🔒

AES Encrypt / Decrypt

Encrypt and decrypt text with AES-256-GCM using a passphrase-derived key (PBKDF2), entirely in your browser. Ciphertext embeds the salt and IV — nothing is uploaded.

Plaintext
Ciphertext

Format: mode|salt(hex)|iv(hex)|tag(hex, GCM only)|data(base64). Key is derived with PBKDF2-SHA-256 (200k iterations). Everything runs locally in your browser.

Encrypt a message

Encrypt a short message with a passphrase and copy the self-contained ciphertext, which can be decrypted with the same passphrase alone.

Ideally use AES-GCM. The output holds the algorithm, salt, IV and authentication tag, so decrypting only needs the same passphrase.

FAQ

Is AES-256-GCM safe to use?

Yes. AES-256 is the industry-standard symmetric cipher and GCM is an authenticated mode that detects tampering. Combined with a PBKDF2-derived key it is a strong choice for ordinary privacy needs.

What happens if I forget the passphrase?

There is no recovery. The key is derived from your passphrase with PBKDF2 and is never stored, so without it the data cannot be decrypted. Keep your passphrase somewhere safe.

GCM vs CBC — what should I pick?

Use GCM. It is authenticated, so it detects any modification of the ciphertext. CBC is listed for legacy compatibility but does not authenticate and is more error-prone.

Where is my key stored?

Nowhere persistent. The key is derived in memory for the life of the operation and discarded after encrypting or decrypting. Nothing you enter here is sent to any server.

Updated 2026-08-10 · Runs in your browser — your data never leaves this page unless the tool explicitly says it makes a network check.