🔒 Text Encrypt/Decrypt (AES)
Encrypt text with a passphrase using AES-GCM (via your browser's Web Crypto API) and decrypt it again with the same passphrase. Everything happens locally — nothing is sent anywhere. This is for casual/personal use; for anything highly sensitive, use dedicated, audited encryption software instead.
What the Encrypt button actually does
Your passphrase is not the key. It is stretched into one with PBKDF2, and the salt and nonce are drawn fresh from the browser's random generator on every press:
key = PBKDF2-HMAC-SHA256(passphrase, salt, 100000 rounds) -> 256 bits
out = base64( salt[16] || iv[12] || AES-256-GCM(key, iv, text) )
GCM appends a 16-byte authentication tag, so a ciphertext altered by one character fails outright rather than decrypting to garbage. Overhead is a fixed 44 bytes: the 25-character sample message comes back as 92 characters of Base64.
How much protection this really gives
- Change the passphrase before you trust anything to it. The box is pre-filled with correct-horse-battery-staple, which is on every wordlist in the world.
- 100,000 PBKDF2 rounds is a modest work factor. Current guidance for this hash is several hundred thousand, so someone who steals the Base64 can grind guesses offline quickly. A short or dictionary passphrase will not survive that; five random words will.
- The passphrase field is ordinary text, not a password input. It is readable over your shoulder and on a shared screen.
- Keep the whole Base64 string. The first 28 bytes are the salt and IV. Trim them and the passphrase alone can never recover the message.
Frequently asked questions
Why does the same text encrypt to a different string every time?
A new 16-byte salt and 12-byte IV are generated per encryption and stored in front of the ciphertext. Identical output would leak the fact that two messages match, so random ones are the point.
Can I recover my text if I forget the passphrase?
No, and there is no reset. Decryption either produces the exact plaintext or fails; nothing tells you whether a guess was close. Store the passphrase somewhere before you close the tab.
Do I need the same browser to decrypt it later?
No. The format is plain AES-256-GCM with the salt and IV prefixed, so any script implementing PBKDF2 and GCM the same way will read it. Nothing is stored on this machine.