Your country

Tools that support it use your country for local currency, number formats, units and paper size. Your choice is saved only in this browser.

Type a name or a two-letter code. Use the up and down arrow keys to move through the countries, Enter to choose one and Escape to close.

Encrypt / Decrypt Text (AES-256)

Password-protect a message, send it anywhere, decrypt it here — even offline.

Security No upload Works offline Free, no sign-up

Encrypt a message

    Output
    Decrypt without this website (Node.js script)

    Save the message in a file (for example message.txt) and this script as decrypt-tvt.mjs, then run node decrypt-tvt.mjs message.txt. It needs Node.js 24.7 or later, no packages, and asks for the password.

    // Decrypts a message from MySmartCoPilot "Encrypt / Decrypt Text" (TVT format, version 1).
    // Needs Node.js 24.7 or later (crypto.argon2Sync); no packages.
    // Usage: node decrypt-tvt.mjs message.txt     (asks for the password; what you type is not shown)
    import { argon2Sync, createDecipheriv, pbkdf2Sync } from 'node:crypto';
    import { readFileSync } from 'node:fs';
    
    // Reads the password without showing it on screen (or one line, when it is piped in).
    function askPassword(prompt) {
      return new Promise((resolve) => {
        const { stdin, stderr } = process;
        const tty = stdin.isTTY;
        let pw = '';
        let done = false;
        const finish = () => {
          if (done) return;
          done = true;
          if (tty) stdin.setRawMode(false);
          stdin.pause();
          stderr.write('\n');
          resolve(pw);
        };
        if (tty) stdin.setRawMode(true); // before the prompt, so that nothing typed is echoed
        stderr.write(prompt);
        stdin.setEncoding('utf8');
        stdin.on('end', finish);
        stdin.on('data', (chunk) => {
          for (const c of chunk) {
            if (done) return;
            if (c === '\r' || c === '\n' || c === '\u0004') return finish(); // Enter (or Ctrl+D)
            if (c === '\u0003') { if (tty) stdin.setRawMode(false); process.exit(130); } // Ctrl+C
            pw = c === '\u007f' || c === '\b' ? [...pw].slice(0, -1).join('') : pw + c; // Backspace
          }
        });
      });
    }
    
    const text = readFileSync(process.argv[2], 'utf8');
    const b64 = text.replace(/^-----(BEGIN|END) [A-Z ]+-----$|^[A-Za-z][A-Za-z0-9-]*: .*$/gm, '').replace(/\s+/g, '');
    const data = Buffer.from(b64, 'base64'); // also accepts the URL-safe alphabet
    if (data.toString('latin1', 0, 3) !== 'TVT' || data[3] !== 1) throw new Error('Not a TVT version 1 message');
    
    const password = (await askPassword('Password: ')).normalize('NFC');
    
    let off, key;
    if (data[4] === 1) { // PBKDF2-HMAC-SHA256: uint32 iterations
      off = 9;
      key = pbkdf2Sync(password, data.subarray(off, off + 16), data.readUInt32BE(5), 32, 'sha256');
    } else if (data[4] === 2) { // Argon2id: uint32 memory (KiB), uint8 passes, uint8 lanes
      off = 11;
      key = argon2Sync('argon2id', { message: password, nonce: data.subarray(off, off + 16),
        memory: data.readUInt32BE(5), passes: data[9], parallelism: data[10], tagLength: 32 });
    } else throw new Error('Unknown key-derivation method');
    
    const iv = data.subarray(off + 16, off + 28);
    const body = data.subarray(off + 28);
    const decipher = createDecipheriv('aes-256-gcm', key, iv);
    decipher.setAAD(data.subarray(0, off + 28)); // the header is authenticated
    decipher.setAuthTag(body.subarray(body.length - 16));
    const plain = Buffer.concat([decipher.update(body.subarray(0, body.length - 16)), decipher.final()]);
    process.stdout.write(plain.toString('utf8'));
    

    Next steps

    About the Encrypt / Decrypt Text (AES-256)

    Turn a private message into text that only someone with the password can read, then send it through any app — chat, e-mail, SMS or a shared document. The password is stretched into a 256-bit key with Argon2id (or PBKDF2-HMAC-SHA256), and the message is encrypted with AES-256-GCM, which also detects any change: a wrong password or one altered character means nothing is decrypted, rather than garbage.

