Why does this only take a passphrase instead of a raw AES key?
Every key here is derived from the passphrase you type via PBKDF2 (100,000 iterations, random salt) — there's no raw-key input. The salt and IV are generated fresh each time and bundled into the output as base64(salt || IV || ciphertext), so Decrypt can pull them back out using the same passphrase.