Web Crypto interoperability lab

AES-256-GCM encrypt and decrypt online

Create a portable AES-GCM payload in your browser. The JSON includes PBKDF2 parameters, salt, IV, ciphertext and authentication tag so the same data can be reproduced in another application.

New payloads use PBKDF2-SHA-256 with 600,000 iterations, a fresh 16-byte salt, a 12-byte IV and a 128-bit tag.

A portable AES-GCM payload, not a mystery string

Every binary value uses Base64URL. The tag is stored separately from the ciphertext, and the payload records its work factor. That makes the format inspectable and safe to evolve.

{
  "version": 2,
  "algorithm": "AES-256-GCM",
  "kdf": { "name": "PBKDF2", "hash": "SHA-256", "iterations": 600000, "salt": "..." },
  "iv": "...", "ciphertext": "...", "tag": "..."
}

Legacy token compatibility

Older HashyTools tokens use GCM.salt.iv.ciphertext or CBC.salt.iv.ciphertext with 150,000 PBKDF2 iterations. They remain available for migration, but new integrations should use the JSON format above and AES-GCM.

What runs locally

Written and technically reviewed by Jorge. Cryptographic method reviewed August 31, 2026 against the Web Crypto API and the published deterministic interoperability vector.

Choose a developer tool

More tools for data, text and testing

Run the AES interoperability guide or read how these tools are checked.