Encrypt / Decrypt Text (AES-GCM)

Set a passphrase and protect your text with modern, authenticated AES-256-GCM encryption; decrypt it again anytime with the same passphrase.

Runs 100% in your browser — your text and passphrase are never sent to a server.
How it works: Encryption happens entirely in your browser — nothing is ever sent to a server. Encrypted text can only be decrypted with the same passphrase; there is no backdoor or "forgot passphrase" recovery path — if you forget the passphrase, the data cannot be recovered. This tool's AES-256-GCM is a real, modern authenticated encryption standard, but the ultimate security depends on the strength of the passphrase you choose: use a long, unpredictable one.

Encrypt

Decrypt

How Does AES-GCM Encryption Work?

AES-GCM (Galois/Counter Mode) is one of the "authenticated encryption" methods that both hides your data and verifies its integrity. At the end of encryption, an extra 16-byte block called the authentication tag is appended to the output; during decryption, this tag is recomputed and compared — if even a single byte of the ciphertext has been changed or corrupted, decryption doesn't silently return a wrong result, it fails outright.

Why isn't the passphrase used directly as the key? An AES-256 key is 32 bytes (256 bits) of random data; a passphrase you type isn't nearly that random, and using it directly would limit the number of candidate passphrases an attacker would need to try. That's why your passphrase is first run through PBKDF2 (Password-Based Key Derivation Function 2); this algorithm deliberately hashes your passphrase 600,000 times in a row (with SHA-256) to turn it into a single encryption key — this slowness makes it dramatically more costly for an attacker to brute-force millions of candidate passphrases.

Every encryption run generates a random 16-byte "salt" and a random 12-byte initialization vector (IV); both are prepended to the actual output and Base64-encoded together. This is why encrypting the same text with the same passphrase twice gives you a completely different output each time — this isn't a bug, it's a deliberate design called "semantic security", and it ensures no pattern or hint about the original content leaks from the ciphertext. During decryption, the salt and IV are parsed back out from the start of the output to re-derive the same key.

An honest limit: This tool uses the browser's built-in Web Crypto API (crypto.subtle) — no third-party encryption library is loaded. AES-256-GCM and PBKDF2 are real, industry-standard algorithms; but no encryption can make a weak passphrase strong. A short or guessable passphrase like "1234" renders even a strong algorithm meaningless — use a long, random passphrase that only you know, and store it somewhere safe (e.g. a password manager).

Try This Next

Finished here? These might be your next step.

Frequently Asked Questions

AES-256-GCM — an authenticated encryption standard with a 256-bit key. The encryption key is derived from your passphrase using PBKDF2 (600,000 iterations, SHA-256). Both are computed with the browser's built-in Web Crypto API (crypto.subtle); no third-party library is used.

No. Both encryption and decryption happen entirely in your browser; neither your text nor your passphrase is ever sent to this site or any other server.

Your encrypted data becomes permanently inaccessible. There is no "forgot passphrase" recovery path or backdoor in this tool (or in AES-GCM itself) — there is no known way to decrypt the data without the passphrase. Make sure to store your passphrase somewhere safe, such as a password manager.

In practice, no — as long as you use a strong, long, random passphrase. AES-256 combined with 600,000 rounds of PBKDF2 makes a brute-force attack (trying candidate passphrases one by one) extremely costly. However, this protection depends entirely on your passphrase's strength: a short or guessable passphrase like "1234" or a dictionary word makes even a strong algorithm meaningless.

This is not a bug — it's an intentional security design. Each encryption run generates a new random "salt" and a new random initialization vector (IV) and prepends them to the output; this prevents the same content from always producing the same ciphertext (which would otherwise leak a pattern). Decryption uses this salt and IV from the start of the output to re-derive the correct key, so decryption always works correctly regardless.

Last updated: