Skip to main content
Skip to tool

Converter

AES Encrypt / Decrypt — GCM & CBC Locally

Encrypt and decrypt with AES-GCM or AES-CBC in your browser. Passphrase PBKDF2 or raw keys — nothing uploaded.
  • Convert
  • Mobile Friendly
  • Accessibility Tested
  • SEO Optimized
  • Fast Loading
  • Responsive

Version 1.0.0 · Last reviewed

How it worksShow guide

Introduction

Run AES-GCM or AES-CBC in your browser with Web Crypto. Derive keys from a passphrase (PBKDF2) or paste a raw key, control IV and salt, and exchange a JSON package that round-trips cleanly.

Step-by-step

  1. Choose encrypt or decrypt, mode, and key size
  2. Provide a passphrase or raw key and your text
  3. Copy the JSON package or recovered plaintext

Worked example

AES-256-GCM with a passphrase produces a JSON package containing iv, salt, ciphertext, and KDF parameters for later decryption.

Use cases

  • Encrypt notes or tokens before storing them locally
  • Experiment with AES-GCM authenticated encryption and AAD
  • Share ciphertext packages between teammates without a server

Frequently asked questions

Is ciphertext uploaded?

No. Encryption and decryption stay in this tab.

GCM or CBC?

Prefer AES-GCM for authenticated encryption. AES-CBC remains available for interoperability with older systems.

Related tools

Popular tools

Was this helpful?

Your feedback stays on this device only — it is not sent to the Bestrao team yet.

Share

Provided by Bestrao

Version 1.0.0 · Last updated: