Skip to main content
WizTools123
WizTools123
Free Online Tools

Tool Categories


Security Tools New Tool

Free Online AES Encrypt and Decrypt with AES-GCM and AES-CBC

Encrypt or decrypt text with AES-GCM or AES-CBC, 128 or 256 bit. The key is derived from your passphrase with PBKDF2 rather than used directly, the salt and the initialisation vector travel inside the output so nothing is lost, and the whole thing runs in your browser with nothing uploaded.

Free Forever Nothing Uploaded GCM Detects Tampering Nothing Uploaded
Free Online AES Encrypt and Decrypt with AES-GCM and AES-CBC
Share this tool
Advertisement Slot (Top Banner) Google AdSense Unit • Responsive Banner
AES Encrypt & Decrypt Everything happens in this tab. Nothing you paste is sent anywhere.
Your text
Result
Direction
Key from
PBKDF2 Iterations. Whoever decrypts has to use the same number, so it is written into the output.
Output

Buy Us A Coffee

Enjoying WizTools123? Help keep our server infrastructure 100% free and open for everyone.

Buy Us A Coffee
Sponsored Content (Below Tool) Google AdSense Placement

What a Cipher Does Not Protect You From

Four things, and the first one surprises people.

AES is sound. Almost everything that goes wrong with encrypted data goes wrong around it, and knowing which problems the cipher does not solve is most of using it properly.

The length of the message is not hidden. Ciphertext is about as long as the plaintext, so an observer learns the size of what you sent, and sometimes that is the whole secret: a yes or a no, which of five documents, how many records. If the length matters, pad before encrypting, and know that this page does not pad for you.
CBC does not tell you whether the ciphertext was altered. Someone who cannot read your message can still flip bits in it, and CBC will decrypt the result into something different without complaint. That is why GCM is the default here: it carries a tag that fails loudly if a single bit has changed. If you are choosing, choose GCM. CBC is offered because data encrypted years ago still has to be read.
Never use the same key and the same initialisation vector twice with GCM. Repeating that pair does not just leak information, it can expose the key used for the tag and let an attacker forge messages. This page generates a fresh random IV for every encryption, which is why encrypting the same text twice gives different output, and why that is correct rather than a bug.
A passphrase is not a key, and the gap between them is PBKDF2. Using passphrase characters directly as key bytes is the single most common mistake in home made encryption, and it reduces a 256 bit key to whatever a person can type. Here the passphrase goes through PBKDF2 with a random salt and a quarter of a million iterations, which is also why the salt and the iteration count have to travel with the ciphertext.

How to Encrypt Text with AES

A few steps, and nothing is uploaded.

1
Pick the direction and the mode Encrypt or decrypt, with GCM unless you are reading something old that used CBC. GCM is the one that notices if the ciphertext has been changed.
2
Give a passphrase, or a raw key A passphrase is turned into a key by PBKDF2 with a random salt. A raw hex key is used as it is, which is what you want when the data came from somewhere else.
3
Read the output as one blob, or as fields The single base64 blob carries the version, the salt, the IV and the ciphertext together, so there is nothing to lose. The field view shows each part separately when you need to hand them to something else.
4
To decrypt, paste the whole blob back The salt, the IV and the iteration count are read out of it, so only the passphrase is needed. If any of it has been altered, GCM says so instead of producing nonsense.

What to Know About AES

Including what a cipher does not protect you from.

Encrypting the same text twice gives different output, and that is correct. A fresh random salt and a fresh random initialisation vector are used every time, so identical input produces different ciphertext. If a tool gives you the same answer twice for the same input, it is reusing the IV, which is a real weakness rather than a convenience.
The output of this page is a format of its own, not a standard. It is a version byte, then the salt, the IV, the iteration count and the ciphertext, packed together and written as base64. Anything else decrypting it needs to know that layout, which is set out in the fields view. If you need to interoperate with another system, use the raw key option and the fields view, and match its layout rather than this one.
AES-CBC here has no authentication, so a wrong passphrase may produce rubbish instead of an error. With GCM a wrong key fails cleanly, because the tag does not verify. With CBC the padding check usually fails, which this page reports, but it can also pass by chance and hand you meaningless bytes. That is a property of the mode, and the reason the mode is labelled on the page rather than hidden.
This page cannot keep anything for you, and will not try. There is no history and no saved setup here, deliberately: a passphrase in browser storage is exactly the thing that gets found later. Copy what you need before closing the tab, because closing it is the whole of the cleanup.

Key Features & Capabilities

What this tool does, and what it deliberately does not.

GCM and CBC GCM for new work, CBC for data that already exists, with the difference stated.
PBKDF2 key derivation A passphrase becomes a key properly, with a random salt and an iteration count you can set.
Self contained output Salt, IV and iteration count packed with the ciphertext, so decryption needs only the passphrase.
Raw keys too A 128 or 256 bit key in hex, for data produced by another system.
The parts shown Salt, IV, tag length and ciphertext listed separately, so the format is not a mystery.
Nothing remembered No history, no saved setups. A passphrase never reaches browser storage.

About AES in a Browser

AES is the block cipher almost everything uses, and in a browser it comes from Web Crypto, the same implementation behind HTTPS. That means the hard part of this page is not the encryption at all. It is everything around it: turning a passphrase a person can remember into a key of the right size, generating an initialisation vector that is never reused, choosing a mode that notices tampering, and keeping those pieces together so that the person decrypting is not left hunting for a salt they were never given.

The choices here are the conventional ones. GCM is the default because it authenticates as well as encrypts, so a changed ciphertext fails loudly instead of decrypting into something subtly different. The key comes from PBKDF2 rather than from the passphrase bytes, with a random salt and a quarter of a million iterations by default. The salt, the IV and that iteration count are packed into the output with a version byte, which is why the single blob can be decrypted with nothing but the passphrase.

CBC is offered without enthusiasm, for one reason: data encrypted years ago still has to be read, and refusing to read it would not make anyone safer. The page labels it as having no tamper detection every time it is selected. A wrong passphrase in CBC often shows up as a padding error, which is reported, and occasionally as meaningless output, which is the mode behaving exactly as designed and the reason not to choose it for new work.

The honest limit of a tool like this is that it is a browser tab. The arithmetic is as sound as anywhere, and nothing is uploaded, but the machine you are sitting at sees your passphrase whatever the page does. For a one off message, a test fixture or a note to yourself that is fine. For a key that protects something that matters over time, generate and use it where it lives, and keep this page for the occasions when you need to look at the result.

Frequently Asked Questions

Modes, passphrases, and what the output contains.

GCM, unless you are decrypting something that was made with CBC. GCM encrypts and authenticates, so it tells you when the ciphertext has been altered. CBC only encrypts, and a modified ciphertext decrypts into different plaintext without any complaint.

Because a new random salt and a new random initialisation vector are used each time. That is required: repeating an IV with the same key in GCM is a serious weakness. Identical output for identical input would be the thing to worry about.

Yes, if you follow the layout. The blob is a version byte, the salt, the IV, the iteration count and the ciphertext, which the fields view sets out. For easier interoperability, use a raw hex key and the fields view, and feed the parts to your own library directly.

The default of 250,000 is a reasonable figure for a browser. More is better up to the point where it becomes annoying to wait, and whoever decrypts has to use the same number, which is why it is written into the output rather than assumed.

No. The encryption runs in the browser own cryptography, with no request made. There is also no history and no saved setup here, so nothing is written to browser storage either.

Every Other Security Tool

10 more tools in this set. All free, all in your browser.

Advertisement Slot (Bottom Banner) Google AdSense Unit • Responsive Banner