message should not be independent — but fall short of the conclusion that insight demands: the key must be as long as the message, truly random, and used once only.