Text Encryption
Encrypt a note with a password, in your browser — AES-GCM with a properly derived key, not a toy cipher.
Runs entirely in your browser
Loading tool...
How to use
- Type or paste the message, and choose a password — a passphrase beats a short password.
- Copy the encrypted block and send it however you like.
- The recipient pastes it here with the same password to read it.
- Share the password by another route than the message itself.
Features
- AES-256-GCM, which authenticates as well as encrypts.
- Key derived with PBKDF2-SHA-256 at 210,000 iterations.
- A fresh random salt and IV each time, so the same message never encrypts the same way twice.
- Tampering fails to decrypt rather than producing plausible nonsense.
- Runs entirely in your browser — nothing is transmitted or stored.
Frequently asked questions
- How strong is this really?
- The cipher is not the weak point — AES-256-GCM is what your bank uses. Your password is. A key derived from “hunter2” is guessable however good the algorithm, and 210,000 PBKDF2 iterations only slow that down. Use a passphrase of several random words, and the encryption is as strong as the mathematics allows.
- Why does the same message look different every time?
- Because a fresh random salt and initialisation vector are used for each encryption, and both are stored alongside the ciphertext. It is what stops an observer from noticing that you sent the same message twice — a leak that has broken real systems.
- Can I use this for something that really matters?
- For a note passed between two people who can share a passphrase another way, yes. For anything ongoing — files, messages at scale, anything with a threat model — use a tool built for it: an encrypted messenger, age, or GPG. This is a page in a browser, and its security depends on the browser being what you think it is.
Related tools
Generate MD5, SHA-1, SHA-256, SHA-384 and SHA-512 hashes, or verify a checksum.
Sign a message with a secret key, or check a webhook signature you were sent.
Generate strong random passwords.