AES Encrypt / Decrypt
Encrypt and decrypt text with AES-GCM
Choose encrypt or decrypt, enter the text and password, then run it first; option details and failure comparisons are available in Advanced mode.
—The full guide also includes pitfalls, worked examples, snippets, FAQs, and related tools for checking results or troubleshooting.
About this tool
Encrypt UTF-8 text with AES-256-GCM using a key derived from a text password by PBKDF2-SHA256. Each encryption draws a fresh 16-byte salt and 12-byte IV from Web Crypto. The output is Base64(salt).Base64(iv).Base64(ciphertext plus 16-byte tag), with no additional authenticated data. To decrypt, supply the same password and iteration count; the count is not stored in the payload. This is a specific interoperability format, not a reader for every AES ciphertext. Plaintext and passwords are not uploaded or saved as drafts.
Production Snippets
Decrypt a fixture produced by independent Node crypto
text
Mode: Decrypt
Password: Toolskit-2026
PBKDF2 iterations: 150000
Payload:
ABEiM0RVZneImaq7zN3u/w==.AAECAwQFBgcICQoL.LANSgCuzJveE6mqH257JcfY+E0SrELE71yz8a8mXTcCMz8qC8lhMBwOY3+7jbgXkyEjnnJJR
Expected plaintext: ToolsKit AES interoperability example.
Fixed salt and IV are for this published fixture only.Frequently Asked Questions
What exactly is in salt.iv.ciphertext?
Three standard Base64 segments separated by dots, with required = padding where applicable. The salt is 16 bytes, IV is 12 bytes, and the final segment contains ciphertext followed by the 16-byte GCM authentication tag. It is not Base64url, OpenSSL salted format, CBC, or an AES file container.
Which settings must match to decrypt external output?
AES-256-GCM; a 128-bit authentication tag appended to ciphertext; PBKDF2 with HMAC-SHA256; the same UTF-8 password, salt, and iteration count; a 12-byte IV; and no AAD. This tool requires its 16-byte salt and three-part Base64 envelope. A raw key is not accepted in place of the password.
How are iteration counts handled?
The default is 150000 and the interface accepts integers from 10000 to 600000. Fractions and values outside that range are rejected. Keep the chosen number with your test settings because it is not embedded in the payload. These interface limits are not a universal production security recommendation.
Why does the ciphertext change for the same text and password?
Every encryption generates a fresh random salt and IV. Different results are expected. The published decryption fixture uses fixed values only to make the example reproducible; do not reuse that fixture’s IV and salt for new encryption.
What causes an authentication failure or unreadable output?
A wrong password, different iteration count, altered ciphertext/tag, or mismatched parameters can cause GCM authentication failure. Authenticated bytes must also decode as valid UTF-8 for this text tool. It cannot recover a forgotten password or infer missing parameters.
Are plaintext and passwords retained?
They are not uploaded or saved in a localStorage draft. The old combined plaintext/password draft is deleted on page open. Editing or clearing input invalidates pending crypto results. PBKDF2 raises guessing cost but does not turn a weak password into a high-entropy secret.
Keep browsing