Real AES-256-GCM authenticated encryption, running in your browser via the Web Crypto API. Not a renamed XOR, not a JavaScript toy implementation — the same primitive that TLS 1.3 uses.
PBKDF2-SHA256, 200,000 iterations, per-message random salt. This is the only realistic option for a browser tool — we never store keys.
AAD is bound to the ciphertext but not encrypted. Decryption requires the same AAD byte-for-byte.
Most "AES online" tools give you three modes: ECB, CBC, and "AES". Half of them default to ECB. ECB mode encrypts each 16-byte block independently, which means two identical plaintext blocks produce two identical ciphertext blocks. For any non-random plaintext — an image, an English message, a JSON document — this leaks structure. We do not offer ECB.
This tool uses GCM (Galois/Counter Mode). GCM is an AEAD — Authenticated Encryption with Associated Data. It produces a ciphertext and a 16-byte authentication tag. The tag is computed over both the ciphertext and the AAD. If either is tampered with, decryption fails and returns an error instead of returning modified plaintext. This is the difference between encryption and authenticated encryption.
The key is derived from your passphrase via PBKDF2-SHA256 with 200,000 iterations. That's the OWASP 2023 minimum for PBKDF2-SHA256. Higher is better, slower is the cost. If you have a true random 32-byte key (e.g., from our CSPRNG), skip the passphrase entirely and convert that key to hex.
The default IV is generated fresh on each encrypt. Never reuse an IV with the same key in GCM. Reuse breaks the authentication property catastrophically. This is the single most common implementation bug in real-world AES-GCM code. The tool enforces a fresh IV unless you explicitly type one.
You need to confirm what "AES-256" actually buys you in a given mode. This tool makes the IV, salt, and tag explicit. They become inspectable. That visibility catches the bugs that real code review misses.
GCM is the default authenticated mode in TLS 1.3, SSH, and modern disk encryption. Understanding it here means understanding how half the secure web works.
Encrypt a message locally, send the ciphertext through any channel (email, chat, paper), and have the recipient decrypt it in their browser. No server sees the plaintext.