Cryptography

AES-GCM Encrypt/Decrypt

Encrypt or decrypt with AES-256-GCM and a password-derived key (PBKDF2). Learning/interoperability tool—not a replacement for audited secret management.

Free to use — no sign-up or login.

Runs entirely in your browser; input is not sent to our servers.

Messages, keys, passwords, plaintext, ciphertext, and files are never stored in localStorage, history, or analytics payloads.

Secure

Minimum 10,000. Default 600,000 (SHA-256).

Result

Package / plaintext

This free AES-GCM Encrypt/Decrypt covers Encrypt or decrypt with AES-256-GCM and a password-derived key (PBKDF2). Learning/interoperability tool—not a replacement for audited secret management.

Enter the AES-GCM Encrypt/Decrypt fields, then read the output. Cryptography calculators on this site keep the formula visible beside the form, with no account required.

Using the AES-GCM Encrypt/Decrypt

Encrypt or decrypt with AES-256-GCM and a password-derived key (PBKDF2). Learning/interoperability tool—not a replacement for audited secret management. Typical inputs are Mode, Password, PBKDF2 iterations and Plaintext (encrypt). How it works beside the form states the identity the AES-GCM Encrypt/Decrypt applies.

FAQ

How do I use the AES-GCM Encrypt/Decrypt?

Open the AES-GCM Encrypt/Decrypt, fill Mode, Password, PBKDF2 iterations and Plaintext (encrypt), and read the result. Encrypt derives an AES-256 key from your password via PBKDF2, then seals the plaintext with a fresh 96-bit IV. The result is a versioned JSON package (algorithm, KDF, iterations, salt, IV, ciphertext). Decrypt reverses that package and fails explicitly if authentication fails—tampered or wrong-password data is rejected, not silently garbled.

What formula does the AES-GCM Encrypt/Decrypt use?

The AES-GCM Encrypt/Decrypt uses the identity in How it works. In words: Encrypt derives an AES-256 key from your password via PBKDF2, then seals the plaintext with a fresh 96-bit IV. The result is a versioned JSON package (algorithm, KDF, iterations, salt, IV, ciphertext). Decrypt reverses that package and fails explicitly if authentication fails—tampered or wrong-password data is rejected, not silently garbled.

Sources