CipherTools
ToolsBlogsSnippets
ToolsBlogsSnippets
  • MD5 Text Hash
  • MD5 File Hash
  • BKDR Text Hash
  • BKDR File Hash
  • SHA-256 Text Hash
  • SHA-256 File Hash
  • SHA-512 Text Hash
  • SHA-512 File Hash
  • SHA-3 Text Hash
  • SHA-3 File Hash
  • SHAKE Text Hash
  • SHAKE File Hash
  • Argon2 Text Hash
  • Argon2 File Hash
  • CRC Text Checksum
  • CRC File Checksum
  • HMAC Text Generator
  • HMAC File Generator
  • BLAKE2 Text Hash
  • BLAKE2 File Hash
  • BLAKE3 Text Hash
  • BLAKE3 File Hash
  • CityHash Text Hash
  • CityHash File Hash
  • FarmHash Text Hash
  • FarmHash File Hash
  • xxHash Text Hash
  • xxHash File Hash
  • MurmurHash2 Text Hash
  • MurmurHash2 File Hash
  • MurmurHash3 Text Hash
  • MurmurHash3 File Hash
  • bcrypt Text Hash
  • bcrypt File Hash
  • scrypt Text Derivation
  • scrypt File Derivation
  • AES Encryption and Decryption
  • AES File Encryption
  • AES File Decryption
  • AES-GCM Encryption and Decryption
  • ChaCha20-Poly1305 Text
  • ChaCha20-Poly1305 File Encryption
  • ChaCha20-Poly1305 File Decryption
  • DES Encryption and Decryption
  • DES File Encryption
  • DES File Decryption
  • RSA Encryption and Decryption
  • RSA File Encryption
  • RSA File Decryption

Symmetric encryption · AES-GCM

AES-GCM Encryption & Authentication

Encrypt or decrypt data with AES-GCM while keeping every byte on your device. Configure the key, nonce, AAD, and tag length to export ciphertext with integrity or to verify inbound payloads.

AES-GCM encryption

Run authenticated encryption entirely in your browser. Configure keys, nonces, AAD, and tag lengths to export ciphertext + auth tags, or supply those values to verify and recover plaintext.

The result is ciphertext concatenated with the tag.

Short keys are zero-padded; longer inputs are truncated.

Nonces must match on both sides and should never be reused with the same key.

AES-GCM tips

AES-GCM layers a GHASH authenticator on top of CTR mode, so ciphertext and auth tags must always travel together. Any bit flip or mismatch during decryption causes authentication to fail.

Never reuse a nonce with the same key. Twelve random bytes are the de facto standard, and longer tags mean stronger integrity guarantees. Additional authenticated data (AAD) is left in the clear but still protected by the tag.

No padding is required—GCM accepts any plaintext length. Make sure both parties agree on key size, nonce, AAD, tag length, and encodings before exchanging data.

© 2026 CipherTools. All computations run locally in your browser.