Tooleux

JWE Encrypt

JWE (2)

Encrypt content with JWE using RSA, AES Key Wrap, or a shared secret.

Runs in your browser. Nothing leaves your device.
Encrypt content with JSON Web Encryption (JWE) in your browser. Supports RSA-OAEP, A256KW, and direct key management with A256GCM. Free, offline, runs client-side. Read more Show less

What is JWE?

JSON Web Encryption (JWE) is a standard defined in RFC 7516 for encrypting arbitrary content so that only the intended recipient can read it. Unlike JWS (the signing format used by most JWTs), JWE protects confidentiality - the payload is unreadable to anyone without the decryption key.

JWE is used by OpenID Connect (the "encrypted ID token" flow), OAuth 2.0 token encryption, and any system that needs to pass sensitive data between parties without exposing it in transit. It supports both symmetric encryption (a shared secret) and asymmetric encryption (public/private key pairs).

How to use

Enter the plaintext and a key, choose the algorithms, and press Encrypt. The output is a compact JWE string in the standard five-part format separated by dots: header.encrypted_key.iv.ciphertext.tag.

To decrypt, use JWE Decrypt with the matching key.

All encryption happens in your browser. Nothing is uploaded.

The two algorithms

Every JWE has two algorithms in its header:

alg (key management) - how the content encryption key is protected. RSA-OAEP wraps it with an RSA public key. A256KW wraps it with AES Key Wrap. "dir" means the shared secret is the content encryption key, with no wrapping.

enc (content encryption) - how the payload is encrypted. A256GCM is the recommended default: authenticated, fast, and widely supported. A128CBC-HS256 is the only non-AEAD option and is included for interop with older systems.

Key management algorithms

RSA-OAEP - RSA with optimal asymmetric encryption padding, using SHA-1. Legacy but widely supported.

RSA-OAEP-256 - RSA-OAEP with SHA-256. The modern recommendation. Use this if you have a choice.

A256KW - AES-256 Key Wrap. Symmetric key wrapping - you need the same 32-byte key on both sides.

dir - Direct use. The shared secret is used directly as the content encryption key. Simplest and fastest, but the key must be exactly the right length for the chosen enc algorithm.

Content encryption algorithms

A256GCM - AES-256-GCM. The recommended default. Authenticated, fast, no padding oracle issues.

A192GCM / A128GCM - Same as above with shorter keys.

A128CBC-HS256 - AES-128-CBC with HMAC-SHA-256. Older but common in legacy systems. Uses Encrypt-then-MAC, so it is authenticated, but is slower than GCM.

FAQ

JWE vs JWS vs JWT

JWS (JSON Web Signature) proves integrity - anyone can read the payload but no one can modify it without the signing key. JWE (JSON Web Encryption) protects confidentiality - the payload is unreadable without the decryption key. A JWT is often a JWS, but can also be a JWE, or even a JWE containing a JWS (nested JWT). They solve different problems.

Should I use symmetric or asymmetric?

Use asymmetric (RSA-OAEP-256) when the sender and receiver are different parties and the sender should not be able to decrypt what they encrypted. Use symmetric (A256KW or dir) when both sides already share a key and you want the fastest option.

How big can the plaintext be?

JWE has no size limit. The compact serialization produces a string about 1.4x the size of the plaintext (due to Base64URL), plus the header. For very large payloads, use JSON Web Encryption with multiple recipients or a different protocol.

Is JWE authenticated?

Yes, when using an AEAD content encryption algorithm (any of the GCM variants) or A128CBC-HS256 (which uses Encrypt-then-MAC). Any modification to the ciphertext will cause decryption to fail with an authentication error.

Where do I get a key?

For RSA: generate a key pair on the RSA Key Generator. Encrypt with the public key, decrypt with the private key. For symmetric: generate a random 32-byte key with Random Bytes and use it on both sides.

Does this match OpenSSL or another library?

The compact serialization output follows RFC 7516 exactly. Any compliant JWE implementation (jose, Nimbus, go-jose, python-jose) will decrypt it, provided you use the same algorithms and key.

Command line equivalent
# Node with jose
npm i jose
node --input-type=module -e '
import { CompactEncrypt, importSPKI } from "jose";
import fs from "fs";
const pem = fs.readFileSync("public.pem", "utf8");
const key = await importSPKI(pem, "RSA-OAEP-256");
const jwe = await new CompactEncrypt(new TextEncoder().encode("hello"))
  .setProtectedHeader({ alg: "RSA-OAEP-256", enc: "A256GCM" })
  .encrypt(key);
console.log(jwe);
'

# Python with jwcrypto
pip install jwcrypto
python3 -c '
from jwcrypto import jwe, jwk
from jwcrypto.common import json_encode
key = jwk.JWK.from_pem(open("public.pem","rb").read())
token = jwe.JWE(b"hello", json_encode({"alg": "RSA-OAEP-256", "enc": "A256GCM"}))
token.add_recipient(key)
print(token.serialize(compact=True))
'

# Go with go-jose
# See https://github.com/go-jose/go-jose
Loads a test value into the form
Plaintext
Compact JWE