Security / Encrypt
Encrypt Text with a Password
Encrypt a message or note with a password in your browser, using AES-256-GCM, and decrypt it again; send the encrypted text anywhere and share the password separately.
Encrypt Text with a Password: Your password is turned into a 256-bit key with PBKDF2 (SHA-256, 600,000 rounds, as OWASP recommends) and a random salt, which makes guessing passwords slow. The text is then encrypted with AES-256-GCM, which also detects any change: a wrong password or an altered message fails to decrypt instead of giving nonsense. The result is a single line of text with the settings, salt, and nonce built in, so it can be pasted into email or chat. All of this uses your browser's built-in Web Crypto. Runs 100% locally in your browser with zero server file uploads.
- Category
- Developer tools
- Runs
- In your browser
- Cost
- Free · no sign-up
- Availability
- Ready to use
Runs entirely in your browser
AES-256-GCM with a key made from your password by PBKDF2 (SHA-256, 600,000 rounds), in your browser. Nothing is sent anywhere.
When to use it
For sending a password, an address, or a private note over a channel you do not fully trust, or keeping a note in cloud storage that only you can read. For regular private conversation, an end-to-end encrypted messenger is easier.
Make a strong password with the password generator; to check whether a file arrived unchanged, compare its hash.
What it does not protect
Encryption hides the content, not the fact that you sent something, to whom, or how long it is. And it protects nothing on a device that is already compromised, where malware could read the text before it is encrypted.
How to use it
- Type or paste the text and choose a strong password, twice.
- Press Encrypt and copy the result, which starts with toea1.
- To read it, paste the encrypted text here with Decrypt and enter the same password.
Privacy & limitations
Your text and password never leave your device; encryption and decryption happen in your browser.
Related tools
Frequently asked questions
What if I forget the password?
The text cannot be recovered. There is no reset or back door: the password is the only key, and it is never stored or sent anywhere.
How strong is the encryption?
AES-256-GCM is the standard used by governments and banks; it is not the weak point. The password is: a short or common one can be guessed. Use 12 characters or more, or four or more random words, and do not reuse a password.
How should I share the password?
By a different channel from the message, such as in person or by phone when the encrypted text goes by email. Anyone with both can read it.
Can other tools decrypt it?
Yes, with standard libraries: the format holds the iteration count, salt, nonce, and ciphertext in base64url, and uses PBKDF2-SHA-256 and AES-256-GCM with no custom steps.
Free tool · runs in your browser · no account required