AES Encryption & Decryption
Perform ultra-secure AES encryption and decryption with custom modes (GCM, CBC, CTR, CFB, OFB, ECB), variable bit depths (128, 192, 256), PBKDF2 key derivation, 7-language code generators, and visual block inspectors.
Perform ultra-secure AES encryption and decryption with custom modes (GCM, CBC, CTR, CFB, OFB, ECB), variable bit depths (128, 192, 256), PBKDF2 key derivation, 7-language code generators, and visual block inspectors.
This developer tool is built with a privacy-first mindset. All transformations, formatting, and operations execute entirely in your local browser sandbox without transmitting sensitive tokens, keys, or code to external servers.
AES — Advanced Encryption Standard (NIST FIPS 197) — is a symmetric block cipher selected worldwide to secure classified data, financial systems, and internet traffic. Operating on fixed 128-bit blocks with 128, 192, or 256-bit keys, modern AES modes such as Galois/Counter Mode (GCM) provide both high-speed encryption and cryptographic integrity verification.
This tool performs Advanced Encryption Standard (AES, NIST FIPS 197) symmetric encryption and decryption directly in your browser. It supports authenticated Galois/Counter Mode (AES-GCM) with 128-bit integrity tags via the native Web Crypto API, as well as Cipher Block Chaining (CBC), Counter (CTR), Cipher Feedback (CFB), and Output Feedback (OFB). Passphrases are converted to cryptographic keys via PBKDF2-HMAC-SHA256 with up to 250,000 rounds and random 128-bit salts. All encryption and decryption runs 100% locally in your browser with zero server transmission.
Step 1
Choose Operation Mode: Select Encrypt to secure plaintext or Decrypt to recover original data from ciphertext.
Step 2
Configure Key Derivation: Use Passphrase KDF (PBKDF2-HMAC-SHA256 with custom iterations and 16-byte cryptographic salt) or specify a Raw Hex Cryptographic Key (32, 48, or 64 hex characters for 128, 192, or 256-bit keys).
Step 3
Select Cipher Settings: Choose your bit length (AES-128, AES-192, AES-256) and chaining block mode (GCM for modern AEAD authenticated encryption, CBC for standard enterprise workflows, CTR for streaming, or CFB/OFB/ECB).
Step 4
Process & Verify: Click Encrypt or Decrypt. The tool generates secure random IVs and salts automatically, computes cryptographic metrics (block count, padding bytes, latency), and outputs Base64, Hex, JSON, or OpenSSL formats.
Step 5
Inspect & Export: Use the Code Generator tab for ready-to-run code in Node.js, Web Crypto, Python, Go, Java, PHP, or OpenSSL CLI, or use the Block Inspector to examine 16-byte block alignments.
Developers and security engineers frequently need to verify AES implementations across systems, generate matching code snippets for cross-language applications, encrypt configuration secrets before committing to repositories, and inspect cryptographic block padding and authentication tags. This tool provides instant multi-language code generation (Node.js, Python, Go, Java, PHP, Web Crypto, OpenSSL), block-level analysis, and automated envelope encoding.
Supports native Web Crypto API AES-GCM (AEAD authenticated encryption with 128-bit auth tags) alongside CBC, CTR, CFB, OFB, and ECB modes
PBKDF2-HMAC-SHA256 key derivation with up to 250,000 iterations and 16-byte cryptographic salts protects against dictionary and rainbow table attacks
Automated code generator produces copy-pasteable, verified scripts for Node.js, Web Crypto, Python, Go, Java, PHP, and OpenSSL CLI
Interactive block inspector visualizes 16-byte block alignments, hex byte allocations, and PKCS#7 padding additions
100% browser-based client-side execution ensures your secret keys, passphrases, and plaintexts never touch any network or server
Supports Base64, Hex, structured JSON envelopes, and OpenSSL Salted__ output formats with single-click swap and export download
Encrypting sensitive API keys and configuration values before storing them in repositories or plain files
Generating authenticated AES-GCM ciphertexts with verified 128-bit tags for secure inter-service communication
Verifying cryptographic output and cross-language compatibility across Node.js, Python, Go, Java, PHP, and OpenSSL
Inspecting 16-byte block alignments and PKCS#7 padding layouts for cryptographic auditing and learning
Generating deterministic test vectors for security unit tests and cryptanalysis verification
Example Input
Plaintext: Confidential Project Titan Specification: Auth Token 9a8f-2841-b0e2-c437 Key: quantum-vault-passphrase-2026!
Example Output
Encrypted (AES-256-GCM, Base64 Envelope): eyJtIjoiR0NNIiwwayI6MjU2LCJzIjoiMDE...LCJjdCI6IlUyc2xkR1Z4...In0= Note: Contains embedded AES-256-GCM ciphertext, 12-byte IV, 16-byte PBKDF2 salt, and 128-bit authentication tag.
GCM Authentication Failure: Decryption fails if the ciphertext, authentication tag, passphrase, IV, or Additional Authenticated Data (AAD) has been modified.
Invalid Raw Hex Key Length: AES-128 requires 32 hex chars (16 bytes), AES-192 requires 48 hex chars (24 bytes), and AES-256 requires 64 hex chars (32 bytes).
Missing Salt in Passphrase Decryption: PBKDF2 key derivation requires the exact 16-byte salt used during encryption.
