File Encryption / Decryption

Encrypt or decrypt any file with a passphrase, using AES-256-GCM.

About this tool

Encrypt any file with a passphrase, or decrypt one you encrypted earlier, entirely in your browser. The file never leaves your device — there's no upload and no server. Decrypting with the correct passphrase restores the original file byte-for-byte, with its original name.

What it uses. AES-256-GCM for the encryption itself, through the browser's built-in Web Crypto API — the same vetted implementation the browser uses for HTTPS. GCM is an "authenticated" mode: as well as hiding the contents, it detects any tampering, so a corrupted or modified encrypted file fails to decrypt rather than producing garbage.

How the passphrase becomes a key. Your passphrase isn't used directly. It's stretched into a 256-bit key with PBKDF2 (250,000 rounds of SHA-256) using a random salt generated per file and stored in the output. The heavy round count makes brute-forcing a weak passphrase slow; the per-file salt means two files encrypted with the same passphrase don't reveal that fact and can't be attacked together.

The passphrase is the only key. There is no recovery, no backdoor, no reset. If you forget it, the file is unrecoverable — that's the point of real encryption. Store the passphrase in a password manager, and keep a copy of an important file somewhere safe before encrypting the only version.

Choosing a passphrase. Length is what matters. Several random words (a passphrase) beats a short string of symbols, and beats any word or name from a dictionary. Reusing a passphrase you use elsewhere weakens this too. For a strong one, use the password generator.

What this protects against, and what it doesn't. It protects a file at rest — on a USB stick, in cloud storage, as an email attachment, on a shared machine. It does not hide that a file exists or its size, it doesn't protect the original once you've decrypted it back to disk, and it can't help if your device itself is compromised by malware that reads the file (or your keystrokes) before encryption. The metadata (filename, size) of the original is inside the encrypted blob and safe; the encrypted file's own name is up to you.

Interoperability. The output format is specific to this tool (salt + IV + ciphertext in a simple container). Decrypt it here, not with OpenSSL or GPG. For encrypting text rather than a file, use text encryption; to verify a file arrived intact, the file checksum tool.

Frequently asked questions

Is my file ever uploaded to a server?
No. Reading, encrypting, and decrypting all happen locally through the Web Crypto API. Nothing about the file or passphrase leaves your device.
What happens if I forget the passphrase?
The file cannot be recovered. There is no reset or backdoor — the passphrase is the only key, as with any real encryption.
What algorithm is used?
AES-256-GCM for encryption and integrity, with the key derived from your passphrase via PBKDF2 (250,000 iterations, SHA-256) and a random per-file salt.
Can I decrypt the file with OpenSSL or another tool?
No. The container format is specific to this tool. Decrypt it here with the same passphrase.
Does it work offline?
Yes, once the page has loaded. No network is used at any point.
Is there a file size limit?
Large files are read entirely into memory, so very large ones (multi-GB) may exceed what the browser tab can hold. Files up to a few hundred MB are fine on most machines.