AES Encryption Tool (Developer)
AES-GCM, CBC and CTR with raw keys, for test vectors and interoperability debugging.
Algorithm and key
Authenticated but not encrypted (for example a header or record ID); the same value is needed to decrypt.
NIST SP 800-38D allows 32- and 64-bit tags only for special, limited uses.
How many bits of the counter block are incremented. It only matters when those bits overflow during the message.
Ciphertext
The same operation in code
About the AES Encryption Tool (Developer)
A developer’s AES workbench on your browser’s Web Crypto: encrypt or decrypt with AES-GCM (with additional authenticated data and a chosen tag length), AES-CBC (PKCS#7 padding, or none for test vectors) or AES-CTR (with a chosen counter width), using raw 128-, 192- or 256-bit keys and IVs in hex or Base64. Input can be text, hex or Base64; output can carry the IV in front and the GCM tag at the end, the way different libraries expect.
It is made for checking test vectors and debugging why two systems disagree: published NIST and GCM vectors load with one click, wrong keys and tags produce clear messages instead of garbage, reusing a nonce on this page is flagged, and the same operation is shown as Node.js, Python or OpenSSL code. ECB is deliberately not offered. Keys and data never leave your device.
How to use it
- Choose Encrypt or Decrypt and the mode — GCM unless you must match an existing system.
- Paste the key in hex or Base64, or press Generate key. Paste the IV, nonce or counter block, or leave it empty when encrypting to get a random one.
- For GCM, add the additional authenticated data (if any) and the tag length; for CBC choose the padding; for CTR the counter width.
- Paste the input, pick its format and the layout (with or without the IV in front), then press Encrypt or Decrypt.
- Copy the result, download the raw bytes, or press Decrypt this to check the round trip. Open The same operation in code to reproduce it in Node.js, Python or OpenSSL.
Examples
Key 603deb10…0914dff4 · counter f0f1f2…feff · plaintext 6bc1bee2…e66c3710
601ec313775789a5b7a7f504bbf3d228f443e3ca4d62b59aca84e990cacaf5c5…
Choose it under Load a test vector; the page confirms the match.
AES-256-GCM · nonce cafebabefacedbaddecaf888 · AAD feedfacedeadbeeffeedfacedeadbeefabaddad2
Ciphertext 522dc1f0…a0abcc9f662 ‖ tag 76fc6ece0f4e1768cddf8853bb2d551b
Change one character of the AAD and decrypting fails with “Authentication failed” — that is GCM working.
Node’s cipher.update() + final() as hex, and getAuthTag() as hex
Paste the ciphertext, put the tag in “Tag, if it is kept separately”, and decrypt
Common uses
- Checking your own AES code against the NIST SP 800-38A and GCM test vectors.
- Finding out why a message encrypted in one language will not decrypt in another: IV placement, tag position, padding or encoding.
- Decrypting a test payload during development when you have the key and the IV.
- Generating random keys and nonces in the right sizes for configuration files.
Which mode?
- GCM (NIST SP 800-38D) encrypts and authenticates: a wrong key, nonce, tag or any modified byte makes decryption fail instead of returning garbage. Use a fresh 12-byte nonce for every message; SP 800-38D requires that a nonce is never repeated under the same key.
- CBC (SP 800-38A) needs a new random 16-byte IV per message and padding. It is not authenticated, so it must be combined with an HMAC (encrypt-then-MAC) to resist tampering.
- CTR (SP 800-38A) turns AES into a stream cipher with no padding. Never reuse a counter block with the same key: the XOR of the two ciphertexts equals the XOR of the plaintexts.
- ECB is not offered: it encrypts equal blocks to equal blocks, so patterns in the data stay visible.
Why two systems disagree
The usual suspects, in order: the key encoding (hex vs Base64 vs a password used directly as a key), the IV (random per message, sent in front of the ciphertext or separately), the GCM tag (Web Crypto, Java, Go and Python’s AESGCM append it; Node.js returns it separately with getAuthTag()), padding (PKCS#7 in most libraries; none for raw test vectors), and the text encoding of the plaintext (UTF-8 here). AES-CTR libraries also differ in how many counter bits they increment: OpenSSL, Node.js, Java and Python’s cryptography package increment the whole 128-bit block, which is the default here.
Keys are not passwords
AES needs a key made of random bytes — exactly 16, 24 or 32 of them. A password is not a key: derive one with a slow, salted function such as PBKDF2, scrypt or Argon2 (the Argon2 tool shows the raw output in hex), or generate a random key here. Keep keys out of source code and logs.
Limitations
- Chrome and Edge do not support 192-bit AES keys in Web Crypto (Firefox and Safari do); use a 128- or 256-bit key there.
- Only raw keys: there is no password-based mode, because different tools derive keys from passwords in incompatible ways (for example OpenSSL’s old EVP_BytesToKey).
- CBC decryption checks PKCS#7 padding; with “None” the raw blocks are returned as they are.
- This is a tool for developers and test data — for files you want to keep private, use the password-protected ZIP tool or dedicated encryption software.
Privacy
Everything happens in your browser. What you enter or open here is not uploaded or stored by MySmartCoPilot.
Frequently asked questions
Is my key or data sent anywhere?
No. Encryption and decryption run in your browser with its built-in Web Crypto API; nothing is uploaded, logged or stored, and the page works offline once loaded.
Why does GCM decryption say “Authentication failed”?
GCM checks the tag before returning anything. The key, nonce, additional data or tag length differ from the ones used to encrypt, the tag is missing or in the wrong place, or the data was changed. Check where your library puts the tag: Node.js keeps it separate from the ciphertext.
What does “The PKCS#7 padding is not valid” mean?
After CBC decryption the last block did not end in valid padding — almost always a wrong key or IV, or ciphertext that was made without padding (choose “None” to see the raw blocks).
Can I reuse an IV or nonce?
Not with the same key. Reusing a GCM nonce or a CTR counter block reveals the XOR of the messages (and for GCM allows forgeries); reusing a CBC IV shows when messages start the same way. This page warns if you do it here.
Why is ECB missing?
ECB encrypts every 16-byte block on its own, so identical blocks give identical ciphertext and patterns in the data remain visible. It is not safe for data and is left out on purpose.