What this does
Encrypts and decrypts text with AES-GCM (128, 192 or 256-bit), ChaCha20-Poly1305, XChaCha20-Poly1305, and, for compatibility with older systems, AES-CTR and AES-CBC. The key comes from a passphrase or from a raw key you supply. Every encryption produces a self-describing envelope that carries everything needed to decrypt except the secret.
Safe by default
- A fresh random nonce (12 bytes, or 24 for XChaCha20) comes from the browser's secure random generator for every message. You cannot choose or reuse one.
- Passphrases go through PBKDF2-HMAC-SHA256 (600,000 iterations) or Argon2id (19 MiB, 2 passes) with a new random 16-byte salt, shown in the result and stored in the envelope.
- GCM and Poly1305 authenticate the data. If the passphrase is wrong or one bit of the envelope changed, decryption fails with "authentication failed" and no plaintext is produced.
- KDF parameters read from a pasted envelope are capped, so a hostile envelope cannot make your browser spin.
Envelope format
JSON output looks like {"v":1,"alg":"AES-256-GCM","kdf":{...},"nonce":"...","ct":"...","tag":"..."}with Base64 values; the compact form isdtenc1.AES-256-GCM.pbkdf2-sha256:600000:salt.nonce.ct.tag. This is this tool's own format, so other software will not read it directly. To decrypt data from another system, use "Manual parameters" with the algorithm, a raw key, the nonce or IV, and the ciphertext (with the tag appended for GCM and ChaCha20-Poly1305).
Compatibility-only modes
AES-CBC and AES-CTR provide confidentiality but no integrity. Anyone can modify the ciphertext in predictable ways, and a wrong key may produce garbage instead of an error. CBC is also exposed to padding-oracle attacks when error messages are observable. If you must use them, authenticate the IV and ciphertext with an HMAC (encrypt-then-MAC) using a separate key; the HMAC generator shows how. Otherwise choose AES-GCM or ChaCha20-Poly1305.
Notes and limits
Plaintext is limited to 8 MiB of UTF-8 text. This is a developer utility for testing and interoperability, not a replacement for audited tools such as age or GnuPG. Passphrase strength is up to you: a weak passphrase is guessable however good the cipher is.
Privacy
Encryption runs in a background worker in your browser. Keys, passphrases and plaintext are never stored or sent anywhere.