AES Decrypt
Audience:
Low-code EngineersSkill Prerequisites:
Actions,Tokens
Decrypts one or more AES-encrypted values and saves the original text in tokens. You need the same key and initialization vector (IV) that were used to encrypt the values, for example with AES Encrypt.
The action expects standard AES in CBC mode with PKCS#7 padding, with the encrypted value as a base64 string. The decrypted bytes are read as UTF-8 text.
Typical Use Cases
- Decrypt a value you encrypted with AES Encrypt before you show it or send it on
- Decrypt a value sent by another system that shares the same key and IV
- Decrypt a value passed in a URL or hidden field
Don't use it to
- Decrypt RSA-encrypted values. Use RSA Decrypt instead.
- Decrypt values made by Connector Encrypt. They use a different key setup, see that page.
- Check a password. Passwords should be hashed and compared, not decrypted.
Which to use
| The value was encrypted with | Decrypt it with |
|---|---|
| AES Encrypt, or another tool using AES-CBC with a shared key and IV | AES Decrypt |
| RSA Encrypt or another tool using an RSA public key | RSA Decrypt |
| Connector Encrypt | Not with an action. Connectors and the Connector Format grid formatter decrypt these values. |
Related Actions
| Action Name | Description |
|---|---|
| AES Encrypt | Encrypts values with an AES key and IV. |
| RSA Decrypt | Decrypts RSA-encrypted values with a private key. |
| RSA Encrypt | Encrypts short values with a public key. |
| Get Connector | Reads connector properties into tokens, for example to load a key. |
Input Parameter Reference
| Parameter | Description | Supports Tokens | Default | Required |
|---|---|---|---|---|
| AES Key | The secret key as a base64 string, the same one used to encrypt. It must decode to 16, 24 or 32 bytes. The key generator linked in the parameter's help text creates keys in this format. | Yes | empty string | Yes |
| IV Vector | The initialization vector as a base64 string, the same one used to encrypt. It must decode to exactly 16 bytes. | Yes | empty string | Yes |
| Fields | A list of values to decrypt. In Data to Decrypt, enter the encrypted base64 value, usually a token such as [NationalIdEncrypted]. In Store in Token, enter the name of the token that gets the decrypted text, such as NationalId. Square brackets around the name are removed. | Yes, in Data to Decrypt | empty | Yes |
Output Parameters Reference
| Token | Description |
|---|---|
[<Store in Token>] | One token for each row in Fields, holding the decrypted text. An empty input gives an empty string. |
When decryption fails
| Situation | What happens |
|---|---|
| Key or IV is empty | Nothing. No tokens are set. |
| Key, IV or encrypted value isn't valid base64 | The action fails with a format error. |
| Wrong key, or the value was changed | Usually the action fails with Failed to decrypt data. Make sure the key used for decryption is the same as the one the content was encrypted with. |
| Right key, wrong IV | No error. The first 16 bytes (about the first 16 characters) come out garbled and the rest is correct. |
To handle a failure yourself, put the action inside Execute Actions and use its On Error actions.
Considerations
- A wrong key doesn't always fail. Rarely, a wrong key or a changed value decrypts without an error and returns garbage. AES here has no tamper check, so the action can't tell. Validate the result if it matters, for example check its format.
- Don't show decryption errors to users. Returning different errors for bad input can help an attacker work out encrypted values. Use a general message in the
On Erroractions. - Protect the key. Load the key and IV from tokens instead of typing them into the action, and don't log them. Only decrypt when you need the plain value, and don't save the decrypted token back to the database.
- The weaknesses of AES Encrypt apply. The IV is fixed and there's no tamper check. See AES Encrypt.
Examples
tip
To understand how to use the below examples, please see Running Examples.
1. Decrypt a national ID
This action decrypts [NationalIdEncrypted] and saves the text in [NationalId]. The key and IV come from the [AesKey] and [AesIV] tokens.
{
"Title": "AES Decrypt",
"ActionType": "DecryptData",
"Description": "Decrypt the national ID",
"Condition": "[NationalIdEncrypted] != \"\"",
"Parameters": {
"Key": "[AesKey]",
"IV": "[AesIV]",
"Fields": {
"[NationalIdEncrypted]": "NationalId"
}
}
}
Revised 09/27/2026