AES-GCM Encrypt / Decrypt

Authenticated AES (AEAD)

100% local — nothing is uploaded
Parameters
Key size
Output
Key
Salt
Iterations
IV / Nonce (12 bytes)
AAD (optional)
Output
—

How to use

  1. Choose a key: a passphrase (PBKDF2-SHA256) or a raw hex key.
  2. Set the 12-byte IV/nonce — use Random for real encryption.
  3. Encrypt to get ciphertext + auth tag, or decrypt and verify.

FAQ

Why AES-GCM instead of AES-CBC?

GCM is authenticated (AEAD): any tampering with the ciphertext is detected. CBC + padding oracle attacks are a real risk — prefer GCM.

Can I reuse the same IV?

Never with the same key — GCM nonce reuse completely breaks confidentiality and authentication. Always generate a fresh 12-byte nonce.

Is the output compatible with other tools?

Yes, it is standard AES-GCM: IV + ciphertext + 16-byte tag, matching WebCrypto, OpenSSL and most libraries.