Encryption Decryption
Encrypt and decrypt text with AES in your browser.
Encryption / Decryption Tool
Encrypt and decrypt text in your browser with AES — the Advanced Encryption Standard used by governments and industry worldwide. Protect a note with a password, exchange a secret message, or produce ciphertext compatible with OpenSSL. Nothing is uploaded; all cryptography runs locally via the Web Crypto API.
Key modes
- Password (PBKDF2-SHA256) – you enter a password; a random 16-byte salt and IV are generated and PBKDF2 stretches the password into an AES key. The output packs salt + IV + ciphertext, so decryption needs only the password.
- OpenSSL enc compatible – produces the
Salted__AES-CBC format thatopenssl enc -pbkdf2reads and writes, for interoperability with command-line tools. - Raw key + IV – you supply an exact AES key and IV in hex (or generate random ones), matching any standard AES implementation.
Cipher modes
- AES-GCM (recommended) – authenticated encryption; tampering or a wrong password is detected.
- AES-CBC – classic block mode with PKCS#7 padding.
- AES-CTR – stream mode.
Choose a 128- or 256-bit key and Base64 or hex output.
How to use it
- Pick Encrypt, type your message, choose a mode, and enter a password.
- Copy the encrypted output and share or store it.
- To read it back, pick Decrypt, paste the ciphertext, and enter the same password and settings. The Decrypt this / Use as input button moves the result across so you can round-trip in one place.
Good to know
AES is a symmetric cipher: the same secret encrypts and decrypts, so share the password over a separate secure channel. This tool encrypts text; to encode binary or files as text see the Base64 Encode / Decode tool, and for one-way hashing see the SHA256 Hash Generator.
Frequently Asked Questions
How is my text encrypted?
The tool uses the browser's built-in Web Crypto API with AES (GCM, CBC, or CTR). In password mode it derives a 128- or 256-bit AES key from your password with PBKDF2-SHA256 and a random salt, so the same password produces a different ciphertext each time.
Which mode should I choose?
AES-GCM is recommended: it is authenticated, so decryption fails loudly if the ciphertext or password is wrong or the data was tampered with. AES-CBC and AES-CTR are provided for compatibility with systems that expect them.
Can I decrypt this with OpenSSL or another tool?
Yes, if you use the OpenSSL-compatible scheme. It produces the \"Salted__\" format from openssl enc -aes-256-cbc -pbkdf2, so you can decrypt with: openssl enc -d -aes-256-cbc -pbkdf2 -iter 10000 -base64. The raw key+IV mode is also standard AES you can reproduce in any library.
Is my data sent to a server?
No. All encryption and decryption happen in your browser using Web Crypto. Your text, password, and keys never leave your device.
I lost my password — can the text be recovered?
No. Without the correct password or key there is no way to recover AES-encrypted data. Store your password safely; a forgotten password means the ciphertext is unreadable.