Guides & Blog
ENES
🛡️

AES Encrypt & Decrypt

cryptoClient-side utility

Encrypt sensitive text or payloads with military-grade AES-256-GCM or AES-CBC authenticated ciphers. Decrypt payloads using matching passphrases locally.

✓ 100% In-Browser Execution✓ Free & No Usage Cap✓ Zero Server Data Storage

📖How to Use This Tool

What is Advanced Encryption Standard (AES)?

AES (Advanced Encryption Standard) is a symmetric block cipher standardized by NIST in 2001 (FIPS PUB 197). It processes data in 128-bit blocks using cryptographic keys of 128, 192, or 256 bits.

Cipher Modes Supported:

  • AES-GCM (Galois/Counter Mode): An Authenticated Encryption with Associated Data (AEAD) mode. In addition to encrypting your plaintext, GCM computes an authentication tag that guarantees the ciphertext has not been tampered with or corrupted in transit.
  • AES-CBC (Cipher Block Chaining): The classic legacy block mode where each plaintext block is XORed with the previous ciphertext block before encryption.

How to Use

To Encrypt:

  1. Select your target mode (AES-GCM is recommended) and key strength (256-bit).
  2. Enter your plaintext message or JSON data.
  3. Supply a strong secret passphrase. The tool automatically derives a cryptographic key using PBKDF2 with 100,000 SHA-256 rounds and a fresh 16-byte random salt.
  4. Click Encrypt. You can copy either the single compact Base64 envelope or the full JSON specification.

To Decrypt:

  1. Switch to the Decrypt Ciphertext tab.
  2. Paste your Base64 envelope or JSON object into the input box.
  3. Enter the exact matching secret passphrase.
  4. Click Decrypt Ciphertext to restore your original plaintext.

🔗Related Tools in this Category

View all crypto tools →

❓Frequently Asked Questions

Q.Why is AES-GCM recommended over AES-CBC?

AES-GCM provides built-in cryptographic integrity checks (AEAD). If an attacker modifies even a single bit of the ciphertext, decryption will fail immediately, preventing padding-oracle and bit-flipping attacks common against CBC mode.

Q.Why does the ciphertext change every time I click Encrypt with the same text?

Security best practices require a fresh, cryptographically random Initialization Vector (IV) and PBKDF2 salt for every encryption operation. This prevents pattern analysis and replay attacks.

Q.Can the server read or store my decrypted payload?

No. All key derivation, encryption, and decryption steps are performed entirely in your browser using the Web Crypto API. No data leaves your machine.

Explore More Developer Utilities

Browse our full suite of 157 browser-based tools, formatters, converters, and guides.

Read Guides & Blog →