HomeCrypto ToolsAES Encryption & Decryption

AES Encryption & Decryption

Perform ultra-secure AES encryption and decryption with custom modes (GCM, CBC, CTR, CFB, OFB, ECB), variable bit depths (128, 192, 256), PBKDF2 key derivation, 7-language code generators, and visual block inspectors.

Perform ultra-secure AES encryption and decryption with custom modes (GCM, CBC, CTR, CFB, OFB, ECB), variable bit depths (128, 192, 256), PBKDF2 key derivation, 7-language code generators, and visual block inspectors.

This developer tool is built with a privacy-first mindset. All transformations, formatting, and operations execute entirely in your local browser sandbox without transmitting sensitive tokens, keys, or code to external servers.

100% PrivateNo data leaves browser
Zero LatencyReal-time processing
CustomizableConfigurable options
Offline ReadyWorks without internet
Dev-FriendlyStandard compliant
One-Click ExportCopy & download

AES — Advanced Encryption Standard (NIST FIPS 197) — is a symmetric block cipher selected worldwide to secure classified data, financial systems, and internet traffic. Operating on fixed 128-bit blocks with 128, 192, or 256-bit keys, modern AES modes such as Galois/Counter Mode (GCM) provide both high-speed encryption and cryptographic integrity verification.

This tool performs Advanced Encryption Standard (AES, NIST FIPS 197) symmetric encryption and decryption directly in your browser. It supports authenticated Galois/Counter Mode (AES-GCM) with 128-bit integrity tags via the native Web Crypto API, as well as Cipher Block Chaining (CBC), Counter (CTR), Cipher Feedback (CFB), and Output Feedback (OFB). Passphrases are converted to cryptographic keys via PBKDF2-HMAC-SHA256 with up to 250,000 rounds and random 128-bit salts. All encryption and decryption runs 100% locally in your browser with zero server transmission.

1

Step 1

Choose Operation Mode: Select Encrypt to secure plaintext or Decrypt to recover original data from ciphertext.

2

Step 2

Configure Key Derivation: Use Passphrase KDF (PBKDF2-HMAC-SHA256 with custom iterations and 16-byte cryptographic salt) or specify a Raw Hex Cryptographic Key (32, 48, or 64 hex characters for 128, 192, or 256-bit keys).

3

Step 3

Select Cipher Settings: Choose your bit length (AES-128, AES-192, AES-256) and chaining block mode (GCM for modern AEAD authenticated encryption, CBC for standard enterprise workflows, CTR for streaming, or CFB/OFB/ECB).

4

Step 4

Process & Verify: Click Encrypt or Decrypt. The tool generates secure random IVs and salts automatically, computes cryptographic metrics (block count, padding bytes, latency), and outputs Base64, Hex, JSON, or OpenSSL formats.

5

Step 5

Inspect & Export: Use the Code Generator tab for ready-to-run code in Node.js, Web Crypto, Python, Go, Java, PHP, or OpenSSL CLI, or use the Block Inspector to examine 16-byte block alignments.

Developers and security engineers frequently need to verify AES implementations across systems, generate matching code snippets for cross-language applications, encrypt configuration secrets before committing to repositories, and inspect cryptographic block padding and authentication tags. This tool provides instant multi-language code generation (Node.js, Python, Go, Java, PHP, Web Crypto, OpenSSL), block-level analysis, and automated envelope encoding.

Supports native Web Crypto API AES-GCM (AEAD authenticated encryption with 128-bit auth tags) alongside CBC, CTR, CFB, OFB, and ECB modes

PBKDF2-HMAC-SHA256 key derivation with up to 250,000 iterations and 16-byte cryptographic salts protects against dictionary and rainbow table attacks

Automated code generator produces copy-pasteable, verified scripts for Node.js, Web Crypto, Python, Go, Java, PHP, and OpenSSL CLI

Interactive block inspector visualizes 16-byte block alignments, hex byte allocations, and PKCS#7 padding additions

100% browser-based client-side execution ensures your secret keys, passphrases, and plaintexts never touch any network or server

Supports Base64, Hex, structured JSON envelopes, and OpenSSL Salted__ output formats with single-click swap and export download

Encrypting sensitive API keys and configuration values before storing them in repositories or plain files

Generating authenticated AES-GCM ciphertexts with verified 128-bit tags for secure inter-service communication

Verifying cryptographic output and cross-language compatibility across Node.js, Python, Go, Java, PHP, and OpenSSL

Inspecting 16-byte block alignments and PKCS#7 padding layouts for cryptographic auditing and learning

Generating deterministic test vectors for security unit tests and cryptanalysis verification

Example Input

Plaintext: Confidential Project Titan Specification: Auth Token 9a8f-2841-b0e2-c437
Key: quantum-vault-passphrase-2026!

