Text encryption

Encrypt text locally, recover older data and explore classic ciphers.

About this tool

Encryption uses authenticated AES-GCM or ChaCha20-Poly1305. Enter text and a strong passphrase, encrypt, then keep the whole Base64 package. Use the swap button to place an output in the input before decrypting. Decryption recognizes the authenticated algorithm and shows it in the result; the algorithm selector chooses new encryption.

TW2 stores its algorithm identifier, a fresh random 16-byte salt, a fresh 12-byte nonce and ciphertext with a 16-byte tag. Its compatibility contract is PBKDF2-HMAC-SHA256 with {iterations} iterations. No passphrase normalization or trimming occurs. Empty text is valid; new encryption needs a nonempty passphrase. Empty passphrases remain readable for older data. Valid UTF-8, including an initial U+FEFF, is preserved.

Older headerless AES-GCM-256 is normally recognized. If its random salt resembles a format header, select the explicit older-GCM option before decrypting. Authentication is still required. Unknown or incomplete modern headers never silently select another cipher.

Old AES-CTR/CBC recovery is a separate, explicit operation. Select the original algorithm; a matching TW2 identifier is required. These formats have no integrity protection. The tool neither creates new CTR/CBC packages nor accepts them in normal authenticated decryption. Recovered text can be wrong or manipulated even without an error.

Classic ciphers are for learning. Caesar uses integer shifts on ASCII letters; Vigenère uses only ASCII key letters, ignoring other key characters. Leet and Morse cannot restore all original text. Encode and decode are explicit actions.

Text is limited to 64 KiB UTF-8, passphrases to 1 KiB and encoded packages to 100,000 characters. Text and passphrase are not stored in cookies or URLs. Pinned views retain their current input in memory until closed; closing or leaving an unpinned view clears it. Edits and tab changes discard old results; pending browser work may finish internally but cannot publish an outdated result. JavaScript memory clearing and constant-time execution are not guaranteed.

The masked passphrase field is single-line; pasting line breaks is rejected instead of silently removing them.

AES-192 is offered only when supported by this browser. Other supported key sizes are not substituted when reading a 192-bit package.