>_devtools

AES Encrypt & Decrypt (GCM, CBC, CTR)

AES-128/192/256 encryption and decryption in GCM, CBC and CTR modes with a random nonce, a passphrase or raw key, and clear authentication errors.

What this does

Encrypts and decrypts text with AES in GCM, CTR or CBC mode using 128, 192 or 256-bit keys. AES-256-GCM is selected by default. Use a passphrase (turned into a key with PBKDF2 or Argon2id and a random salt) or paste a raw key in hex or Base64.

Which mode

  • GCM encrypts and authenticates. Use it unless you must match an existing system. It takes a 12-byte nonce, produced randomly here, and a 16-byte tag; a message that was changed fails with "authentication failed".
  • CBC needs a 16-byte IV and PKCS#7 padding, and has no authentication. Compatibility only.
  • CTR turns AES into a stream cipher with a 16-byte initial counter block and has no authentication. Compatibility only.

Never reuse a nonce

Repeating a nonce with the same key breaks GCM and CTR completely: it reveals the XOR of the plaintexts and, for GCM, lets an attacker forge messages. This tool always generates a fresh random nonce, which is safe for roughly 232 messages per key with a 96-bit nonce. For more messages per key use XChaCha20-Poly1305 in thetext encryption tool.

Decrypting data from elsewhere

Choose Decrypt, then "Manual parameters", pick the exact algorithm, supply the raw key, the nonce or IV and the ciphertext. For GCM append the tag to the ciphertext, as Web Crypto, Go and most libraries do. Optional additional authenticated data must match what was used when encrypting.

Privacy

Everything is done by your browser's Web Crypto implementation. Keys and text are never stored or sent anywhere.