AES Encrypt / Decrypt
Encrypt or decrypt text with AES-256-GCM using a passphrase — all in your browser.
The AES Encrypt / Decrypt tool lets you protect text with AES-256 in GCM mode using a passphrase you choose, all inside your browser. GCM is an authenticated cipher, so it not only encrypts the data but also detects if it has been tampered with, failing loudly rather than returning garbage. Encryption and decryption are symmetric, which means the exact passphrase is the only key: keep it safe, because there is no recovery if you lose it. Use it to store a secret on disk, to scramble a value inside a config file, or to understand how a strong, modern cipher behaves. Everything runs locally, so the plaintext and the passphrase never leave your device. Symmetric encryption uses one key for both directions, and AES is the modern standard for it, with 256 bit keys being the strongest widely deployed choice. The mode matters as much as the cipher: GCM is an authenticated mode, meaning it produces not only ciphertext but a tag that lets the receiver detect any modification, so a tampered message fails to decrypt cleanly rather than returning plausible garbage. That single property is why GCM is the default recommendation for new work, since it combines confidentiality with integrity in one step and removes an entire class of bugs where encrypted data is silently altered. In practice, symmetric encryption is the right tool for data at rest, such as a secret kept in a configuration file or a value stored in a database that must not be readable by anyone with access to the storage. The critical operational point is that the passphrase is the entire security boundary. There is no recovery mechanism, no reset, and no backdoor, so a lost key means permanently unreadable data, which makes storing the key somewhere durable and separate from the data essential. Used with that discipline, it is a straightforward way to add a real layer of protection without a larger system.
AES-256-GCM with a PBKDF2-derived key (100k iterations). Output bundles salt + IV + ciphertext as Base64.
Result appears here.
Frequently Asked Questions
Is AES-256-GCM safe to use?
Yes — GCM is an authenticated cipher that detects tampering. The encryption runs entirely in your browser from a passphrase; no data is uploaded.
Why must I keep the passphrase?
There is no recovery. AES is symmetric, so the exact passphrase is the only way to decrypt. Losing it means the data is unrecoverable by design.
Should I use the same passphrase for everything?
No. Reusing a passphrase across sensitive items means one leak exposes all. Generate a unique passphrase per secret.