Text Encryptor

Works offlineNothing is uploadedFree, no sign-up
There is no recovery. Lose the passphrase, lose the text.

Key derivation and encryption run in this tab via WebCrypto. No text, passphrase or payload ever leaves your browser.

Encrypt any text with a passphrase — AES-256-GCM, with the key derived by 210,000 rounds of PBKDF2, entirely in your browser. Paste the result back on the decrypt tab to get the text out again. Nothing is ever sent anywhere.

What the payload contains

The output is one base64 block: a four-byte format tag, the random salt, the random IV, then the ciphertext with GCM's authentication tag at its end. Everything needed to decrypt — except the passphrase — travels inside the block, which is why it can be stored in a note, a file or a message and decrypted here later.

Because the tool is a static page, this works offline once loaded, and there is no server to trust or subpoena: the browser's own WebCrypto implementation does the mathematics, and the network tab stays empty from the first keystroke to the last.

Frequently asked questions

What exactly protects the text?

AES-256 in GCM mode, the same construction TLS uses. Your passphrase is stretched into a 256-bit key by PBKDF2 with 210,000 SHA-256 rounds and a fresh random salt, so the same passphrase produces a different key every time and dictionary attacks pay full price per guess.

Why does the same text encrypt differently each time?

A fresh random salt and IV are generated per encryption — that is a feature, not a bug. Identical outputs would leak the fact that two payloads hide the same text. Any payload decrypts with the right passphrase regardless.

What happens with a wrong passphrase?

You get an error and nothing else. GCM authenticates while decrypting: a wrong key and a tampered payload both fail the tag check, so the tool never emits garbage that might be mistaken for the real text — and deliberately does not say which of the two happened.

Can I recover text if I forget the passphrase?

No, and neither can anyone else — that is the point. There is no account, no reset, no back door; the key exists only while your passphrase is in the box. Store the passphrase somewhere as durable as the text it protects.

Related tools