---
title: AES (Advanced Encryption Standard)
slug: aes-advanced-encryption-standard
docTags: 
createdAt: 2026-02-24T10:08:08.166Z
---

[AES (Advanced Encryption Standard)](https://apps.make.com/crypto#encryptor-modules) is a symmetric algorithm, using the same key for both encryption and decryption. You can choose between simple and advanced modules in the Encryptor app. Advanced modules are recommended, giving you more control and allowing your key to be hidden.&#x20;

The AES algorithm has four components:

| **Component**             | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| ------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Key**                   | Select a key of either 128 or 256 bits. A longer key provides more<br />security.                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| **Initialization vector** | A random value used at the beginning of encryption to make sure<br />the same data looks different each time it's encrypted, so no one<br />can guess the plaintext value from the results. The initialization<br />vector is sometimes called Nonce.<br /><br />You can choose UTF-8, Base64, or Hexadecimal for encoding.                                                                                                                                                                                                |
| **Authentication tag**    | A code generated after encrypting the message. It is also called an<br />integrity check value (ICV) or message authentication code (MAC).<br /><br />This value is calculated using the cyphertext and the initialization<br />vector. It is a unique value generated from the encrypted message.<br />The tag is sent with the message and the recipient repeats the<br />process to generate the authentication tag using the received<br />message. If the two tags are the same, the shared message is<br />the same. |
| **Modes**                 | Methods for encrypting data. <br />* CBC (Cipher Block Chaining) mode: Encrypts each block of &#xA;data by combining it with the previous block's ciphertext and &#xA;requires an initialization vector to start the chain.
* GCM (Galois/Counter) mode: Combines encryption with the &#xA;authentication tag to ensure the integrity of the data.                                                                                                                                                                         |

::::::ExpandableHeading
## Example: Encrypt and decrypt a message with the Encryptor app AES (simple) modules

In this example we will:

1. Select content to encrypt and send to a recipient.
2. Select a secret key to share with the recipient ahead of time, to decrypt the content.
3. Encrypt the message.
4. Decrypt the message.

**Step 1: Select content to encrypt**

In this example, we set a variable `InitialText` with our content to send with encryption.&#x20;

In your scenario, you may have the content set another way or pulled from a different source.

::Image[]{src="https://api.archbee.com/api/optimize/oAyFj2GHlBeBVWF5OAir2/9wX8upJMbxY8yqAmPXHk--20260209-123012.png" size="60" width="724" height="555" position="flex-start" showCaption="false"}

**Step 2: Select a secret key**

A secret key can be any content agreed upon by the sender and recipient: a word, a phrase, or a series of characters.&#x20;

In AES simple encryption and decryption, the secret key is not hidden. If you share the scenario with any other users or download the blueprint to share, your secret key is exposed.

**Step 3: Encrypt the message:**

:::::WorkflowBlock
:::WorkflowBlockItem
Add the **Encryptor > AES Encrypt (simple)** module to your scenario.
:::

:::WorkflowBlockItem
Select the **Input encoding**. In this example, we use UTF-8.
:::

:::WorkflowBlockItem
In the **Data** field, map or input the value of the content you want to encrypt.
:::

:::WorkflowBlockItem
Select the **Output encoding.** In this example, we use hexadecimal.
:::

::::WorkflowBlockItem
In the **Secret key** field, enter the secret key you have shared with the recipient.

:::hint{type="warning"}
The secret key is not hidden. If you share the scenario with any other users or download the blueprint to share, your secret key is exposed.
:::
::::

:::WorkflowBlockItem
Click **Save**.

::Image[]{src="https://api.archbee.com/api/optimize/oAyFj2GHlBeBVWF5OAir2/OVqt4BWqZJLxD-rkE-7gj-20260216-120555.png" size="40" width="437" height="462" position="flex-start" showCaption="false"}
:::
:::::

The message is encrypted. The output of this module is the encrypted message in hexadecimal format.



**Step 4: Decrypt the message:**

:::::WorkflowBlock
:::WorkflowBlockItem
Add the **Encryptor > AES Decrypt (simple)** module to your scenario.
:::

:::WorkflowBlockItem
Select the **Input encoding**. In this example, we use hexadecimal to match the output encoding used to encrypt the message.
:::

:::WorkflowBlockItem
In the **Data** field, map or input the value of the content you want to decrypt.
:::

:::WorkflowBlockItem
Select the **Output encoding.** In this example, we use UTF-8.
:::

::::WorkflowBlockItem
In the **Secret key** field, enter the secret key you have shared with the sender.

