AES Encrypt & Decrypt
Encrypt sensitive text or payloads with military-grade AES-256-GCM or AES-CBC authenticated ciphers. Decrypt payloads using matching passphrases locally.
Encrypt sensitive text or payloads with military-grade AES-256-GCM or AES-CBC authenticated ciphers. Decrypt payloads using matching passphrases locally.
AES (Advanced Encryption Standard) is a symmetric block cipher standardized by NIST in 2001 (FIPS PUB 197). It processes data in 128-bit blocks using cryptographic keys of 128, 192, or 256 bits.
Generate and verify Blowfish-based Bcrypt cryptographic password hashes with configurable cost factors completely inside your browser.
Generate standard 2048-bit and 4096-bit RSA key pairs in your browser using the Web Crypto API. Export clean PEM files for SSH, JWT, or SSL/TLS.
Compute cryptographic HMAC authentication signatures for webhooks, REST APIs, and message verification using SHA-256, SHA-512, or SHA-1.
Generate and verify standard 30-second Two-Factor Authentication (2FA) TOTP codes from Base32 secrets. Compatible with Google Authenticator, Authy, and 1Password.
AES-GCM provides built-in cryptographic integrity checks (AEAD). If an attacker modifies even a single bit of the ciphertext, decryption will fail immediately, preventing padding-oracle and bit-flipping attacks common against CBC mode.
Security best practices require a fresh, cryptographically random Initialization Vector (IV) and PBKDF2 salt for every encryption operation. This prevents pattern analysis and replay attacks.
No. All key derivation, encryption, and decryption steps are performed entirely in your browser using the Web Crypto API. No data leaves your machine.
Browse our full suite of 157 browser-based tools, formatters, converters, and guides.