AES-GCM Encrypt / Decrypt
Authenticated AES (AEAD)
100% local — nothing is uploaded
Parameters
Key size
Output
Key
Salt
Iterations
IV / Nonce (12 bytes)
AAD (optional)
Output
—
How to use
- Choose a key: a passphrase (PBKDF2-SHA256) or a raw hex key.
- Set the 12-byte IV/nonce — use Random for real encryption.
- Encrypt to get ciphertext + auth tag, or decrypt and verify.
FAQ
Why AES-GCM instead of AES-CBC?
GCM is authenticated (AEAD): any tampering with the ciphertext is detected. CBC + padding oracle attacks are a real risk — prefer GCM.
Can I reuse the same IV?
Never with the same key — GCM nonce reuse completely breaks confidentiality and authentication. Always generate a fresh 12-byte nonce.
Is the output compatible with other tools?
Yes, it is standard AES-GCM: IV + ciphertext + 16-byte tag, matching WebCrypto, OpenSSL and most libraries.