:::hint{type="info"}
The secret key is not hidden. If you share the scenario with any other users or download the blueprint to share, your secret key is exposed.
:::
::::

:::WorkflowBlockItem
Click **Save**.

::Image[]{src="https://api.archbee.com/api/optimize/oAyFj2GHlBeBVWF5OAir2/_5kk3IwM3AKwNJ2TDeYqF-20260216-121619.png" size="40" width="429" height="454" position="flex-start" showCaption="false"}
:::
:::::

The message is decrypted. The output of this module is the decrypted message and should match the original content set in the `InitialText` variable.

:::hint{type="info"}
If the wrong secret key is used, the message has been modified, or the encoding does not match, the module outputs an error.
:::
::::::

::::::ExpandableHeading
## Example: Encrypt and decrypt a message with the Encryptor app AES (advanced) modules

In this example we will:

1. Select content to encrypt and send to a recipient.
2. Generate an AES key.
3. Set an initialization vector.
4. Encrypt the message (GCM ciphor algorithm).
5. Decrypt the message (GCM ciphor algorithm).

**Step 1: Select content to encrypt**

In this example, we set a variable `InitialText` with our content to send with encryption.&#x20;

In your scenario, you may have the content set another way or pulled from a different source.

::Image[]{src="https://api.archbee.com/api/optimize/oAyFj2GHlBeBVWF5OAir2/9wX8upJMbxY8yqAmPXHk--20260209-123012.png" size="60" width="724" height="555" position="flex-start" showCaption="false"}

**Step 2: Generate an AES key**

:::hint{type="info"}
To encrypt and decrypt messages with AES, the key must be shared between the sender and recipient ahead of time.
:::



To generate an AES key:

::::WorkflowBlock
:::WorkflowBlockItem
Go to an encryption key generator website of your choice. In this example, we use [this tool](https://randomkeygen.com/encryption-key).
:::

:::WorkflowBlockItem
Select or set the following values:
**Key Size**: 128 or 256 bits. In this example we use 256 bits.
**Format:** Hexadecimal or Base64. In this example, we use hexadecimal.
:::

:::WorkflowBlockItem
Click **Generate&#x20;**&#x74;o get your **AES Key**. If you are using a different tool to generate your key, your steps may be different.

::Image[]{src="https://api.archbee.com/api/optimize/oAyFj2GHlBeBVWF5OAir2/M-GauvU6EG0dnC5jhsKxv-20260217-101920.png" size="90" width="886" height="429" position="flex-start" showCaption="false"}
:::

:::WorkflowBlockItem
Copy the AES key save it in a safe place.
:::
::::

You will use this AES key to create a keychain and encrypt your content.&#x20;



**Step 3: Set an initialization vector**

Although AES key generator websites also provide initialization vectors, it is best to use a different initialization vector every time, for more secure encryption.

For this reason, we use the **Set variable** module to generate a new initialization variable before the content is encrypted.

::Image[]{src="https://api.archbee.com/api/optimize/oAyFj2GHlBeBVWF5OAir2/ao-OH9MM7wlO3h0wZ4huC-20260217-102107.png" size="90" width="1000" height="325" position="center" showCaption="false"}

::::WorkflowBlock
:::WorkflowBlockItem
Add the **Tools > Set variable** module to your scenario.
:::

:::WorkflowBlockItem
In the **Variable name** field, enter a name for your initialization vector.
:::

:::WorkflowBlockItem
In the **Variable value** field, enter the following to generate a substring of a unique ID (128 bit) with only the first 16 characters:

`substring(uuid; 0; 16)`

::Image[]{src="https://api.archbee.com/api/optimize/oAyFj2GHlBeBVWF5OAir2/-algyZOvbnfpgWL_dOpCm-20260217-104345.png" size="40" width="436" height="293" position="flex-start" showCaption="false"}

The `UUID` variable can be found under the **Text and binary functions** tab:

::Image[]{src="https://api.archbee.com/api/optimize/oAyFj2GHlBeBVWF5OAir2/sP9hOOImQvM13OX8B-xaE-20260217-104530.png" size="40" width="383" height="368" position="flex-start" showCaption="false"}
:::
::::

The initialization vector variable is mapped in the encryption module in the next step.&#x20;

