AES Encryptor and Decryptor

Encrypt confidential text with authenticated AES-256-GCM encryption or decrypt a compatible encrypted package.

Browser onlyAES-256-GCMAuthenticated encryption

Plain text

Encryption settings

Encryption

AES-256-GCM

Key derivation

PBKDF2-SHA-256

Authentication tag

128 bits

Random IV

96 bits

Encrypted output

Enter text and a password

The result will appear here after you start the operation.

Authenticated encryption

Protect confidentiality and detect unauthorized modifications

AES-GCM encrypts the content and generates an authentication tag that causes decryption to fail when the password or encrypted data is incorrect.

Use a strong, unique password

Password-based encryption remains vulnerable when the password is short, predictable, or reused. Prefer a long password generated and stored by a password manager.

Store the password separately

Sending the encrypted package and its password through the same channel removes much of the protection. Share or store them separately.

Guide

About AES Encryptor and Decryptor

AES is a symmetric encryption standard used to protect data at rest and in transit. The same secret key is used for encryption and decryption.

This tool helps developers test AES workflows, inspect parameters, and convert encrypted values without sending plaintext or keys to a server.

For new designs, authenticated encryption such as AES-GCM is generally preferable because it protects confidentiality and detects tampering.

What this AES tool supports

Encrypt or decrypt text with browser cryptography and inspect the parameters required to reproduce the result.

  • AES-GCM authenticated encryption
  • AES-CBC compatibility workflows
  • Configurable keys and initialization vectors
  • Hex and Base64 output formats

AES-GCM versus AES-CBC

AES-GCM provides encryption and integrity protection in one operation. AES-CBC requires a separate authentication mechanism such as HMAC to detect modification.

Key and IV safety

Encryption remains secure only when keys are random, secret, and managed correctly. IVs do not usually need to be secret, but they must follow the uniqueness requirements of the selected mode.

  • Never reuse a GCM nonce with the same key
  • Do not derive keys directly from weak passwords
  • Store keys separately from ciphertext
  • Authenticate CBC ciphertext before decryption

When to use this tool

Use it for development, interoperability testing, test-vector creation, and understanding AES parameters. Production applications should use reviewed libraries and a documented key-management design.

FAQ

Frequently asked questions

Is AES encryption reversible?

Yes. AES is symmetric encryption, so data can be decrypted with the correct key and compatible parameters.

Should I use AES-GCM or AES-CBC?

AES-GCM is usually the better default because it provides authenticated encryption. AES-CBC needs a separate integrity mechanism.

What is an initialization vector?

An IV or nonce makes repeated encryption operations produce different ciphertext. Its required size and uniqueness rules depend on the AES mode.

Can I use a password directly as an AES key?

Not safely. Passwords should be processed with a password-based key derivation function using a salt and suitable work factor.

Why does decryption fail after one character changes?

Authenticated modes reject modified ciphertext, tags, or parameters because integrity verification fails.

Is my plaintext uploaded?

The tool is intended to perform encryption and decryption locally in your browser.

Continue exploring

Useful tools for the next step in the same workflow.