AES Encrypt / Decrypt

1 line · 0 B

AES Encrypt / Decrypt

Encrypt or decrypt text with AES-256-GCM, keyed by a passphrase stretched with PBKDF2. The IV is generated automatically for every encryption.

1 line · 0 B
AES-256-GCM

About this AES Encrypt / Decrypt

Encrypt or decrypt text with AES-256-GCM, keyed by a passphrase stretched with PBKDF2. The IV is generated automatically for every encryption.

Encryption runs locally in your browser via the Web Crypto API. The secret key is never uploaded, stored, or included in a share link. Output is base64(salt || IV || ciphertext) — a single self-contained blob that Decrypt can parse back apart given the same secret key.

FAQ

Why does this only take a passphrase instead of a raw AES key?

Every key here is derived from the passphrase you type via PBKDF2 (100,000 iterations, random salt) — there's no raw-key input. The salt and IV are generated fresh each time and bundled into the output as base64(salt || IV || ciphertext), so Decrypt can pull them back out using the same passphrase.

Why do I need a fresh IV for every encryption?

An IV ensures the same plaintext encrypted twice with the same key produces different ciphertext. This tool generates a random one automatically for every run, so you never have to manage it yourself.

Why did decryption fail with an "authentication tag" error?

GCM mode authenticates as it decrypts — that error means the ciphertext, passphrase, salt, or IV doesn't match what encrypted it, so something was altered or you typed the wrong passphrase. Don't try to bypass this check; it exists specifically to catch tampering.

Is AES symmetric or asymmetric?

Symmetric — the same passphrase both encrypts and decrypts. To exchange that passphrase securely with someone else, pair it with RSA or another asymmetric method.

Is my plaintext or passphrase sent to a server?

No — encryption and decryption run entirely in your browser via the Web Crypto API. Pasting the exact data you're trying to protect into someone else's server would defeat the purpose of testing encryption in the first place.

Related tools