AES Encrypt & Decrypt
Encrypt or decrypt text with a password using AES-256-GCM, entirely in your browser.
How to use the AES Encrypt/Decrypt
- Choose Encrypt or Decrypt.
- Enter the text: plain text to encrypt, or the encrypted Base64 string to decrypt.
- Enter a strong password. You'll need exactly the same password to decrypt.
- Click Run and copy the result.
How the AES Encrypt/Decrypt works
When you encrypt, the tool generates a random salt and a random 96-bit initialization vector (IV). It derives a 256-bit key from your password using PBKDF2 with 150,000 iterations of SHA-256, which makes guessing passwords slow, then encrypts your text with AES-256 in GCM mode. GCM also adds an authentication tag, so any change to the ciphertext, or a wrong password, makes decryption fail rather than produce garbage.
The salt, IV and ciphertext are combined and Base64-encoded into a single string you can store or send. Everything runs locally through the Web Crypto API. The password is never stored, so if you lose it the data cannot be recovered.
Frequently asked questions
- Is this tool free?
- Yes. Encrypt or decrypt text at no cost, with no account required.
- Does my text or password leave my browser?
- No. Encryption and decryption run entirely client-side using the Web Crypto API.
- What happens if I lose the password?
- There is no way to recover encrypted data without the original password - it is used to derive the encryption key and is never stored.
- How is the key derived?
- A random salt and IV are generated per encryption, and the key is derived from your password using PBKDF2 with 150,000 iterations of SHA-256, then used with AES-256-GCM.