🔒 Text Encrypt/Decrypt (AES)

Encrypt text with a passphrase using AES-GCM (via your browser's Web Crypto API) and decrypt it again with the same passphrase. Everything happens locally — nothing is sent anywhere. This is for casual/personal use; for anything highly sensitive, use dedicated, audited encryption software instead.

What the Encrypt button actually does

Your passphrase is not the key. It is stretched into one with PBKDF2, and the salt and nonce are drawn fresh from the browser's random generator on every press:

key  = PBKDF2-HMAC-SHA256(passphrase, salt, 100000 rounds) -> 256 bits
out  = base64( salt[16] || iv[12] || AES-256-GCM(key, iv, text) )

GCM appends a 16-byte authentication tag, so a ciphertext altered by one character fails outright rather than decrypting to garbage. Overhead is a fixed 44 bytes: the 25-character sample message comes back as 92 characters of Base64.

How much protection this really gives

The maths here is the browser's own audited Web Crypto, and nothing is uploaded - but this is a web page, not a hardened tool. For material that would genuinely hurt you if exposed, use offline software such as GnuPG or age.

Frequently asked questions

Why does the same text encrypt to a different string every time?

A new 16-byte salt and 12-byte IV are generated per encryption and stored in front of the ciphertext. Identical output would leak the fact that two messages match, so random ones are the point.

Can I recover my text if I forget the passphrase?

No, and there is no reset. Decryption either produces the exact plaintext or fails; nothing tells you whether a guess was close. Store the passphrase somewhere before you close the tab.

Do I need the same browser to decrypt it later?

No. The format is plain AES-256-GCM with the salt and IV prefixed, so any script implementing PBKDF2 and GCM the same way will read it. Nothing is stored on this machine.