AES Encrypt
Audience:
Low-code EngineersSkill Prerequisites:
Actions,Tokens
Encrypts one or more values with AES and saves each result in a token. You supply the key and the initialization vector (IV). The same key and IV decrypt the values again with AES Decrypt.
AES is symmetric: one secret key both encrypts and decrypts. The action uses standard AES in CBC mode with PKCS#7 padding. The text is encoded as UTF-8 before it's encrypted, and the result is a base64 string.
Typical Use Cases
- Encrypt a sensitive value, such as a national ID or bank account number, before saving it to the database
- Encrypt a value you'll send to another system that shares the same key and IV
- Encrypt a value you'll put in a URL or hidden field, and decrypt it later with AES Decrypt
Don't use it to
- Store passwords. Encryption can be reversed. Passwords should be hashed, not encrypted.
- Encrypt for someone who must not be able to encrypt too. Everyone with the key can do both. Use RSA Encrypt instead.
- Encrypt connector values. Use Connector Encrypt instead.
- Prove a value wasn't changed. AES here has no tamper check, see
Considerations.
Which to use
| You need to | Use |
|---|---|
| Encrypt and decrypt inside your own app, or with a partner that shares the secret | AES Encrypt and AES Decrypt |
| Let others encrypt data that only you can decrypt | RSA Encrypt with a public key, RSA Decrypt with the private key |
| Encrypt long text | AES Encrypt. RSA only handles short values. |
| Encrypt a value in the format the connector store uses | Connector Encrypt |
Related Actions
| Action Name | Description |
|---|---|
| AES Decrypt | Decrypts values encrypted by this action. |
| RSA Encrypt | Encrypts short values with a public key. |
| RSA Decrypt | Decrypts RSA-encrypted values with the private key. |
| Connector Encrypt | Encrypts values with the key the connector store uses. |
| Get Connector | Reads connector properties into tokens, for example to load a key. |
Input Parameter Reference
| Parameter | Description | Supports Tokens | Default | Required |
|---|---|---|---|---|
| AES Key | The secret key as a base64 string. It must decode to 16, 24 or 32 bytes, which gives AES-128, AES-192 or AES-256. It isn't a password: text such as MySecret won't work. Use the key generator linked in the parameter's help text to create one. | Yes | empty string | Yes |
| IV Vector | The initialization vector as a base64 string. It must decode to exactly 16 bytes. The key generator creates one together with the key. | Yes | empty string | Yes |
| Fields | A list of values to encrypt. In Data to Encrypt, enter the value, usually a token such as [NationalId]. In Store in Token, enter the name of the token that gets the encrypted result, such as NationalIdEncrypted. Square brackets around the name are removed. | Yes, in Data to Encrypt | empty | Yes |
Output Parameters Reference
| Token | Description |
|---|---|
[<Store in Token>] | One token for each row in Fields, holding the encrypted value as a base64 string. An empty input gives an empty string. |
Generating a key and IV
The AES Key help text links to a key generator page. Where it asks for a key size, pick 256 bit and click Generate. The page shows a random key and IV, both as base64. Copy them somewhere safe. If you lose the key, the encrypted data can't be recovered.
Working with other tools
The output is plain AES-CBC with PKCS#7 padding. Another tool can decrypt it if it uses:
- the same key and IV, decoded from base64 to bytes (tools often want them in hex)
- CBC mode and PKCS#7 padding (sometimes called PKCS#5)
- UTF-8 for the text
The IV isn't added to the output, so the other side needs the IV too.
Considerations
- The IV is fixed. The same IV is used for every value. So the same text always gives the same encrypted result, and values that start the same way give results that start the same way. Someone who sees the data can tell which records have equal values. Good practice is a new random IV for each value, which this action doesn't do.
- There's no tamper check. The result isn't signed. Someone can change the encrypted value, and decrypting may produce altered text or an error instead of a clear "tampered" warning. Don't rely on this action to prove a value came from you.
- Errors end up in the token. If the key or IV is invalid, for example not base64 or the wrong length, the action doesn't fail. The error message is saved in the output token instead of an encrypted value. Check the result before you save it.
- Empty key or IV does nothing. If either one is empty, for example because a token didn't resolve, no tokens are set at all.
- Protect the key. Anyone who has the key and IV can decrypt the data. Don't type the key directly into the action if you can avoid it. Load it from a token instead, and don't log it. Keep the key out of the database that holds the encrypted data.
- Keep the key forever. If you change the key, old values can't be decrypted with the new one. Decrypt and re-encrypt them first.
Examples
To understand how to use the below examples, please see Running Examples.
1. Encrypt a national ID before saving it
This action encrypts the NationalId field and saves the result in [NationalIdEncrypted]. The key and IV come from the [AesKey] and [AesIV] tokens.
{
"Title": "AES Encrypt",
"ActionType": "AesEncrypt",
"Description": "Encrypt the national ID",
"Parameters": {
"Key": "[AesKey]",
"IV": "[AesIV]",
"Fields": {
"[NationalId]": "NationalIdEncrypted"
}
}
}
2. Encrypt several values at once
This action encrypts a bank account number and a routing number in one step.
{
"Title": "AES Encrypt",
"ActionType": "AesEncrypt",
"Description": "Encrypt bank details",
"Condition": "[AccountNumber] != \"\"",
"Parameters": {
"Key": "[AesKey]",
"IV": "[AesIV]",
"Fields": {
"[AccountNumber]": "AccountNumberEncrypted",
"[RoutingNumber]": "RoutingNumberEncrypted"
}
}
}
Revised 09/27/2026