← All tools
BROWSER · Web Crypto API · AES-256-GCM · PBKDF2-SHA-256

AES Encrypt & Decrypt

Encrypt or decrypt text and files locally with AES-256-GCM and PBKDF2-SHA-256. Passwords, plaintext, and encrypted data stay in your browser.

✓ AES-256-GCM authenticated encryption✓ Password-based PBKDF2-SHA-256 key derivation✓ Text and file encryption modes
About this tool

A local AES-256-GCM encryption and decryption tool for text and files. Passwords are converted to 256-bit keys with PBKDF2-SHA-256 using a random salt; each encryption also receives a fresh 96-bit IV. Processing uses the browser Web Crypto API and data is not uploaded.

Common uses
aes encrypt decryptaes 256 encryptaes gcm encryptaes decrypt

How it works

  1. 1Choose Text or File mode and enter a password.
  2. 2Encrypt plaintext/a file or paste/load a Toolardo AES package to decrypt.
  3. 3Copy the encrypted text or download the encrypted/decrypted file.

Frequently asked questions

Which AES mode does this tool use?

AES-256-GCM with a 128-bit authentication tag. GCM provides both encryption and tamper detection.

How is the AES key created from my password?

The password is processed locally with PBKDF2-HMAC-SHA-256 and a new random 16-byte salt. Toolardo currently uses 600,000 iterations.

Are my password or files uploaded?

No. Encryption and decryption use the browser Web Crypto API. The input, password, key, and result remain on your device.

Can I decrypt the output with OpenSSL or CryptoJS directly?

Not directly. Toolardo stores salt, IV, KDF settings, authenticated metadata, and ciphertext in its own TLAES envelope. The underlying cipher is standard AES-256-GCM, but another program must understand the Toolardo envelope.

Why are very large files limited?

Web Crypto AES-GCM is a one-shot API and browsers may need multiple copies of the file in memory. This version blocks files above 256 MB to reduce the chance of a tab crash.

Related tools