Protect a message with real encryption. Your text is encrypted with AES-256-GCM using a key derived from your password with PBKDF2, and the result is one shareable Base64 string that packs the salt, IV and ciphertext together. Decryption happens entirely in your browser.
Length is the single biggest factor in password strength.
A unique password per account limits the damage of any breach.
Store strong generated passwords in a reputable manager.
Two-factor authentication protects accounts even if a password leaks.
Protect a message with real encryption. Your text is encrypted with AES-256-GCM using a key derived from your password with PBKDF2, and the result is one shareable Base64 string that packs the salt, IV and ciphertext together. Decryption happens entirely in your browser.
Type or paste the text you want to protect in the Encrypt tab.
Use a long, unique passphrase — it is the only thing standing between the ciphertext and your message.
Paste the Base64 output into the Decrypt tab with the same passphrase to recover the text.
| Plaintext | Base64 ciphertext (start) |
|---|---|
| Meet me at noon | k3Fq7bY2nW... |
| password=secret | Zk9T1sQ8rA... |
Every encryption uses a fresh random salt and IV, so the same message never produces the same output twice.
It is completely free, private and requires no signup.
Use the tool nowYes. AES-256-GCM is authenticated encryption used across the industry, and the key is derived from your password with PBKDF2 over 150,000 iterations.
It packages three things: a random salt, a random IV (nonce) and the encrypted text with its authentication tag. All are needed to decrypt.
Only with software that follows the exact same construction (AES-256-GCM with PBKDF2-SHA256 and the same iteration count). The bundled salt and IV make that possible.
The message is unrecoverable. There is no backdoor and no reset — that is exactly what makes the encryption trustworthy.
Explore the whole collection — no signup, 100% free & private.