Free · No account · Runs in your browser
Text Encryption Tool – Encrypt & Decrypt Text Online
Transform text using Base64, ROT13, Caesar cipher, XOR, and AES-256-GCM. All processing happens locally in your browser — your text and keys never leave your device.
Text Encryption
Use −25 to +25. Shifts wrap around modulo 26, so only 26 distinct letter substitutions exist.
Encryption Methods Explained
Six methods ranging from simple encoding to strong AES encryption. Each is labeled with its real security level so you can choose correctly.
Base64
Converts text into an ASCII-safe representation. Anyone can decode it — it hides nothing.
Used for: email attachments, data URLs, API payloads where binary-safe transport is needed.
ROT13
Rotates each letter by 13 positions. Reversible without a key — applying it twice returns the original.
Used for: hiding spoilers on forums, light casual obfuscation.
Caesar Cipher
Shifts letters by a fixed amount (default 3). Trivial to break by brute force — only 26 possible keys.
Used for: education, puzzles, children's secret messages.
Custom Shift
Same algorithm as Caesar with shifts between −25 and +25. Shifts wrap around modulo 26, so only 26 distinct letter substitutions exist.
Used for: custom puzzles, teaching cryptography basics.
XOR
Lightweight byte-level obfuscation using a repeating key. It should not be used as a replacement for authenticated encryption.
Used for: lightweight obfuscation when both sides share a simple key.
AES-256-GCM
Industry-standard authenticated encryption via the browser's Web Crypto API. Uses PBKDF2 with 100,000 iterations, random salt, and random IV.
Used for: sensitive messages, private notes, short secrets, and data that needs authenticated encryption.
User Cases — Where & How Each Method Is Used
Real-world scenarios for each encryption option, with the specific workflow users follow in each case.
Sending binary-safe data over text channels
A developer has a JSON payload containing special characters that might get mangled in an email body or a legacy API. They encode it to Base64 first so the receiver can decode it safely on the other side.
Hiding plot spoilers from casual readers
A forum moderator wants to discuss a movie's ending without ruining it for people scrolling by. They ROT13 the spoiler so only readers who choose to decode it will see the content.
Teaching cryptography or designing scavenger hunts
A teacher prepares a lesson on classical cryptography. Students receive ciphertext and must figure out the shift value by hand, learning how frequency analysis and brute force work on weak ciphers.
Obfuscating a shared note between friends
Two friends want to pass a note through a shared Google Doc without the doc's contents being readable to anyone else with access. They agree on a passphrase beforehand and XOR the note with it.
Sharing a Wi-Fi password securely
A homeowner wants to send their Wi-Fi password to a guest via a messaging app they don't fully trust. They encrypt the password with AES-256-GCM using a strong passphrase, share the ciphertext through the app, and share the passphrase over a phone call.
Encrypting diary entries before saving to cloud
A user keeps a private journal in a notes app synced across devices. They encrypt each entry with a personal master key before pasting it in, so even if the account is compromised, the content stays private.
Protecting invoice numbers or client data in email
A freelancer emails a client a list containing account numbers and pricing. They encrypt the list with AES and a shared passphrase so intercepted emails remain unreadable.
Layering ciphers in escape-room clues
A game designer wants a clue that requires two decoding steps. They ROT13 first, then Caesar shift the result. Players must reverse both steps in the correct order.
Common Uses
Quick reference for which method fits which job.
| Use case | Best method | Why |
|---|---|---|
| Sensitive text & secrets | AES-256-GCM | Strong, authenticated encryption; key shared through a separate channel. |
| API / email payloads | Base64 | Preserves special characters during transport over text-only channels. |
| Spoiler hiding | ROT13 | Keyless, reversible by anyone who chooses to decode. |
| Classroom cryptography | Caesar / Custom Shift | Simple enough to break by hand, ideal for learning. |
Capabilities & Limitations
What this tool handles natively, and what it deliberately leaves to other software.
What it does
- Offer six transformation methods from encoding to strong encryption.
- Use real AES-256-GCM via the browser's Web Crypto API with PBKDF2 key derivation.
- Keep your text and key entirely in your browser — nothing is transmitted.
- Never display the secret key in the result metadata.
- Support plain text, Hex, and Base64 output formats for text-based transport.
What it does not
- Store, log, or transmit your key — even we cannot recover it if you lose it.
- Encrypt files or images (text only, 10,000 characters max).
- Provide strong encryption with ROT13, Caesar, or Base64 — these are encoding/obfuscation methods, not modern encryption.
- Replace dedicated password managers or encrypted email services for ongoing communication.
Troubleshooting
Common errors and what they actually mean.
Decryption returns gibberish or "Decryption failed"
With AES-256-GCM this almost always means the key doesn't match what was used to encrypt. Even one wrong character will fail the authentication check. With XOR, a wrong key produces nonsense but no error — verify the key matches exactly.
"Output format does not match"
When decrypting, the output format dropdown must match the format the ciphertext was created in. If the ciphertext ends with = or contains only A-Z a-z 0-9 +/, select Base64. If it is all 0-9 a-f, select Hex.
AES encryption feels slow on long text
AES-256-GCM uses PBKDF2 with 100,000 iterations to derive the key — this is intentional and protects weak passwords. It's expected to take a short moment, especially near the 10,000-character limit.
Character limit reached
The input is capped at 10,000 characters. This covers most messages, passwords, and short notes. For larger documents, use dedicated file encryption software instead.
Frequently Asked Questions
Everything you need to know about encryption, privacy, and the methods available.
Is the encryption secure?
All processing happens in your browser and no data is sent to any server. AES-256-GCM uses the Web Crypto API with PBKDF2 key derivation for strong encryption, while methods like Base64, ROT13, and Caesar cipher are simple encodings intended for casual, non-sensitive purposes.
Do I need to create an account?
No account is required. The tool is 100% free and runs entirely in your browser without login or signup.
Which encryption methods can I use?
You can choose from Base64, ROT13, Caesar cipher, custom shift, XOR encoding, and AES-256-GCM for transforming your text.
Does this tool store my data?
No, all processing happens entirely in your browser. Your text and keys never leave your device, and we have no way to recover your data if you lose your key.
Is there a limit to how much text I can process?
The input is limited to 10,000 characters, which covers most messages, passwords, and short text. For larger files, use dedicated file encryption software.