Tooleux

AES Encrypt

AES (2)

Encrypt any text with AES-256-GCM using a password or raw key.

Runs in your browser. Nothing leaves your device.
Encrypt text with AES-256-GCM. Free, offline, runs entirely in your browser. Read more Show less

What is AES-GCM encryption?

AES-GCM is an authenticated encryption mode that combines AES encryption with a GMAC authentication tag. It provides both confidentiality and integrity: a modified ciphertext will fail authentication on decryption.

This tool derives an AES-256 key from a password using PBKDF2 with 200,000 iterations, or accepts a raw 32-byte key. The output is a single Base64 string containing the mode byte, optional salt, random IV, ciphertext, and GCM tag. Use AES Decrypt to reverse it.

How to use

Choose Password mode and enter a strong passphrase, or Raw key mode and paste a 64-character hex key. Type your plaintext. The output is the encrypted payload as Base64.

Every encryption uses a fresh random IV and (in password mode) a fresh random salt. Encrypting the same text twice produces different output.

FAQ

Is this safe to use?

Yes, if the password is strong and the site is loaded over HTTPS. The cryptography is native browser Web Crypto, the same primitive used by TLS.

What if I forget the password?

There is no recovery. AES-256 is not practically brute-forceable.

What is the output format?

Base64 of: 1 mode byte, 16-byte salt (password mode only), 12-byte IV, ciphertext, 16-byte GCM tag.

Can I use a raw key?

Yes. Paste a 64-hex-character key (32 bytes). In that case no salt is used and the mode byte is 0x02.

How to verify

AES-GCM uses a random IV on every encryption, so encrypting the same text twice produces different output. This is intentional: it prevents an attacker from learning anything about the plaintext by comparing two ciphertexts.

To verify your result, paste the output into the AES Decrypt tool with the same password. It should return the original plaintext.

Loads a test value into the form
Input
Output