AES Text Encryption
Encrypt and decrypt text with AES-256-GCM and a passphrase. Everything runs locally in your browser with the Web Crypto API — your text and passphrase never leave your device and nothing is stored.
How to use the AES encrypter
- Choose Encrypt or Decrypt.
- To encrypt, type your message and a strong passphrase, then click Encrypt and copy the Base64 result.
- To decrypt, paste the Base64 text and enter the same passphrase used to encrypt it, then click Decrypt.
Keys are derived with PBKDF2 (SHA-256, random 16-byte salt, 100,000 iterations) and the message is encrypted with
AES-256-GCM using a random 12-byte IV. The output is the Base64 of salt || iv || ciphertext.
All of it happens in your browser — nothing is sent anywhere and nothing is stored.
More PAYATE tools
Frequently asked questions
What does this AES tool do?
It encrypts and decrypts text with AES-256-GCM. You type a message and a passphrase; a 256-bit key is derived from the passphrase and the message is encrypted into a Base64 string you can share. Anyone with the same passphrase can decrypt it back to the original text.
Is my text or passphrase sent anywhere?
No. Everything runs entirely in your browser using the native Web Crypto API. Your message and passphrase never leave your device, nothing is uploaded to a server, and nothing is stored — close the tab and it is gone.
How is the key derived from my passphrase?
With PBKDF2 using SHA-256, a random 16-byte salt and 100,000 iterations, producing a 256-bit AES key. The random salt means the same passphrase yields a different output every time, which protects against precomputed-dictionary attacks.
What is in the Base64 output?
The output packs three parts together: the random salt (16 bytes), the random IV (12 bytes) and the ciphertext, concatenated as salt || iv || ciphertext and encoded as Base64. The decrypt step splits them back out, so you only need to keep the single Base64 string and the passphrase.
Why did decryption fail?
Decryption shows “Wrong passphrase or corrupted data” when the passphrase does not match, or when the Base64 text was altered, truncated or not produced by this tool. AES-GCM verifies integrity, so even a single changed character makes it refuse to decrypt.
How strong is this encryption?
AES-256-GCM is a widely trusted authenticated cipher. The real strength depends on your passphrase: use a long, unpredictable one. A short or common passphrase can be guessed regardless of the algorithm.