Symmetric encryption
Encrypt and decrypt text locally with WebCrypto AES-GCM / AES-CBC 256-bit, deriving the key from a passphrase via PBKDF2 (SHA-256, configurable iterations and salt length) and packing the result as base64 salt|iv|ciphertext.
Runs in your browserEvery computation happens in your browser — your data never leaves this device.
Ciphertext (base64 packed string)
What this tool does
- Encrypt a piece of text — a config snippet, a key, a private note — into a copyable base64 packed string when a browser is all you have.
- Send the ciphertext to yourself or a colleague, let them paste the whole string back to decrypt, and pass the passphrase over a separate channel.
- Compare the two modes: AES-GCM is authenticated and fails loudly when the ciphertext or passphrase is wrong, while AES-CBC is there for legacy systems that require it.
- Play with the PBKDF2 iteration count to feel where key derivation time goes and why more iterations make brute force harder.
Example
Input
Hello, UniKit! (passphrase hunter2, AES-GCM, 1000 PBKDF2 iterations)
Output
AAECAwQFBgcICQoLDA0ODw==|AAECAwQFBgcICQoL|hzpq+MCEzRaF9ectXqUe3DcrUPdic3HFFX9bkY47
This is a fixed test vector using a known salt (00…0f) and IV (00…0b). The tool generates a fresh random salt every run, so encrypting the same plaintext again gives a different string — just paste the whole thing back to decrypt.
Frequently asked questions
Should I use AES-GCM or AES-CBC?
AES-GCM by default. It carries an authentication tag, so a wrong passphrase or a modified ciphertext fails with "decryption failed" instead of returning garbage. AES-CBC only encrypts, so a wrong passphrase may still decrypt into meaningless bytes — use it only when a legacy system demands it.
Why do I have to pick the algorithm and iteration count again when decrypting?
The packed string only stores the salt, the IV and the ciphertext. The IV length hints at the algorithm (12 bytes means GCM, 16 means CBC), but the iteration count must match the one used for encryption, otherwise the derived key differs and decryption can never succeed.
Does the passphrase strength matter, and is more iterations always better?
Passphrase strength matters most — PBKDF2 only slows brute force down, it cannot rescue a weak passphrase. The 210,000 default is a common recommendation; 500,000 is harder to attack but noticeably slower on every operation, especially on phones.
What is the difference between leaving the IV blank and typing one?
Leaving it blank is safest: every encryption gets a fresh random IV, so the same plaintext never produces the same ciphertext twice. A fixed IV is only useful for reproducing test vectors, and reusing one IV weakens the encryption.
Is my passphrase or plaintext uploaded anywhere?
No. Everything runs through the browser WebCrypto API locally, the page makes no network requests, and neither the passphrase nor the plaintext leaves your device.
Keywords:aesaes-gcmaes-cbcencryptdecrypt加密解密pbkdf2webcrypto对称加密