DevToolPal
EN

AES Encrypt & Decrypt

Encrypt and decrypt text with AES-GCM or AES-CBC using a passphrase (PBKDF2) or a raw hex key, with Base64 output.

Runs locally, never uploaded

Options

Mode
Algorithm
Key
Key size

Input

0 chars · 0 B

Output

0 chars · 0 B

What it does

AES (Advanced Encryption Standard) is the symmetric cipher used almost everywhere: HTTPS, disk encryption, password managers and messaging apps. The same secret key encrypts and decrypts. This tool encrypts text into Base64 you can paste anywhere, and decrypts it again.

You can use either:

  • a passphrase, which is turned into a 128- or 256-bit key with PBKDF2-HMAC-SHA256 and a random salt, or
  • a hex key: 32 or 64 hex digits (128 or 256 bits), used directly. Click Random key to create one.

Two modes of operation are available. AES-GCM is the modern default and detects tampering. AES-CBC with PKCS#7 padding is offered for compatibility with older systems.

How to use

  1. Choose Encrypt or Decrypt, the algorithm and the key type.
  2. Type the passphrase or paste the hex key at the top of the input box.
  3. Paste the text (or the Base64 to decrypt). The result appears on the right; Use as input switches direction to check the round trip.

Output format

The output is one Base64 string so it survives email and chat:

passphrase:  salt (16 bytes) | IV (12 GCM / 16 CBC) | ciphertext (+ 16-byte tag for GCM)
hex key:     IV (12 GCM / 16 CBC) | ciphertext (+ 16-byte tag for GCM)

To decrypt, use the same algorithm, key type, key size and iteration count that were used to encrypt. These settings are kept in the page address, so a shared link carries them while the key stays with you.

Choosing a passphrase

PBKDF2 makes each guess slower, but it cannot save a short or common passphrase. Use a long random passphrase, for example from a password generator, and share it through a different channel than the ciphertext. More iterations make guessing harder and decryption slightly slower; 100,000 to 600,000 are typical.

FAQ

› Should I choose GCM or CBC?

Choose GCM unless another system requires CBC. GCM is authenticated, so a wrong key or a single changed byte is detected instead of producing garbage. CBC only provides confidentiality and is mainly useful for compatibility with older code.

› Why is the ciphertext different every time?

Every encryption uses a fresh random IV, and with a passphrase also a fresh random salt. Both are stored at the start of the output, so decryption still works. Reusing an IV with the same key, especially with GCM, would be a serious weakness.

› How do I decrypt the output in my own code?

Decode the Base64. With a passphrase, the first 16 bytes are the PBKDF2 salt, then the IV (12 bytes for GCM, 16 for CBC), then the ciphertext. Derive the key with PBKDF2-HMAC-SHA256 using the same iteration count. With a hex key there is no salt. For GCM the last 16 bytes are the authentication tag.

› Is my passphrase or key stored or sent anywhere?

No. Encryption runs in your browser with the Web Crypto API. The passphrase or key is kept only in memory on this page. It is not saved, not written to the address bar and not included in share links, so you can share an encrypted message without its key.