# AES Encrypt / Decrypt

> Encrypt or decrypt text with a password using AES-256-GCM. The encryption runs entirely in your browser, the password never leaves the page, and the result is a portable text envelope you can paste into an email, a chat, or a file.

URL: https://uttir.com/aes-encrypt
Categories: security-tools, developer-tools, encoding-tools
Privacy: Encryption and decryption run in your browser. The password and the message never leave the page.

## About

Encrypt text with a password and paste the result into an email, a chat, or a file. The recipient decrypts with the same password.

Encryption is AES-256-GCM (authenticated, so tampering is detected). Keys are derived from the password with PBKDF2-SHA256 and 250,000 iterations. Everything runs in your browser — the password and the message never reach a server.

## How to use

1. **Choose encrypt or decrypt** — Two modes. Same password field, different input and output sides.
2. **Pick a strong password** — A random 20-character string is the right pick for sensitive data. Use the password generator if you do not have one.
3. **Encrypt or decrypt** — The result is a portable text envelope you can paste anywhere.

## Examples

### Send a one-time secret in an email

Encrypt a password, a token, or a short message with a passphrase. Send the ciphertext in an email, share the passphrase by phone. The recipient pastes the ciphertext, enters the passphrase, and gets the original.

Input:

```
Plaintext: "Meeting at 3pm, use the back door"
Password: "blue-river-42"
```

Output:

```
A v1:base64... envelope that decrypts only with "blue-river-42".
```

### Encrypt a note for yourself

Store a ciphertext in a note-taking app, a password manager, or a file. Decrypt it from any device with the password. Useful for API keys, recovery codes, or anything you do not want in plaintext.

Input:

```
Plaintext: an API key
Password: a strong password you remember
```

Output:

```
The ciphertext is safe to store. Only the password unlocks it.
```

## FAQ

### Is my password uploaded?

No. The password, the plaintext, and the ciphertext all stay in your browser. The encryption runs locally using the Web Crypto API. Close the tab when you are done and there is no trace.

### Which algorithm is used?

AES-256-GCM (authenticated encryption) for the message, PBKDF2-HMAC-SHA256 with 250,000 iterations for key derivation. These are the standard choices for password-based encryption in 2026 and are well above the threshold for brute-force resistance.

### What is the "v1:" prefix?

A version marker for the envelope format. If the parameters ever change (more iterations, a different hash, a different cipher), a new version is introduced and old envelopes still decrypt. Today everything is v1.

### Can the recipient decrypt on a different device?

Yes. The envelope is plain text. Paste it into the same tool on any device, enter the password, and the original message comes back. The tool is the same on every device because it runs in the browser.

### What happens if the ciphertext is tampered with?

AES-GCM detects tampering. If a single byte of the ciphertext is changed, decryption fails with an error. The original message cannot be recovered from a tampered envelope, by design.

### What if I forget the password?

The message is unrecoverable. There is no backdoor and no reset — that is the trade-off for end-to-end encryption. Store the password in a password manager, write it down, or use a recovery code.

### Why 250,000 iterations of PBKDF2?

It balances brute-force resistance with a tolerable wait. A 2026 attacker with a GPU can test billions of password guesses per second; 250,000 iterations of PBKDF2-SHA256 slow each guess to ~1ms. For high-stakes data, use Argon2 or scrypt — but neither is built into the browser, so PBKDF2 is the practical default.

## Related tools

- [Password Generator](https://uttir.com/password-generator) — Create strong, random passwords with custom length and character sets — right in your browser.
- [Password Strength Checker](https://uttir.com/password-strength-checker) — See how strong a password really is — entropy, time-to-crack, and a list of issues, all computed in your browser.
- [Hash Generator](https://uttir.com/hash-generator) — Generate MD5, SHA-1, SHA-256, and SHA-512 hashes of any text instantly.
- [JWT Decoder](https://uttir.com/jwt-decoder) — Decode a JWT’s header and payload and check its expiration — without sending it anywhere.
- [Base64 Encoder](https://uttir.com/base64-encoder) — Encode any text — including emoji and non-Latin scripts — into standard Base64.
- [Base64 Decoder](https://uttir.com/base64-decoder) — Decode Base64 back into readable text, with clear errors for malformed input.
- [URL Encoder](https://uttir.com/url-encoder) — Percent-encode text for safe use in URLs — as a query value or a full URL.

---

For the full HTML page with the live tool, visit https://uttir.com/aes-encrypt.
This file is the markdown rendering at https://uttir.com/aes-encrypt.md. See https://uttir.com/llms.txt for a site-wide summary.
