AES encrypt and decrypt tool. Encrypt text with AES-256-GCM using a password-derived key. Decrypt ciphertext back to plain text.
100% browser-based — your data never leaves your device
Encrypt and decrypt text using AES-256-GCM with a password-based key.
Type or paste the text you want to encrypt, or paste ciphertext to decrypt.
Enter a strong password used to derive the encryption key via PBKDF2.
Click Encrypt to secure your text or Decrypt to recover the original plaintext.
Ctrl+Enter to encrypt
Decode and inspect JWT tokens instantly.
Password GeneratorGenerate strong, secure random passwords with customizable options.
Passphrase GeneratorGenerate memorable, secure passphrases from word lists.
UUID GeneratorGenerate UUID v4 identifiers instantly.
UUID ValidatorValidate UUID strings and identify the version (v1, v2, v3, v4, v5).
Hash GeneratorGenerate SHA-1, SHA-256, SHA-384, and SHA-512 hashes from text.
JWT GeneratorGenerate signed JWT tokens for testing with custom headers and payloads.
Bcrypt Hash GeneratorGenerate bcrypt password hashes with configurable salt rounds.
API Key GeneratorGenerate cryptographically secure API keys in hex, base64, alphanumeric, and UUID formats.
HMAC GeneratorGenerate HMAC hashes with SHA-256, SHA-384, and SHA-512 algorithms.
AES EncryptEncrypt and decrypt text using AES-256-GCM with a password-based key.
This tool applies AES-256-GCM, the same authenticated encryption standard used across modern infrastructure, to text you type, deriving the key from a password rather than a pre-shared key file. Everything runs locally through the Web Crypto API.
Anyone who has to move secrets across untrusted territory has a use for this tool. You can encrypt sensitive configuration values and environment variables before storing them in a file or handing them to a teammate, protect confidential text before sending it over channels you do not fully trust, and wrap backup data or API credentials in password-based encryption so that a lost file does not mean a lost secret.
Because AES-256-GCM is a public standard, your output is portable. Any compliant tool that knows the password can decrypt what you produce here, which makes the tool useful for exchanging encrypted values between environments and teams without locking anyone into a proprietary format.
Encryption tools sit at the most sensitive end of the spectrum, because they are used precisely when data matters too much to expose. If that tool is server-based, the plaintext you are trying to protect crosses the network, and the password that unlocks it crosses with it, turning the exercise into theater.
Here, the Web Crypto API does all the work in your browser. Plaintext, ciphertext, salt, and password never leave your device, so the secrecy of your data depends on your own password hygiene rather than on a third-party server keeping its logs clean.
Type or paste the text you want to encrypt, or paste ciphertext to decrypt.
Enter a strong password used to derive the encryption key via PBKDF2.
Click Encrypt to secure your text or Decrypt to recover the original plaintext.
Practical examples to help you get the most out of AES Encrypt:
// Plaintext: Hello, World! // Password: MySecurePass123! // Result: U2FsdGVkX1+ZJL4GxQvYpO3mGmYLBm5Lh0nTqVcKfDk=
// Paste the ciphertext, enter the same password, and click Decrypt to recover the original text.
AES-256-GCM decryption requires the exact same password used for encryption. There is no password recovery — store passwords in a secure manager.
If you share encrypted data and the password through the same channel, encryption provides little benefit. Share the password via a separate secure channel.
AES-256-GCM (Advanced Encryption Standard with 256-bit key in Galois/Counter mode).
Your password is combined with a random salt using PBKDF2 with 600,000 iterations.
No. All encryption and decryption happens entirely in your browser using the Web Crypto API.
Yes, AES-256-GCM is a standard — any compliant tool with the same password and IV can decrypt.
Industry-standard authenticated encryption with 256-bit keys in Galois/Counter mode.
Your password is converted to a 256-bit key using PBKDF2 with a random salt.
GCM mode provides both confidentiality and integrity verification.
All encryption happens in your browser using the Web Crypto API — nothing is sent to any server.
AES Encrypt & Decrypt is useful in a variety of scenarios across different workflows:
Encrypting sensitive configuration data and environment variables for secure storage
Protecting personal or confidential text data before transmission over untrusted networks
Securing backup data and API credentials with password-based encryption
AES-256-GCM is only as secure as your password. Use a long, random password or passphrase. This tool uses PBKDF2 with 600,000 iterations.
The initialization vector (IV) is required for decryption but does not need to be secret. Store it alongside the encrypted data.
Explore more tools in the Security workspace:
JWT Decoder
Decode and inspect JWT tokens instantly.
Password Generator
Generate strong, secure random passwords with customizable options.
Passphrase Generator
Generate memorable, secure passphrases from word lists.
UUID Generator
Generate UUID v4 identifiers instantly.
UUID Validator
Validate UUID strings and identify the version (v1, v2, v3, v4, v5).
Hash Generator
Generate SHA-1, SHA-256, SHA-384, and SHA-512 hashes from text.