Encrypt and decrypt text strings with AES-256-GCM and PBKDF2 key derivation, entirely in your browser. Output is a portable Base64 string. Nothing uploaded.
Most password managers and secure-note apps encrypt locally before syncing, but sometimes you just need to turn a raw text string into something unreadable, share the output over an insecure channel, and let the recipient reverse it with nothing but a passphrase. That is what this tool does: no account, no server, no upload.
Type or paste any text, set a passphrase, and click Encrypt. The output is a self-contained Base64 string that embeds the random salt and IV used for that specific encryption, so decryption needs only the ciphertext and the passphrase, with no side channel for the parameters.
ATXT, the 16-byte PBKDF2 salt, and the 12-byte GCM IV before the ciphertext, so no side channel is needed to pass these values to the decryptor.Click Sample to load: Service: Northwind Payments API / Key: npk_live_4Xr8mKqZ2wJsLv9YbTcDnF1eUoHgPi0A / Environment: production / Rotate every 90 days. Enter any passphrase and click Encrypt. A 280+ character Base64 string appears. Switch to Decrypt, paste it, use the same passphrase, and the original credential block comes back verbatim. Change even one character of the ciphertext and you will see: “Decryption failed — wrong passphrase, or the ciphertext has been modified.”
150 / 50,000 characters
How this works
Your passphrase is stretched into a 256-bit key via PBKDF2 (250,000 × SHA-256). The text is then encrypted with AES-256-GCM, which also authenticates the ciphertext — any tampering makes decryption fail rather than silently returning garbage. A fresh random salt and IV are generated per encryption, so the same plaintext + passphrase produces a different ciphertext every time.
⚠ Nothing is uploaded. All cryptography runs in your browser tab.