AES Encryption & Decryption
Encrypt and decrypt text with a passphrase using AES-256-GCM, entirely in your browser.
AES-256-GCM, with the key derived from your passphrase by PBKDF2-SHA-256 (250,000 rounds) and a random salt and IV each time. Everything runs in your browser. There is no way to recover the text if you lose the passphrase.
AES Encryption & Decryption
Encrypt a message so that only someone with the passphrase can read it. The tool uses AES-256 in GCM mode, which also detects any tampering, and turns your passphrase into a key with PBKDF2-SHA-256 and 250,000 rounds plus a random salt, so every encryption of the same text looks different. It all runs in your browser through the Web Crypto API; nothing is sent to a server.
How to use AES Encryption & Decryption
- Choose Encrypt, type the message and a strong passphrase.
- Copy the encrypted text and send it; share the passphrase through a different channel.
- To decrypt, choose Decrypt, paste the encrypted text and enter the same passphrase.
When it comes in handy
- Sending a password or private note through email or chat more safely.
- Storing a sensitive note in a shared document.
- Learning how authenticated encryption works.
Frequently asked questions
- What happens if I forget the passphrase?
- The text cannot be recovered. There is no back door.
- Can other AES tools decrypt this?
- The output packs the salt, IV and ciphertext together in this tool's own format (Base64), so decrypt it here. The algorithms are standard, so a developer could decrypt it with any Web Crypto or OpenSSL code that follows the same layout.
- How strong should the passphrase be?
- Long and random: four or five random words, or a password manager's generated password. PBKDF2 slows guessing down but cannot save a weak passphrase.