About AES Encrypt and Decrypt
Use this AES encryption tool to check an integration before you ship it: decrypt a field an API sent you, encrypt a test payload the way your backend does, or confirm that a key and IV really belong together. It supports AES-CBC with PKCS#7 padding, AES-GCM and AES-CTR with 128- or 256-bit keys, encrypts and decrypts, and gives encrypted output as Base64 or hex.
There are two ways to supply the key. Passphrase mode reads and writes the Salted__ format used by CryptoJS and OpenSSL (CBC), so text a web page encrypted with a CryptoJS passphrase can be decrypted here, and the other way round. Raw key mode takes the key and IV as hex, Base64 or text, for code that sets them explicitly. AES-192 isn't offered because Chrome's Web Crypto doesn't support it, and ECB is left out because it's insecure. The encryption is done by your browser's Web Crypto, so keys and data are never uploaded. How hard a passphrase is to guess can be checked in the Password Strength Checker.
How to use AES Encrypt and Decrypt
- 1Choose encrypt or decrypt
Then pick the mode, CBC, GCM or CTR.
- 2Enter the key
Type a passphrase, or give the raw key and IV as hex, Base64 or text.
- 3Paste the data
Plain text to encrypt, or Base64 or hex ciphertext to decrypt.
- 4Copy the result
Encrypted output comes as Base64 or hex, decrypted output as text.
Why use Cubfile for this
- Three modes
CBC with PKCS#7 padding, GCM with built-in tamper detection, and CTR.
- CryptoJS-compatible passphrases
Reads and writes the OpenSSL Salted__ format.
- Raw key and IV
Hex, Base64 or text, with 128- or 256-bit keys.
- Web Crypto on your device
Encryption runs in the browser, with nothing uploaded.