Encryption Decryption

Encrypt and decrypt text with AES in your browser.

Encryption / Decryption Tool

Encrypt and decrypt text in your browser with AES — the Advanced Encryption Standard used by governments and industry worldwide. Protect a note with a password, exchange a secret message, or produce ciphertext compatible with OpenSSL. Nothing is uploaded; all cryptography runs locally via the Web Crypto API.

Key modes

  • Password (PBKDF2-SHA256) – you enter a password; a random 16-byte salt and IV are generated and PBKDF2 stretches the password into an AES key. The output packs salt + IV + ciphertext, so decryption needs only the password.
  • OpenSSL enc compatible – produces the Salted__ AES-CBC format that openssl enc -pbkdf2 reads and writes, for interoperability with command-line tools.
  • Raw key + IV – you supply an exact AES key and IV in hex (or generate random ones), matching any standard AES implementation.

Cipher modes

  • AES-GCM (recommended) – authenticated encryption; tampering or a wrong password is detected.
  • AES-CBC – classic block mode with PKCS#7 padding.
  • AES-CTR – stream mode.

Choose a 128- or 256-bit key and Base64 or hex output.

How to use it

  1. Pick Encrypt, type your message, choose a mode, and enter a password.
  2. Copy the encrypted output and share or store it.
  3. To read it back, pick Decrypt, paste the ciphertext, and enter the same password and settings. The Decrypt this / Use as input button moves the result across so you can round-trip in one place.

Good to know

AES is a symmetric cipher: the same secret encrypts and decrypts, so share the password over a separate secure channel. This tool encrypts text; to encode binary or files as text see the Base64 Encode / Decode tool, and for one-way hashing see the SHA256 Hash Generator.

Frequently Asked Questions

The tool uses the browser's built-in Web Crypto API with AES (GCM, CBC, or CTR). In password mode it derives a 128- or 256-bit AES key from your password with PBKDF2-SHA256 and a random salt, so the same password produces a different ciphertext each time.

AES-GCM is recommended: it is authenticated, so decryption fails loudly if the ciphertext or password is wrong or the data was tampered with. AES-CBC and AES-CTR are provided for compatibility with systems that expect them.

Yes, if you use the OpenSSL-compatible scheme. It produces the \"Salted__\" format from openssl enc -aes-256-cbc -pbkdf2, so you can decrypt with: openssl enc -d -aes-256-cbc -pbkdf2 -iter 10000 -base64. The raw key+IV mode is also standard AES you can reproduce in any library.

No. All encryption and decryption happen in your browser using Web Crypto. Your text, password, and keys never leave your device.

No. Without the correct password or key there is no way to recover AES-encrypted data. Store your password safely; a forgotten password means the ciphertext is unreadable.