    The result is a versioned, self-describing Base64 text that carries everything needed to decrypt it except the password: the key-derivation settings, a random salt and a random IV. Paste it back here — on any device, even offline — to read it, or decrypt it with the short Node.js script on this page. Encryption runs in your browser with Web Crypto; the message and the password never leave the page.

    How to use it

    1. Under Encrypt, type or paste the message.
    2. Enter a password twice, or press Suggest a strong password. Keep it somewhere safe: there is no way to recover a forgotten password.
    3. Keep the recommended Argon2id setting (PBKDF2 is faster on very old phones) and choose One line for chat apps or Block for e-mail, then press Encrypt.
    4. Copy, download or share the encrypted text. Give the password to the recipient another way — in person or by phone, never in the same message.
    5. To read a message, choose Decrypt, paste it — the words around it in a chat or an e-mail can stay — enter the password and press Decrypt. The settings are read from the message itself.

    Examples

    Test vector (for developers)
    Input
    Meet at 5 pm · password "correct horse battery staple" · PBKDF2-HMAC-SHA256 with 1,000 iterations, salt 00 01 … 0f, IV a0 a1 … ab
    Result
    VFZUAQEAAAPoAAECAwQFBgcICQoLDA0OD6ChoqOkpaanqKmqq5u51qZteneVJZ/BjZJQSamch6NJ3GtzNbnzlhw=

    A fixed vector from this tool’s tests (Node’s own crypto module decrypts it independently). The page itself always uses 600,000 iterations or Argon2id with a fresh random salt and IV, so your output differs every time — even for the same message and password.

    Block format for e-mail
    Input
    Any message, with Block (e-mail) chosen
    Result
    -----BEGIN TOOLVERSE ENCRYPTED MESSAGE-----
    Comment: Decrypt with the password at …/tools/text-encryption-tool/
    
    VFZUAQIAAQAAAw…
    -----END TOOLVERSE ENCRYPTED MESSAGE-----

    Line breaks, the comment line and the “> ” marks an e-mail reply adds are ignored when the block is pasted back.

    Common uses

    • Sending a Wi-Fi password, an account number or an address over chat or e-mail without the app — or anyone glancing at the screen — being able to read it.
    • Keeping private notes as unreadable text in a notes app, a cloud document or a backup.
    • Sharing a secret with someone who has no special software: they need only this page and the password.
    • Developers: a documented, versioned container (AES-256-GCM with Argon2id or PBKDF2) with a standalone Node.js decryptor.

    How the message is protected

    • Key derivation. The password (as UTF-8 after Unicode NFC normalisation) and a new random 16-byte salt go through Argon2id (RFC 9106) with 64 MiB of memory, 3 passes and 4 lanes — RFC 9106’s recommended setting when memory is limited — or with OWASP’s minimum of 19 MiB and 2 passes; or through PBKDF2-HMAC-SHA256 (RFC 8018) with 600,000 iterations, the OWASP Password Storage Cheat Sheet figure. The output is a 256-bit key.
    • Encryption. AES-256 in Galois/Counter Mode (NIST SP 800-38D) with a random 96-bit IV — the IV length SP 800-38D recommends — and a 128-bit authentication tag. Because every message gets a new salt, every message also gets its own key.
    • Authentication. The header (format version, key-derivation settings, salt and IV) is passed to GCM as additional authenticated data, so changing any byte of the message, including its settings, makes decryption fail.
    • Argon2id runs in a background worker (WebAssembly), so the page stays responsive while the key is derived.