Padding Mismatch in CBC Mode: Decrypting CBC ciphertext with an incorrect key or corrupted final block causes a PKCS#7 padding error.
Ciphertext Truncated During Copy: Make sure you copy the entire output string including any trailing Base64 padding characters.
⚠Reusing the same IV / Nonce across multiple encryptions with the same key
Best Practice: Never reuse an IV in AES-GCM or AES-CTR. Reusing an IV destroys the cipher security, allowing attackers to XOR ciphertexts and recover the plaintext. Always generate a fresh random 12-byte IV for GCM and 16-byte IV for CBC/CTR.
⚠Using AES-ECB mode for structured application data
Best Practice: Electronic Codebook (ECB) mode encrypts identical 16-byte plaintext blocks into identical ciphertext blocks, leaking structural patterns (the ECB Penguin problem). Use AES-GCM or AES-CBC with a random IV instead.
⚠Using AES encryption as a substitute for proper secrets management
Best Practice: AES encrypting a secret is only secure if the decryption key is managed securely. For application secrets in production, use a dedicated secrets manager (AWS Secrets Manager, HashiCorp Vault, GCP Secret Manager) rather than hardcoded keys.
JWT
Syntaxes and patterns for JSON Web Tokens: structure (Header.Payload.Signature), signing keys, validation, claims (sub, exp, iat), and storage.
Regex Cheatsheet
Interactive guide to Regex anchors, character classes, quantifiers, lookarounds, capturing groups, and search flags.
HTTP Headers Cheatsheet
Complete guide to standard and security HTTP headers including Authorization, CORS control, caching policies, and CSP directives.
Git Cheatsheet
Quick reference guide for essential Git commands, branching workflows, remote repositories, stashing, and rollbacks.
Why is AES-GCM preferred over AES-CBC for modern applications?
AES-GCM (Galois/Counter Mode) provides Authenticated Encryption with Associated Data (AEAD). It produces both ciphertext and an authentication tag that guarantees integrity. If an attacker modifies even a single bit of ciphertext in transit, GCM decryption rejects the payload. In contrast, AES-CBC only provides confidentiality and is vulnerable to padding oracle attacks unless paired with a separate HMAC authentication layer (Encrypt-then-MAC).
Why is it dangerous to reuse an Initialization Vector (IV)?
An IV ensures that encrypting the same plaintext multiple times produces completely different ciphertexts. In stream-like modes (GCM and CTR), reusing an IV with the same key allows attackers to XOR ciphertexts together, stripping away the keystream to recover the plaintext and forge authentication tags. Always generate a unique random IV (12 bytes for GCM, 16 bytes for CBC/CTR) for every encryption operation.
What is PBKDF2 and why should I not use raw passwords directly as AES keys?
AES requires a fixed-length key (128, 192, or 256 bits) with uniform cryptographic entropy. Passwords chosen by humans are typically short and have low entropy. PBKDF2 (Password-Based Key Derivation Function 2) applies HMAC-SHA256 repeatedly (e.g., 100,000 iterations) with a unique cryptographic salt, transforming human passphrases into high-entropy AES keys while rendering rainbow table and GPU dictionary attacks computationally infeasible.
Can I decrypt the outputs of this tool in Node.js, Python, Java, or Go?
Yes! The tool includes a dedicated Code Generator tab with ready-to-run snippets for Node.js (crypto), Web Crypto API, Python (cryptography), Go, Java (javax.crypto), PHP, and OpenSSL CLI that utilize the exact same PBKDF2, IV, and cipher configurations.
Does this tool transmit my secret keys or plaintext to any server?
No. All operations run 100% locally in your browser using the native Web Crypto API and client-side cryptographic functions. Your plaintext, passwords, salts, and derived keys never leave your device.
How to Secure a Spring Boot Application in 10 Minutes: The 2026 Developer Security Checklist
A Spring Boot app can look production-ready and still expose dangerous defaults — from open actuator endpoints and weak JWT filters to hardcoded secrets, vulnerable dependencies, and unsafe SQL queries. This practical developer checklist walks through the exact 10-minute security checks you should run before deployment.
SQL Injection in Spring Boot (2026): Real Vulnerabilities, Prevention & Testing
Learn how SQL injection still breaks Spring Boot apps in 2026 with real Java vulnerabilities, blind SQLi examples, prevention checklists, and practical testing payloads.
Mastering API Security: How to Implement OAuth2 and JWT Without Common Vulnerabilities (2026)
Learn how to implement OAuth2 and JWT securely in 2026. Covers PKCE, token replay attack prevention, code examples in Python and Node.js, a full comparison table, and a developer checklist.
Related Developer Tools
Discover more fast, browser-based utilities in the Crypto Tools suite.
JWT Decoder
Decode and inspect JSON Web Tokens instantly in your browser. Paste any JWT to extract and read the header, payload, and signature — no libraries, no installs, your token never leaves your machine.
SHA Hash Generator & Audit Workspace
Generate, verify, and analyze SHA-1, SHA-224, SHA-256, SHA-384, SHA-512, and SHA-3 family hashes. Features HMAC signature generation, file checksum auditing, input entropy analysis, and instant comparison.
Recently Visited Tools
No recent tools visited yet. Explore tools above to build your quick-access history.