Skip to content

Free tool

Encrypt text

Lock text with a password into a block you can paste anywhere. Only the password opens it. Nothing is uploaded.

AES-256-GCMNetwork: none
0 bytes

Pasting an encrypted block here switches to Decrypt.

Send it to the other person a different way than the block.

A typo here would lock you out.

The password is stretched 600,000 times. Takes a moment.

How it works

A password in, a sealed block out

Stretch the password
PBKDF2-SHA256 runs 600,000 times with a fresh random salt, so every guess an attacker makes costs real time.
Encrypt and sign
AES-256-GCM encrypts the text and adds a 16-byte tag. Change one character of the block and it refuses to open.
Wrap it as text
Salt, IV and ciphertext are joined and wrapped between BEGIN and END lines, so email, chat and notes apps leave it intact.
Open it anywhere
Paste the block back here with the password, on any device. No account, no server, no expiry.

Format

What the block looks like

-----BEGIN PROTECTEDSHARE MESSAGE-----
Version: 2 (AES-256-GCM, PBKDF2-SHA256 600k, HKDF)

<salt>.<iv>.<ciphertext>          base64url, wrapped at 64 columns
-----END PROTECTEDSHARE MESSAGE-----

The AES key comes from HKDF-SHA256 over the stretched password with the info string ps/v2/enc, and the additional authenticated data is ps/v2/password. Nothing about you or the text is in the header.

Use it for

When a block beats a link

  • Keeping recovery codes or a seed phrase in a notes app or cloud drive you don't fully trust.
  • Sending a secret through a channel that keeps history, when you can share the password another way.
  • Storing an encrypted copy of a secret for longer than our 30-day link limit.

FAQ

Questions

Is my text sent to your server?

No. The text and password are processed by JavaScript in this tab, in a Web Worker. The tool has no upload endpoint. The page itself loads from our server like any website; after it has loaded you can disconnect and it keeps working.

What encryption does it use?

Your password is stretched with PBKDF2-SHA256 at 600,000 iterations with a random 16-byte salt, then HKDF-SHA256 derives an AES-256-GCM key. A random 12-byte IV is used for each message. GCM also detects any change to the block, so a tampered block fails to open instead of decrypting to garbage.

What if I forget the password?

The text can't be recovered. There's no reset and no copy anywhere else. That's the point, so store the password in a password manager.

How strong does the password need to be?

Anyone who gets the block can try passwords offline as fast as their hardware allows, with no rate limit. The 600,000-iteration stretch slows each guess, but a short or common password will still fall. Use the Generate button for a five-word passphrase, or a long random password.

Can someone open the block without this website?

Yes. The format is documented on the page: salt, IV and ciphertext in base64url, using standard algorithms that any mainstream crypto library can reproduce. The code is open source under the MIT license.

How is this different from a secure note?

A secure note stores ciphertext on our server and gives you a link that can expire or burn after one read. This tool stores nothing: you keep the block and decide where it goes. Use a note to hand off a secret, and this tool to keep or send an encrypted copy yourself.

Related tools