Skip to content

Encryption Tool

Encrypt and decrypt text with AES-GCM, using a key derived from your passphrase with PBKDF2.

AES Encryption Tool

Encrypt and decrypt messages securely using a secret key.

Required

AES-256-GCM. The key is derived from your passphrase with PBKDF2-HMAC-SHA256 over 250,000 iterations and a random 16-byte salt; each message gets a fresh random 12-byte IV. The result is the salt, the IV and the authenticated ciphertext concatenated and Base64-encoded.

Only messages produced by this tool can be decrypted here. Your passphrase and text never leave the browser.

What Encryption Tool does

This tool encrypts a short piece of text under a passphrase so it can be stored or sent through a channel you do not fully trust, and decrypted later by someone who knows the passphrase.

It uses AES-256 in GCM mode with a key derived by PBKDF2-SHA256 over a random salt, and a random initialisation vector for every message. GCM is authenticated, which means decryption fails loudly if the ciphertext has been altered rather than quietly producing wrong plaintext.

  • AES-256-GCM authenticated encryption
  • PBKDF2-SHA256 key derivation with a random salt per message
  • Fresh random initialisation vector per message
  • Salt, IV and ciphertext bundled into one base64 string

How to use Encryption Tool

  1. 1

    Enter your message

    Paste the text you want to protect.

  2. 2

    Choose a strong passphrase

    The passphrase is the only thing standing between the ciphertext and the plaintext. A long generated passphrase is far better than a memorable one.

  3. 3

    Encrypt and save the output

    The output contains everything needed to decrypt except the passphrase. Store the whole string.

  4. 4

    Decrypt when needed

    Paste the full string back with the same passphrase. If either the passphrase or the ciphertext is wrong, decryption fails rather than returning nonsense.

Limits and known behaviour

  • There is no recovery. Lose the passphrase and the message is gone; that is the point of encryption, not a fault to be worked around.
  • Security rests entirely on passphrase strength. A weak passphrase can be attacked offline by anyone holding the ciphertext.
  • This is designed for short text. It is not a file encryption tool and not a replacement for full-disk encryption or an end-to-end encrypted messenger.
  • The output format is specific to this tool. Other AES implementations will not decrypt it without knowing how the salt and IV are packed.
  • Encryption protects the message in transit and at rest. It does not protect a device that is already compromised, since the plaintext is on screen.

Privacy and data handling

Runs entirely in your browser

  • Encryption and decryption use the browser's Web Crypto implementation in this page. Neither the plaintext nor the passphrase is transmitted.
  • No key material is stored. The derived key exists only for the operation.

Site-wide data handling, including analytics and advertising, is described in the privacy policy.

Frequently asked questions

What happens if I use the wrong passphrase?

Decryption fails and reports an error. Because GCM authenticates the ciphertext, a wrong passphrase cannot produce plausible-looking wrong plaintext.

Why does encrypting the same text twice give different output?

A fresh random salt and initialisation vector are used each time. Identical output for identical input would leak the fact that two messages are the same, which is exactly what a random IV prevents.

Can I use this for files?

No, it works on text. For files, use a purpose-built tool such as an encrypted archive or your operating system's disk encryption.

Is this suitable for genuinely sensitive information?

For sending a credential to a colleague, it is reasonable if the passphrase is strong and shared through a different channel. For anything where the consequences of disclosure are serious, use a tool that has been independently audited for that purpose.