AES Symmetric Encryption & Decryption Online
AES-256-GCM authenticated encryption / AES-128-GCM fast mode / CBC+HMAC compatible mode
256-bit key, authenticated encryption, recommended for most cases. Each encryption produces a full JMENC1 payload; paste the whole string to decrypt.
About Modern Symmetric Encryption
AES-256-GCM is the default recommendation: an authenticated encryption algorithm that protects both confidentiality and integrity. The password is used to derive a key via PBKDF2-SHA256; each encryption generates a random salt and IV and outputs a full JMENC1 payload, so decryption only needs the whole string plus the same password.
Encrypted Result Format
The new default output is a compact JMENC1 payload; most users just copy and save the whole string. The advanced parameters still show the JSON envelope, including algorithm, KDF, iteration count, salt, IV and ciphertext. Decryption accepts the compact JMENC1 format, the JSON envelope and legacy AES-GCM Base64 results.
FAQ
GCM (Galois/Counter Mode) is an authenticated encryption (AEAD) mode: it provides confidentiality and integrity at once and detects tampering automatically. CBC provides confidentiality only and needs HMAC for integrity checking (this tool’s CBC+HMAC mode already wraps that in). GCM is recommended for new projects.
PBKDF2 (Password-Based Key Derivation Function 2) turns an easy-to-remember password into a real encryption key through many iterations and salting. Each encryption uses a random salt and 310,000 iterations, so even two encryptions with the same password produce different keys, effectively blocking rainbow-table attacks.
Symmetric encryption (AES) uses the same password for encryption and decryption: fast and suited to large data. Asymmetric encryption (RSA) encrypts with a public key and decrypts with a private key — no shared secret, but slow. Real systems often combine them: RSA encrypts an AES key, then AES encrypts the data. For asymmetric encryption, use theRSA encryption tool.
These legacy algorithms have been retired by modern cryptography. DES has only a 56-bit key and can be brute-forced; 3DES performs poorly; RC4 has serious bias flaws. The browser Web Crypto API no longer natively supports them, and this tool focuses on modern, secure schemes.