AES Text Encryption
Encrypt and decrypt text with AES-256-GCM using a password (PBKDF2 key derivation), entirely in your browser. Strong, standard cryptography with zero uploads.
Last reviewed by the Radiatus Cloud team
AES-256-GCM · PBKDF2 (150k iterations, SHA-256) · output is Base64(salt|iv|ciphertext).
Need this handled by experts?
Radiatus runs VAPT, managed SOC & security engineering for regulated teams.
Encrypt text with a password
Sometimes you need to protect a piece of text so only someone with the password can read it. This tool encrypts and decrypts text using AES-256-GCM with a password-derived key, so you can secure a message or note with strong, standard encryption entirely in your browser.
Why the details here are the right ones
AES-256-GCM is a strong, authenticated encryption standard, authenticated meaning it also detects tampering, not just hides the content. The password is turned into a key using PBKDF2, a deliberately slow derivation that resists password guessing. Together these are sound modern choices. The security rests entirely on the password: a strong one gives real protection, a weak one can be brute-forced regardless of the algorithm. Because it all runs in your browser, the plaintext and the password never leave your machine, which is essential for encryption to mean anything.
Standard encryption, locally
The tool runs entirely in your browser, so nothing you paste is uploaded, which is exactly what you want when the input is your own security-sensitive data.
Related tools
- Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
- Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
- Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
- Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.
Frequently Asked Questions
What encryption does it use?
AES-256-GCM, a strong authenticated standard that both hides the content and detects tampering, with the key derived from your password using PBKDF2.
Why does authenticated encryption matter?
Because it detects if the ciphertext has been tampered with, not just hides it, so you know the decrypted result is genuine and unaltered.
What determines the strength?
The password. AES-256 is effectively unbreakable, so the security rests entirely on a strong password; a weak one can be guessed regardless of the algorithm.
Why does PBKDF2 matter?
It turns the password into a key slowly and deliberately, which resists brute-force guessing of the password far better than using it directly.
Is my text or password uploaded?
No. The encryption runs entirely in your browser, so neither the plaintext nor the password leaves your machine.
Privacy & Security
All processing happens locally in your browser — nothing is uploaded.
How to Use
Enter text and a password, then Encrypt. To decrypt, paste the encrypted output with the same password.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Password Strength Checker
SecurityMeasure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
Password Generator
SecurityGenerate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
Hash Generator
SecurityGenerate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.