Example Output

Encrypted (AES-256-GCM, Base64 Envelope):
eyJtIjoiR0NNIiwwayI6MjU2LCJzIjoiMDE...LCJjdCI6IlUyc2xkR1Z4...In0=

Note: Contains embedded AES-256-GCM ciphertext, 12-byte IV, 16-byte PBKDF2 salt, and 128-bit authentication tag.

GCM Authentication Failure: Decryption fails if the ciphertext, authentication tag, passphrase, IV, or Additional Authenticated Data (AAD) has been modified.

Invalid Raw Hex Key Length: AES-128 requires 32 hex chars (16 bytes), AES-192 requires 48 hex chars (24 bytes), and AES-256 requires 64 hex chars (32 bytes).

Missing Salt in Passphrase Decryption: PBKDF2 key derivation requires the exact 16-byte salt used during encryption.

Padding Mismatch in CBC Mode: Decrypting CBC ciphertext with an incorrect key or corrupted final block causes a PKCS#7 padding error.

Ciphertext Truncated During Copy: Make sure you copy the entire output string including any trailing Base64 padding characters.

⚠Reusing the same IV / Nonce across multiple encryptions with the same key

Best Practice: Never reuse an IV in AES-GCM or AES-CTR. Reusing an IV destroys the cipher security, allowing attackers to XOR ciphertexts and recover the plaintext. Always generate a fresh random 12-byte IV for GCM and 16-byte IV for CBC/CTR.

⚠Using AES-ECB mode for structured application data

Best Practice: Electronic Codebook (ECB) mode encrypts identical 16-byte plaintext blocks into identical ciphertext blocks, leaking structural patterns (the ECB Penguin problem). Use AES-GCM or AES-CBC with a random IV instead.

⚠Using AES encryption as a substitute for proper secrets management

Best Practice: AES encrypting a secret is only secure if the decryption key is managed securely. For application secrets in production, use a dedicated secrets manager (AWS Secrets Manager, HashiCorp Vault, GCP Secret Manager) rather than hardcoded keys.

Why is AES-GCM preferred over AES-CBC for modern applications?

AES-GCM (Galois/Counter Mode) provides Authenticated Encryption with Associated Data (AEAD). It produces both ciphertext and an authentication tag that guarantees integrity. If an attacker modifies even a single bit of ciphertext in transit, GCM decryption rejects the payload. In contrast, AES-CBC only provides confidentiality and is vulnerable to padding oracle attacks unless paired with a separate HMAC authentication layer (Encrypt-then-MAC).

Why is it dangerous to reuse an Initialization Vector (IV)?

An IV ensures that encrypting the same plaintext multiple times produces completely different ciphertexts. In stream-like modes (GCM and CTR), reusing an IV with the same key allows attackers to XOR ciphertexts together, stripping away the keystream to recover the plaintext and forge authentication tags. Always generate a unique random IV (12 bytes for GCM, 16 bytes for CBC/CTR) for every encryption operation.

What is PBKDF2 and why should I not use raw passwords directly as AES keys?

AES requires a fixed-length key (128, 192, or 256 bits) with uniform cryptographic entropy. Passwords chosen by humans are typically short and have low entropy. PBKDF2 (Password-Based Key Derivation Function 2) applies HMAC-SHA256 repeatedly (e.g., 100,000 iterations) with a unique cryptographic salt, transforming human passphrases into high-entropy AES keys while rendering rainbow table and GPU dictionary attacks computationally infeasible.

Can I decrypt the outputs of this tool in Node.js, Python, Java, or Go?

Yes! The tool includes a dedicated Code Generator tab with ready-to-run snippets for Node.js (crypto), Web Crypto API, Python (cryptography), Go, Java (javax.crypto), PHP, and OpenSSL CLI that utilize the exact same PBKDF2, IV, and cipher configurations.

Does this tool transmit my secret keys or plaintext to any server?

No. All operations run 100% locally in your browser using the native Web Crypto API and client-side cryptographic functions. Your plaintext, passwords, salts, and derived keys never leave your device.

Recently Visited Tools

No recent tools visited yet. Explore tools above to build your quick-access history.