AES Text Encryption - Encrypt and Decrypt Text with a Password (AES-256-GCM)
AES Text Encryption
Password-protect a message with AES-256-GCM in your browser
Strong, Standard Crypto
AES-256 in GCM mode, which both encrypts and detects tampering, via the browser's Web Crypto API.
Slow to Guess
600,000 PBKDF2 rounds make each password guess expensive for an attacker.
Self-Contained Output
The encrypted text carries its own salt, IV and settings, so only the password is needed to open it.
Private
Everything runs in your browser; nothing you paste is uploaded.
How It Works
Your password is stretched into a 256-bit key with PBKDF2-HMAC-SHA-256, using a random 16-byte salt so the same password never gives the same key twice. The text is then encrypted with AES-256-GCM and a random 12-byte nonce. GCM adds a 16-byte authentication tag, so a wrong password or any change to the encrypted text is detected instead of producing garbage. The output looks like AESGCM1.600000.salt.iv.ciphertext.
The encryption is only as strong as the password: a long passphrase of several random words is far harder to guess than a short one. Send the password by a different channel from the message. There is no recovery: if you lose the password, nobody, including this site, can decrypt the text. For files or long-term storage, a dedicated tool such as age or 7-Zip with AES is a better fit.
Key Takeaways
- Long passphrases: Several random words beat a short complex password.
- Tamper-evident: GCM rejects altered ciphertext and wrong passwords.
- No recovery: Lose the password and the text is gone for good.