Skip to content

AES Encryption / Decryption

Free AES encryption and decryption online tool for AES-256-GCM (recommended) and AES-CBC. Derive a key from a passphrase with PBKDF2, paste a raw hex/Base64 AES encryption key, or generate one. Runs entirely via the Web Crypto API — plaintext is never uploaded.

  • AES-GCM (default) and AES-CBC
  • AES-256 or AES-128 key sizes
  • Passphrase (PBKDF2) or raw hex/Base64 key
  • Random AES encryption key generator
  • IV auto-generated and bundled in the JSON package
  • 100% client-side via Web Crypto — nothing uploaded

Cryptographer

Runs in your browser via Web Crypto — plaintext never uploaded

Ciphertext package (JSON)

Format: JSON with alg, ks,iv, ct — plussalt / iter when a passphrase is used. Compact paste also accepted: iv:ct orsalt:iv:ct (Base64).

How to encrypt or decrypt text with AES

  1. 01

    Choose mode and algorithm

    Pick Encrypt or Decrypt, then AES-GCM (recommended) or AES-CBC, and AES-256 or AES-128.

  2. 02

    Provide a key

    Enter a passphrase (PBKDF2 derives the key) or a raw hex/Base64 key. Use Generate random key when you need a fresh AES encryption key.

  3. 03

    Paste plaintext or the ciphertext package

    For encrypt, type the text. For decrypt, paste the JSON package produced earlier (IV and ciphertext together).

  4. 04

    Run and copy the result

    Encrypt embeds a random IV in the package. Decrypt restores the plaintext when the same key and package are used.

What AES encryption online should (and should not) do#

AES (Advanced Encryption Standard) is the block cipher almost every modern system uses to keep data confidential. An AES encryption online tool is useful when you need to encrypt text AES 256 for a quick test, a demo, or a local workflow — but only if cryptography runs in your browser. This page is an AES encryption and decryption workspace built on the Web Crypto API: plaintext, passphrases, and raw keys are processed locally and are never uploaded.

That client-side boundary matters for encrypt text AES 256 online use cases. A server-side “free encryptor” that accepts your secret over HTTP is asking you to trust an unknown operator with the very data you wanted to protect. Prefer tools that state clearly that work stays on-device, and treat even a good browser tool as a convenience layer — not a full key-management product.

AES-256 vs AES-128, and what AES-256-GCM actually is#

AES-128 and AES-256 describe the key length (128 or 256 bits). Both are secure when used correctly; AES-256 is the common default in new designs and is what people mean by AES 256 encrypt decrypt online. The larger key raises the brute-force cost further, which is why this tool defaults to 256-bit keys.

What is AES-256-GCM? It is AES with a 256-bit key in Galois/Counter Mode. GCM encrypts and also authenticates: if someone tampers with the ciphertext or you use the wrong key, decryption fails instead of returning silent garbage. That is why AES 256 GCM online / AES GCM encryption online tool workflows prefer GCM over older modes for new work. Is AES-256-GCM secure? Yes, when IVs are unique per key, implementations are constant-time and vetted (as in Web Crypto), and keys stay secret. It is widely standardized and used in TLS 1.3 and many storage systems.

GCM vs CBC, keys, and CryptoJS compatibility#

AES-CBC only provides confidentiality (with PKCS#7 padding in Web Crypto). It does not authenticate. A wrong key may yield nonsense plaintext rather than a hard failure, and CBC needs careful IV handling. Prefer AES-GCM unless you must interoperate with a CBC-only peer. This tool still offers CBC for those cases.

An AES encryption key is raw key material — 16 bytes for AES-128 or 32 bytes for AES-256 — usually shown as hex or Base64. The built-in AES encryption key generator fills a cryptographically random hex key via crypto.getRandomValues. A passphrase is not the AES key itself: this tool runs PBKDF2-HMAC-SHA-256 (210,000 iterations) with a random salt stored in the JSON package so the same passphrase can unlock the ciphertext later.

People searching cryptojs aes often expect OpenSSL-compatible ciphertext from the CryptoJS library. This tool does not use CryptoJS. It uses the browser’s Web Crypto API. The ideas (AES, GCM/CBC, passphrases) overlap, but ciphertext encodings, KDF parameters, and OpenSSL “Salted__” blobs are not interchangeable. Decrypt CryptoJS output with CryptoJS (or a matching OpenSSL pipeline); use this package format with this tool.

Output format and safe habits#

On encrypt, a fresh IV is generated (12 bytes for GCM, 16 for CBC), shown for inspection, and embedded in a JSON package: alg, ks, iv, ct, plus salt and iter when a passphrase was used. You can also paste compact iv:ct or salt:iv:ct (Base64) on decrypt if you set algorithm and key size in the UI. Never reuse an IV with the same key in GCM. Store raw keys like passwords. For real production systems, use a proper KMS or sealed secrets — this page is for transparent, local AES encryption examples and day-to-day encrypt/decrypt checks.

Frequently asked questions

Is it safe to encrypt text AES 256 online with this tool?

Yes for confidentiality of the operation itself: encryption runs in your browser via Web Crypto and plaintext is never uploaded. Safety still depends on key strength, not reusing GCM IVs, and not pasting secrets into untrusted extensions or shared machines.

What is the difference between AES-256 and AES-128?

Only the key length. AES-256 uses a 256-bit key; AES-128 uses 128 bits. Both are considered secure with proper modes and random IVs. This tool defaults to AES-256 because it is the usual modern choice for new AES 256 encrypt decrypt online workflows.

GCM vs CBC — which should I use?

Prefer AES-GCM. It authenticates ciphertext so wrong keys or tampering fail closed. AES-CBC encrypts without authentication and is mainly for legacy interoperability. The default here is AES-GCM for AES 256 GCM online use.

What is AES-256-GCM and is it secure?

AES-256-GCM is the AES block cipher with a 256-bit key in Galois/Counter Mode, providing encryption plus integrity. It is secure when IVs are unique per message under a key and the implementation is sound — Web Crypto’s AES-GCM is the right primitive for browser-side work.

How does the AES encryption key generator work?

Generate random key creates a cryptographically random raw key with crypto.getRandomValues and fills it as hex (32 bytes / 64 hex digits for AES-256). Store it offline; anyone with the key and the JSON package can decrypt.

Can I decrypt CryptoJS AES output here?

Not reliably. CryptoJS often uses its own OpenSSL-compatible salted format and different defaults. This tool uses Web Crypto with an explicit JSON package (iv, ct, optional salt/iter). Same algorithm family, different ciphertext formats — they are not drop-in compatible.

Where is the IV and how do I decrypt later?

On encrypt, the IV is auto-generated, shown in its own panel, and stored inside the JSON package. To decrypt, paste that whole package and use the same passphrase or raw key. You do not need to paste the IV separately when using the JSON output.

Why did decryption fail?

Usually a wrong key, a truncated package, mixed-up passphrase vs raw-key mode, or tampered GCM ciphertext. GCM reports an authentication error instead of returning corrupted text. Double-check you pasted the full JSON and matched AES-GCM/CBC and 128/256 to how it was encrypted.

Developers

UUID Generator

Generate cryptographically random UUID v4 or time-ordered UUID v7, in bulk.

Developers

Base64 Encoder & Decoder

Encode and decode Base64 with correct UTF-8 handling, including the URL-safe alphabet.

Developers

ULID Generator

Generate ULIDs — sortable by creation time like UUID v7, but Crockford Base32 instead of hex.