UtilityToolsLab

© 2026 UtilityToolsLab. Built and maintained by the UtilityToolsLab Team.

Free eBooks·About·Changelog·Privacy Policy·Terms of Service·Report a bug
HomeEncryption & KeysAES Text Encryptor

Related Tools

AES File EncryptorRSA Key GeneratorECDSA Key GeneratorCert DecoderCSR Generator

AES Text Encryptor / Decryptor

Encrypt and decrypt text strings with AES-256-GCM and PBKDF2 key derivation, entirely in your browser. Output is a portable Base64 string. Nothing uploaded.

You Might Also Like

All Encryption & Keys

AES File Encryptor

Encrypt or decrypt any file with a passphrase using AES-256-GCM and PBKDF2 key derivation, entirely in your browser. Nothing is uploaded.

RSA Key Generator

Generate RSA key pairs (2048, 3072, 4096-bit) for encryption (OAEP) or signing (PSS) in PEM format using WebCrypto. Download or copy instantly.

ECDSA Key Generator

Generate ECDSA or ECDH key pairs on P-256, P-384, or P-521 in PEM or JWK format using WebCrypto. Private key blurred by default. Nothing uploaded.

Cert Decoder

Paste a PEM certificate and read its subject, issuer, validity dates, SANs, key algorithm and SHA-256 fingerprint. Decoded in your browser only.

Most password managers and secure-note apps encrypt locally before syncing, but sometimes you just need to turn a raw text string into something unreadable, share the output over an insecure channel, and let the recipient reverse it with nothing but a passphrase. That is what this tool does: no account, no server, no upload.

Type or paste any text, set a passphrase, and click Encrypt. The output is a self-contained Base64 string that embeds the random salt and IV used for that specific encryption, so decryption needs only the ciphertext and the passphrase, with no side channel for the parameters.

Getting Your First Text Encrypted

  1. Click Sample to load a realistic API key block into the input, or paste your own text.
  2. Type a passphrase into the Passphrase field, or click Random to generate a 20-character one. The strength bar turns green at 16 characters.
  3. Click Encrypt. A 280+ character Base64 string appears in the output panel.
  4. Click Send to Decrypt panel to verify round-trip to confirm the output decrypts back to the original before you rely on it.
  5. To decrypt later: switch to the Decrypt tab, paste the Base64 string, enter the same passphrase, and click Decrypt.

Algorithm and Wire Format

  • PBKDF2 (250,000 rounds of SHA-256) stretches the passphrase into a 256-bit key. 250,000 rounds adds roughly 0.3 s of computation on modern hardware, making brute-force expensive for an attacker who only has the ciphertext.
  • AES-256-GCM is the symmetric cipher. GCM mode authenticates the ciphertext: any modification to the Base64 output causes decryption to fail rather than silently returning garbled text.
  • Random salt and IV per encryption. The same plaintext and passphrase produce a different Base64 string every time. This prevents frequency analysis across a collection of ciphertexts produced by the same key.
  • Self-contained output. The 32-byte header embeds the 4-byte marker ATXT, the 16-byte PBKDF2 salt, and the 12-byte GCM IV before the ciphertext, so no side channel is needed to pass these values to the decryptor.

Worked Example: Encrypting an API Key

Click Sample to load: Service: Northwind Payments API / Key: npk_live_4Xr8mKqZ2wJsLv9YbTcDnF1eUoHgPi0A / Environment: production / Rotate every 90 days. Enter any passphrase and click Encrypt. A 280+ character Base64 string appears. Switch to Decrypt, paste it, use the same passphrase, and the original credential block comes back verbatim. Change even one character of the ciphertext and you will see: “Decryption failed — wrong passphrase, or the ciphertext has been modified.”

When Not to Use This Tool

  • For files, use the AES File Encryptor on this platform. It handles binary input and sizes up to 100 MB.
  • For sending a secret to someone who does not already know the passphrase, you need asymmetric encryption (RSA or ECDH key exchange). Both key generators are on this platform. This tool requires a pre-shared secret.
  • The maximum input is 50,000 characters. An error names the exact character count when exceeded.
  • Nothing is stored or uploaded. Closing the tab discards all state. Keep a copy of the passphrase separately; there is no recovery path if it is lost.

150 / 50,000 characters

How this works

Your passphrase is stretched into a 256-bit key via PBKDF2 (250,000 × SHA-256). The text is then encrypted with AES-256-GCM, which also authenticates the ciphertext — any tampering makes decryption fail rather than silently returning garbage. A fresh random salt and IV are generated per encryption, so the same plaintext + passphrase produces a different ciphertext every time.

⚠ Nothing is uploaded. All cryptography runs in your browser tab.