Sign up free

AES Encryption and Decryption Tool

Encrypt or decrypt text with AES in CBC, GCM or CTR mode, using a passphrase or your own key and IV.

About AES Encrypt and Decrypt

Use this AES encryption tool to check an integration before you ship it: decrypt a field an API sent you, encrypt a test payload the way your backend does, or confirm that a key and IV really belong together. It supports AES-CBC with PKCS#7 padding, AES-GCM and AES-CTR with 128- or 256-bit keys, encrypts and decrypts, and gives encrypted output as Base64 or hex.

There are two ways to supply the key. Passphrase mode reads and writes the Salted__ format used by CryptoJS and OpenSSL (CBC), so text a web page encrypted with a CryptoJS passphrase can be decrypted here, and the other way round. Raw key mode takes the key and IV as hex, Base64 or text, for code that sets them explicitly. AES-192 isn't offered because Chrome's Web Crypto doesn't support it, and ECB is left out because it's insecure. The encryption is done by your browser's Web Crypto, so keys and data are never uploaded. How hard a passphrase is to guess can be checked in the Password Strength Checker.

How to use AES Encrypt and Decrypt

  1. 1
    Choose encrypt or decrypt

    Then pick the mode, CBC, GCM or CTR.

  2. 2
    Enter the key

    Type a passphrase, or give the raw key and IV as hex, Base64 or text.

  3. 3
    Paste the data

    Plain text to encrypt, or Base64 or hex ciphertext to decrypt.

  4. 4
    Copy the result

    Encrypted output comes as Base64 or hex, decrypted output as text.

Why use Cubfile for this

  • Three modes

    CBC with PKCS#7 padding, GCM with built-in tamper detection, and CTR.

  • CryptoJS-compatible passphrases

    Reads and writes the OpenSSL Salted__ format.

  • Raw key and IV

    Hex, Base64 or text, with 128- or 256-bit keys.

  • Web Crypto on your device

    Encryption runs in the browser, with nothing uploaded.

FAQ

AES Encrypt and Decrypt: questions and answers

Can I use AES ECB mode here?
No. ECB turns identical blocks of data into identical output, which leaks patterns, so it's left out on purpose. Use CBC, GCM or CTR instead.
Why is there no AES-192 encryption option?
The encryption is done by the browser's Web Crypto, and Chrome's Web Crypto doesn't offer 192-bit AES. 128- and 256-bit keys are supported.
Is Java's PKCS5Padding the same as PKCS#7?
For AES, yes. Java calls it PKCS5Padding, but with 16-byte blocks it's the same PKCS#7 padding that CBC uses here.
Why does decryption fail?
Usually the key, IV, mode or key size differs from the side that encrypted, or the ciphertext is hex while Base64 is selected, or the other way round. Text encrypted with a passphrase must be decrypted in passphrase mode.
Is my AES key safe if I encrypt and decrypt here?
Yes. Encryption and decryption run in your browser with Web Crypto, the key and text are never uploaded, and the page keeps working offline once loaded. To hand the key to someone else, encrypt it with their public key in the RSA tool.
Share AES Encrypt and Decrypt with a friendIt runs in any browser, and they can try it without signing up.

Related tools

HASH Hash GeneratorGet MD5, SHA-1, SHA-256, SHA-512 and SM3 hashes of text in one go.
TIME Unix Timestamp ConverterConvert Unix timestamps to dates and back, in your time zone and UTC.
U+UNI Unicode ConverterConvert text to and from \u escapes, &#; codes, U+ points and UTF-8 bytes.
&;HTML HTML Entity Encoder/DecoderEscape text into HTML entities, or turn entities back into text.
JWT JWT DecoderDecode a JSON Web Token’s header and payload and check its expiry and signature.
01BIN Number Base ConverterConvert numbers between binary, octal, decimal, hex and any base up to 36.
BASE Base32 and Base58 EncoderEncode and decode Base32, Base58, Base85 and Base16.
0xHEX Text to Hex ConverterTurn text into hexadecimal bytes in UTF-8, GBK or UTF-16, and back.