About AES-GCM 256-Bit Text Encryptor & Decryptor
Protect confidential text using authenticated AES-GCM 256-bit encryption. Uses PBKDF2 (100,000 rounds of SHA-256) to derive keys from your passphrase, generates unique 12-byte IVs and 16-byte salts, and authenticates data integrity.
Key Capabilities & Features
- Authenticated AES-GCM 256-bit symmetric encryption
- PBKDF2 key derivation with 100,000 iterations of SHA-256
- Cryptographic 12-byte random IV and 16-byte random salt per payload
- Portable salt:iv:ciphertext Base64 output packaging
- Automatic authentication tag verification (rejects modified payloads)
How to Use AES-GCM 256-Bit Text Encryptor & Decryptor
Select Action
Choose Encrypt Text or Decrypt Payload.
Enter Secret Passphrase
Provide the secret passphrase used to derive the encryption key.
Execute & Copy
Encrypt to generate secure ciphertext or decrypt to retrieve authenticated plaintext.
Privacy & In-Browser Execution Guarantee
All cryptographic operations execute locally in your browser memory via the W3C Web Cryptography API. Passwords and plaintext are never transmitted over any network.
Frequently Asked Questions
What happens if someone modifies the encrypted ciphertext?
AES-GCM includes an authentication tag. If even a single byte or character is tampered with, decryption will immediately fail and reject the payload.
Can NEOKYRU recover my password if I forget it?
No. Because encryption runs strictly on your machine with zero server storage, only the exact original passphrase can derive the decryption key.
Why is AES-GCM preferred over older AES-CBC mode?
AES-GCM provides authenticated encryption (AEAD), combining confidentiality with built-in cryptographic integrity verification to protect against padding oracle attacks.