AES-256 Encrypt / Decrypt

Password-based AES-256-GCM encryption performed entirely in your browser with the native Web Crypto API.

Plaintext (to encrypt) or ciphertext (to decrypt)
Output

How the encryption works

Your password is stretched with PBKDF2-SHA256 (150,000 iterations, random 16-byte salt) into a 256-bit AES-GCM key. Each message gets a fresh random 12-byte IV. The output is a single Base64 string in the self-describing format TF1.salt.iv.ciphertext — salt and IV travel with the message, so only the password needs to be remembered to decrypt. GCM also provides integrity: a wrong password or tampered ciphertext fails instead of returning garbage.

FAQ

Can you recover my password?

No. The password never exists anywhere except this page's memory. Lose it and the ciphertext is unrecoverable.

Can I decrypt the output in other tools?

The format is specific to this tool. OpenSSL compatibility (e.g. enc -aes-256-gcm interop) is on the roadmap.

Is my plaintext or password uploaded?

No. Everything — key derivation, encryption, decryption — happens locally.

AES-256 Encrypt / Decrypt — FAQ

Is AES-256 Encrypt / Decrypt free to use?

Yes. It is completely free, with no signup, no installation and no usage limits.

Is my data uploaded to a server?

No. The tool runs entirely in your browser — the data you paste or upload never leaves your device.

Does it work on mobile devices?

Yes. It works in any modern desktop or mobile browser, with nothing to install.