Skip to main content
Version: 1.28 (Current)

AES Decrypt

Audience: Low-code Engineers

Skill Prerequisites: Actions, Tokens

Decrypts one or more AES-encrypted values and saves the original text in tokens. You need the same key and initialization vector (IV) that were used to encrypt the values, for example with AES Encrypt.

The action expects standard AES in CBC mode with PKCS#7 padding, with the encrypted value as a base64 string. The decrypted bytes are read as UTF-8 text.

Typical Use Cases​

  • Decrypt a value you encrypted with AES Encrypt before you show it or send it on
  • Decrypt a value sent by another system that shares the same key and IV
  • Decrypt a value passed in a URL or hidden field

Don't use it to​

  • Decrypt RSA-encrypted values. Use RSA Decrypt instead.
  • Decrypt values made by Connector Encrypt. They use a different key setup, see that page.
  • Check a password. Passwords should be hashed and compared, not decrypted.

Which to use​

The value was encrypted withDecrypt it with
AES Encrypt, or another tool using AES-CBC with a shared key and IVAES Decrypt
RSA Encrypt or another tool using an RSA public keyRSA Decrypt
Connector EncryptNot with an action. Connectors and the Connector Format grid formatter decrypt these values.
Action NameDescription
AES EncryptEncrypts values with an AES key and IV.
RSA DecryptDecrypts RSA-encrypted values with a private key.
RSA EncryptEncrypts short values with a public key.
Get ConnectorReads connector properties into tokens, for example to load a key.

Input Parameter Reference​

ParameterDescriptionSupports TokensDefaultRequired
AES KeyThe secret key as a base64 string, the same one used to encrypt. It must decode to 16, 24 or 32 bytes. The key generator linked in the parameter's help text creates keys in this format.Yesempty stringYes
IV VectorThe initialization vector as a base64 string, the same one used to encrypt. It must decode to exactly 16 bytes.Yesempty stringYes
FieldsA list of values to decrypt. In Data to Decrypt, enter the encrypted base64 value, usually a token such as [NationalIdEncrypted]. In Store in Token, enter the name of the token that gets the decrypted text, such as NationalId. Square brackets around the name are removed.Yes, in Data to DecryptemptyYes

Output Parameters Reference​

TokenDescription
[<Store in Token>]One token for each row in Fields, holding the decrypted text. An empty input gives an empty string.

When decryption fails​

SituationWhat happens
Key or IV is emptyNothing. No tokens are set.
Key, IV or encrypted value isn't valid base64The action fails with a format error.
Wrong key, or the value was changedUsually the action fails with Failed to decrypt data. Make sure the key used for decryption is the same as the one the content was encrypted with.
Right key, wrong IVNo error. The first 16 bytes (about the first 16 characters) come out garbled and the rest is correct.

To handle a failure yourself, put the action inside Execute Actions and use its On Error actions.

Considerations​

  • A wrong key doesn't always fail. Rarely, a wrong key or a changed value decrypts without an error and returns garbage. AES here has no tamper check, so the action can't tell. Validate the result if it matters, for example check its format.
  • Don't show decryption errors to users. Returning different errors for bad input can help an attacker work out encrypted values. Use a general message in the On Error actions.
  • Protect the key. Load the key and IV from tokens instead of typing them into the action, and don't log them. Only decrypt when you need the plain value, and don't save the decrypted token back to the database.
  • The weaknesses of AES Encrypt apply. The IV is fixed and there's no tamper check. See AES Encrypt.

Examples​

tip

To understand how to use the below examples, please see Running Examples.

1. Decrypt a national ID​

This action decrypts [NationalIdEncrypted] and saves the text in [NationalId]. The key and IV come from the [AesKey] and [AesIV] tokens.

{
"Title": "AES Decrypt",
"ActionType": "DecryptData",
"Description": "Decrypt the national ID",
"Condition": "[NationalIdEncrypted] != \"\"",
"Parameters": {
"Key": "[AesKey]",
"IV": "[AesIV]",
"Fields": {
"[NationalIdEncrypted]": "NationalId"
}
}
}

Revised 09/27/2026