    The format (TVT, version 1)

    The encrypted text is standard Base64 of these bytes (all numbers big-endian):

    • 3 bytes TVT and 1 byte format version 01 — so every message starts with VFZUAQ;
    • 1 byte key-derivation method: 01 = PBKDF2-HMAC-SHA256, followed by the iteration count (4 bytes); 02 = Argon2id v1.3, followed by the memory in KiB (4 bytes), the passes (1 byte) and the lanes (1 byte);
    • 16 bytes salt, then 12 bytes IV;
    • the AES-256-GCM ciphertext followed by its 16-byte tag; the additional authenticated data is every byte before the ciphertext.

    The block form puts the same Base64 between -----BEGIN TOOLVERSE ENCRYPTED MESSAGE----- and -----END TOOLVERSE ENCRYPTED MESSAGE-----, wrapped at 64 characters, after an optional Comment: line. The overhead is 53 bytes with PBKDF2 and 55 with Argon2id, before Base64.

    The password is the security

    AES-256 is not the weak point; the password is. Anyone who copies the encrypted text can try passwords on their own computer, as fast as their hardware allows — Argon2id makes each guess expensive, but it cannot save a password such as priya123. Use four or more random words, or the suggested 20-character password (about 99 bits of randomness), and test your own choices with the password strength checker. Never send the password in the same message or chat as the encrypted text.

    Decrypting without this website

    Your messages are not locked to MySmartCoPilot. The Decrypt without this website panel below the tool has a short Node.js script (Node.js 24.7 or later, no packages) that reads a saved message and asks for the password; this tool’s tests run that exact script against messages made here. Any language with AES-GCM and Argon2id or PBKDF2 can implement the format above.

    Limitations

    • A forgotten password cannot be recovered: there is no reset, no back door and no copy anywhere.
    • Up to 5 MB of text per message. For larger data or for files, use the File Encryption tool.
    • This is password (symmetric) encryption: anyone who learns the password can read the message. To encrypt for a person’s public key instead, use PGP Encrypt / Decrypt.
    • The encrypted text shows roughly how long the message is (53–55 bytes longer, before Base64).
    • Messages from other tools — OpenSSL enc, CryptoJS, PGP — use other formats and cannot be decrypted here. For raw AES with a known key and IV, use the AES Encryption Tool (Developer).

    Privacy

    The message and the password stay in this tab: AES runs in your browser’s Web Crypto and Argon2id in a background worker on your device. Nothing is uploaded, logged or stored; only your choice of key setting and output format is remembered on this device.

    Frequently asked questions

    Is my message or password sent anywhere?

    No. Everything happens in your browser, and the page works offline once it has loaded. The encrypted text is only shared if you copy or send it yourself.

    Why is the result different every time, even for the same message?

    Each encryption uses a new random salt and IV, so the key and the ciphertext change every time. All versions decrypt to the same message with the same password — and nobody can tell that two of them hold the same text.

    Which key setting should I choose?

    Keep Argon2id (64 MiB). It is memory-hard, which makes password guessing on graphics cards expensive. Choose the 19 MiB setting or PBKDF2 only if decrypting is too slow on the recipient’s device. You do not have to tell the recipient the setting: it is stored in the message and read automatically.

    Can AES-256 be cracked?

    AES-256-GCM combines AES, the NIST standard cipher (FIPS 197), with the authenticated GCM mode (NIST SP 800-38D), which is also widely used to protect HTTPS connections. Attacks on messages like these go after the password instead, which is why the page uses a slow, salted key derivation and warns about short passwords. A long random password makes guessing impractical.

    How is this different from the AES Encryption Tool?

    The AES tool is a developer workbench for raw keys, IVs and test vectors. This tool is for people: you choose a password, and the key derivation, salt, IV and authentication are handled and stored for you in one text you can share.

    What does “Wrong password, or the message was changed” mean?

    AES-GCM checks the whole message before showing anything. Either the password differs (check capital letters, spaces and the keyboard layout) or the text was cut off or altered on the way — copy it again from the original. The page never shows a partly decrypted or tampered message.

    Quick answers and tool search

    Type to search tools or to get a quick answer, for example 18% of 2500. Use the up and down arrow keys to move through the results, Enter to choose, and Escape to close.