AES Encryption & Decryption

Encrypt and decrypt text with a passphrase using AES-256-GCM, entirely in your browser.

AES-256-GCM, with the key derived from your passphrase by PBKDF2-SHA-256 (250,000 rounds) and a random salt and IV each time. Everything runs in your browser. There is no way to recover the text if you lose the passphrase.


AES Encryption & Decryption

Encrypt a message so that only someone with the passphrase can read it. The tool uses AES-256 in GCM mode, which also detects any tampering, and turns your passphrase into a key with PBKDF2-SHA-256 and 250,000 rounds plus a random salt, so every encryption of the same text looks different. It all runs in your browser through the Web Crypto API; nothing is sent to a server.

How to use AES Encryption & Decryption

  1. Choose Encrypt, type the message and a strong passphrase.
  2. Copy the encrypted text and send it; share the passphrase through a different channel.
  3. To decrypt, choose Decrypt, paste the encrypted text and enter the same passphrase.

When it comes in handy

  • Sending a password or private note through email or chat more safely.
  • Storing a sensitive note in a shared document.
  • Learning how authenticated encryption works.

Frequently asked questions

What happens if I forget the passphrase?
The text cannot be recovered. There is no back door.
Can other AES tools decrypt this?
The output packs the salt, IV and ciphertext together in this tool's own format (Base64), so decrypt it here. The algorithms are standard, so a developer could decrypt it with any Web Crypto or OpenSSL code that follows the same layout.
How strong should the passphrase be?
Long and random: four or five random words, or a password manager's generated password. PBKDF2 slows guessing down but cannot save a weak passphrase.

Choose which cookies SEOpeck may use. You can change this at any time from "Cookie settings" at the bottom of every page.