Skip to main content

Text Encryption

AES-GCM encryption plus classical ciphers, all local

AES-GCM authenticatedEncryption vs encoding labelledPassword never leaves browser

Mode

Algorithm

Modern authenticated encryption. The same plaintext produces different ciphertext each time, and tampering is detected. Requires a password.

Result

Enter something to process

Everything runs locally in your browser — neither the password nor the content is ever sent anywhere. If you lose the password the encrypted content cannot be recovered; this tool stores nothing.

Last updated: 2026-10-11

About this tool

The most important thing an encryption tool can do is be clear about which options actually protect privacy and which merely change the representation. AES-GCM is real encryption — without the password, the content cannot be recovered. Base64 and Morse code are encodings: anyone who gets them can read them instantly, so they suit escaping problems or non-sensitive content only. This tool groups them together and labels each clearly to prevent misuse. The AES-GCM path uses the browser’s WebCrypto implementation, includes integrity verification, and produces different ciphertext every time for the same plaintext. All computation is local; the password and content never leave your device.

Features

AES-GCM authenticated encryption

A modern recommended algorithm with built-in integrity checking. Tampered ciphertext or a wrong password fails loudly instead of returning plausible-looking garbage.

Random IV, unique ciphertext

Every encryption uses a fresh random initialisation vector, so the same plaintext never produces the same ciphertext — no comparisons leak information.

Encryption and encoding kept distinct

Base64 and Morse code are explicitly marked as "encoding, no confidentiality" so they are not mistaken for encryption.

Adjustable Caesar shift

Set any shift from 1 to 25 — useful for teaching, demos and puzzles.

Password strength reminder

A warning appears for passwords under 8 characters — with AES, the password strength is the whole ballgame.

One-click direction swap

After decrypting you can send the result back to the input to keep working or verify in reverse.

How to use

  1. 1

    Choose mode and algorithm

    Decide whether to encrypt or decrypt, then pick an algorithm.

  2. 2

    Set the key

    AES-GCM needs a password; Caesar shift needs a shift amount.

  3. 3

    Paste the content

    Paste the text to process; the result appears as you type.

  4. 4

    Copy the result

    Copy the ciphertext or plaintext, or swap it back into the input to continue.

Options

Mode
Encrypt or decrypt.
Algorithm
AES-GCM (real encryption) or Caesar shift, Morse code and Base64 (encoding or classical ciphers with no real confidentiality).
Password
The password used by AES-GCM. Its strength determines the security of the ciphertext.
Shift amount
Letter offset for the Caesar cipher, from 1 to 25.

Common use cases

  • Encrypt a sensitive note before storing it in a notes app
  • Add a layer of encryption before sending something over an untrusted channel
  • Demonstrate how a Caesar shift works
  • Convert Chinese text to Morse code, or decode it back

FAQ

Questions you may have about this tool

How is AES-GCM different from plain AES?

GCM is an authenticated mode: besides confidentiality it provides integrity checking. If the ciphertext is altered, decryption fails outright instead of returning wrong content. Modes like CBC provide confidentiality only, so a tampered message usually decrypts to garbage and you cannot tell whether the password was wrong or the data was damaged. New applications should prefer an authenticated mode.

Why is the output different each time I encrypt the same text?

Because every encryption generates a random initialisation vector (IV) that participates in the computation and is stored alongside the ciphertext. This is correct and necessary — if the same plaintext always produced the same ciphertext, an attacker could compare ciphertexts to learn whether two messages are identical, leaking information. Decryption reads the IV back out of the ciphertext, so it still recovers the original.

Is Base64 encryption?

No. Base64 is an encoding that represents binary data using printable characters; anyone can reverse it in one step with no key. It solves "make this data survive a text-only channel", not confidentiality. The algorithm list labels this explicitly to avoid confusion.

Is my password recorded anywhere?

No. The password lives in browser memory only for the duration of the operation — it is never sent and never written to storage, and it disappears when you close the page. That is also why a lost password means unrecoverable content: it is the unavoidable cost of local encryption, so keep the password safe.

Why is the encrypted result much longer than the input?

Because the ciphertext also carries the initialisation vector and the authentication tag, and the whole thing is Base64-encoded (turning binary into text inflates it by about a third). None of that is waste — it is what makes the result both secure and verifiable.

Can the Caesar cipher protect my data?

No. There are only 25 possible shifts — tryable by hand, let alone by computer. It is a classical substitution cipher and today belongs in teaching or puzzle-solving. It is included so the idea of shifting is visible, not as a usable protection method.

Does Morse code support Chinese?

Standard Morse defines Latin letters, digits and common punctuation — there is no Chinese encoding scheme. Out-of-range characters are reported explicitly rather than being silently dropped. To encode Chinese, use AES-GCM, or convert it to Base64 first.

Why use WebCrypto instead of implementing the algorithm myself?

Cryptographic implementations are extremely easy to get wrong; a hand-written AES may introduce side-channel flaws or misuse the mode. WebCrypto is provided by the browser and operating system, has been thoroughly reviewed, and supplies cryptographically secure randomness. When WebCrypto is unavailable this tool stops rather than substituting an insecure fallback.