:::hint{type="info"}
You need to use a 128-bit initialization vector for the GCM cipher algorithm. For the CBC cipher algorithm, you can use a 96-bit initalization vector instead. GCM is the preferred method, shown here.
:::



**Step 4: Encrypt the message (GCM ciphor algorithm)**

::::WorkflowBlock
:::WorkflowBlockItem
Add the **Encryptor > AES Encrypt (advanced)** module to your scenario.
:::

:::WorkflowBlockItem
Click **Create a keychain**.
:::

:::WorkflowBlockItem
Enter a **Name** for your AES key.
:::

:::WorkflowBlockItem
In the **Key** field, enter your AES key.
:::

:::WorkflowBlockItem
In the **Key Encoding** field, select Hexadecimal.
:::

:::WorkflowBlockItem
Click **Create**.
:::

:::WorkflowBlockItem
In the **Bits** field, select 256.
:::

:::WorkflowBlockItem
In the **Input encoding** field, select UTF-8.
:::

:::WorkflowBlockItem
In the **Data** field, map the value of the content you want to encrypt.
:::

:::WorkflowBlockItem
In the **Output encoding** field, select Hexadecimal.
:::

:::WorkflowBlockItem
In the **Cipher Algorithm** field, select GCM.
:::

:::WorkflowBlockItem
In the **Initialization Vector Encoding** field, select UTF-8.
:::

:::WorkflowBlockItem
In the **Initalization Vector** field, map the value of the initialization vector created in the previous **Set variable** module.
:::

:::WorkflowBlockItem
Click **Save**.

::Image[]{src="https://api.archbee.com/api/optimize/oAyFj2GHlBeBVWF5OAir2/7KEmOjBuGMi36mig1HDoe-20260217-110725.png" size="60" width="734" height="815" position="flex-start" showCaption="false"}
:::
::::

The message is encrypted.

The output of this module has the Data, Initialization Vector, and Authentication Tag in hexadeximal format. You will use these values to decrypt the message.

::Image[]{src="https://api.archbee.com/api/optimize/oAyFj2GHlBeBVWF5OAir2/oUNWjuzX_OVonUUpPOwcq-20260217-111529.png" size="40" width="410" height="120" position="flex-start" showCaption="false"}

:::hint{type="info"}
If you run the scenario again, the output data will be different because the initialization vector is a variable that changes with each run.&#x20;

The initialization vector and the authentication tag can be sent in cleartext to the recipient; they don't need to be secured.
:::

****

**Step 5: Decrypt the message (GCM ciphor algorithm)**

:::::WorkflowBlock
:::WorkflowBlockItem
Add the **Encryptor > AES Decrypt (advanced)** module to your scenario.
:::

::::WorkflowBlockItem
Use the same keychain created in Step 4 above or create a new keychain with the same values.

:::hint{type="info"}
In AES encryption, the sender and recipient use the same key to encrypt and decrypt the message.
:::
::::

:::WorkflowBlockItem
In the **Bits** field, select 256.
:::

:::WorkflowBlockItem
In the **Input encoding** field, select Hexadecimal to match the encryption output encoding.
:::

:::WorkflowBlockItem
In the **Data** field, map the value of the encryption output Data.
:::

:::WorkflowBlockItem
In the **Output encoding** field,select UTF-8.
:::

:::WorkflowBlockItem
In the **Cipher Algorithm** field, select GCM to match the same algorithm used for encryption.
:::

:::WorkflowBlockItem
In the **Initialization Vector Encoding** field, select Hexadecimal to match the encyption output encoding of this value.
:::

:::WorkflowBlockItem
In the **Initalization Vector** field, map the value of the initialization vector from the encryption output.
:::

:::WorkflowBlockItem
In the **Authentication Tag Encoding** field, select Hexadecimal to match the encryption output encoding of this value.
:::

:::WorkflowBlockItem
In the **Authentication Tag** field, map the value of the authentication tag from the encryption output.
:::

:::WorkflowBlockItem
Click **Save**.

::Image[]{src="https://api.archbee.com/api/optimize/oAyFj2GHlBeBVWF5OAir2/t7yTsWDw9Ew6kpsCYYkAy-20260217-120827.png" size="50" width="431" height="979" position="flex-start" showCaption="false"}
:::
:::::

The message is decrypted. The output of this module is the decrypted message and should match the original content set in the `InitialText` variable.

:::hint{type="warning"}
If the wrong key is used, the message has been modified, or there is a discrepancy with the initalization vector or authentication tag, the module outputs an error.
:::
::::::

