๐Ÿ” Text Encryptor

Output
(empty)

Encrypt text using a passphrase with AES-GCM, or decrypt previously encrypted text. This uses the browser's built-in Web Crypto API โ€” your text and passphrase are never sent to any server.

How to use

  1. Choose the "Encrypt" or "Decrypt" tab.
  2. Enter the text to encrypt (or the ciphertext to decrypt) along with your passphrase.
  3. Press the run button to see the result โ€” use the copy button to copy it to your clipboard.

How the calculation works

This tool encrypts and decrypts text with a passphrase, entirely in your browser, using the built-in Web Crypto API. Encryption works like this: 1. Generate a random 16-byte salt and a random 12-byte IV (initialisation vector). 2. Derive a 256-bit key from the passphrase and salt with PBKDF2 (SHA-256, 100,000 iterations). 3. Encrypt the text with AES-256-GCM using that key and IV. 4. Join salt + IV + ciphertext (including a 16-byte authentication tag) and encode the result as Base64. To decrypt, the salt and IV are read back from the string, the same key is derived from the same passphrase, and the text is restored. AES-GCM detects tampering, so decryption fails with an error if the passphrase is wrong or even one character of the ciphertext has changed.

Worked example

Plaintext: ็ง˜ๅฏ†ใฎใƒกใƒข (15 bytes in UTF-8) Passphrase: anything Length of the Base64 output: 80 characters Breakdown: salt 16 + IV 12 + ciphertext 15 + tag 16 = 59 bytes โ†’ 80 Base64 characters Encrypting the same text with the same passphrase gives a different string every time, because the salt and IV are random.

Things to be aware of

  • If you forget the passphrase, nobody can recover the encrypted text.
  • The encryption is only as strong as the passphrase. Short or guessable passphrases can be broken by brute force.
  • Neither the text nor the passphrase leaves your browser. If you send the ciphertext to someone, share the passphrase by a different channel.

FAQ

Is the encrypted data stored anywhere?

No. All processing happens entirely inside your browser โ€” your text and passphrase are never sent to any server.

What encryption method does this use?

It uses the browser's standard Web Crypto API: a key is derived from your passphrase using PBKDF2 (100,000 iterations), and the text is encrypted with AES-GCM (256-bit). The output includes a random salt and initialization vector (IV) and is Base64-encoded.

Why does decryption fail?

Either the passphrase is wrong, or the ciphertext was truncated or altered. AES-GCM includes built-in tamper detection, so decryption only succeeds with the exact correct passphrase and an unmodified ciphertext.