Skip to content
Aback Tools Logo

Fernet Token Encoder/Decoder

Encrypt messages into Fernet tokens (AES-128-CBC + HMAC-SHA256) or decode and verify Fernet tokens with timestamp and HMAC validation. Compatible with Python's cryptography library. All processing is local and private in your browser.

Fernet Token Encoder/Decoder
Encrypt messages into Fernet token format (AES-128-CBC + HMAC-SHA256) compatible with Python's cryptography library. Decode and verify Fernet tokens with timestamp and HMAC validation. All processing is local in your browser.

The key is derived from your password using PBKDF2 + HKDF (480,000 iterations)

Enter a password and message, then click Encrypt to Fernet Token

Why Use Our Fernet Token Encoder/Decoder?

Python cryptography Library Compatible

Fernet tokens generated by our encoder can be decrypted by Python's cryptography.fernet library, and vice versa. Full compatibility with the standard Fernet specification (AES-128-CBC + HMAC-SHA256).

HMAC Signature Verification

Every Fernet token includes an HMAC-SHA256 signature that is verified during decryption. If the token has been tampered with or the wrong password is used, the HMAC check fails immediately.

Timestamp Validation & Token Age

Each Fernet token contains an embedded Unix timestamp showing exactly when it was created. On decryption, the Fernet encoder shows the token age and creation time for auditing and expiry checking.

Secure PBKDF2 Key Derivation

Your password is converted into a Fernet-compatible 32-byte key using PBKDF2 with 480,000 iterations and HKDF expansion. Combined key+token output format makes sharing easy - just paste the whole string.

Common Use Cases for Fernet Token Encoder/Decoder

Secure Message Exchange

Use the Fernet token encoder to encrypt messages before sending them over email, chat, or social media. The recipient can decrypt the Fernet token using the same password. No third-party service required.

Python Developer Integration

Python developers can use this online Fernet encoder to quickly generate tokens for testing or debugging. The output is fully compatible with Python's cryptography.fernet module - no need to write test scripts.

API Token Generation

Generate Fernet tokens for API authentication or session management. The embedded timestamp allows servers to verify token freshness, while the HMAC ensures tokens haven't been tampered with.

Configuration Secret Storage

Encrypt sensitive configuration values - API keys, database passwords, or service credentials - into Fernet tokens. Store the tokens in config files and decrypt them at runtime with the master password.

Cross-Platform Data Portability

Fernet tokens are platform-independent. Encrypt data in your browser with our Fernet encoder, then decrypt it in Python, Go, Rust, or any language with a Fernet-compatible library.

Cookie & Session Encryption

Encrypt web session data or cookies into Fernet tokens. The HMAC signature prevents tampering, while the timestamp allows session expiry. All processing is browser-local for testing and prototyping.

Understanding Fernet Tokens

What is a Fernet Token?

A Fernet token is a symmetric encryption format defined by the Python cryptography library. It combines AES-128-CBC for encryption withHMAC-SHA256 for authentication. Each Fernet token contains a version byte, a Unix timestamp, a random initialization vector (IV), the ciphertext, and an HMAC signature - all packed into a Base64-encoded string. The token format ensures both confidentiality and integrity: the ciphertext cannot be read without the key, and the HMAC prevents undetected tampering. This dual protection makes Fernet tokens suitable for secure message exchange, session management, and configuration encryption.

How Our Fernet Token Encoder/Decoder Works

  1. Key Derivation: Your password is converted into a 32-byte Fernet key using PBKDF2 with 480,000 iterations of SHA-256, followed by HKDF expansion. The first 16 bytes become the HMAC signing key and the last 16 bytes become the AES encryption key.
  2. Encryption (Encoding): A random 16-byte IV is generated. The plaintext is padded using PKCS7, encrypted with AES-128-CBC, and assembled into the token format: version byte (0x80) + 8-byte timestamp + IV + ciphertext + HMAC. The entire binary token is Base64-encoded.
  3. Decryption (Decoding): The token is Base64-decoded, parsed into its components, the HMAC is verified against the signing key, and if valid, the ciphertext is decrypted with AES-128-CBC and unpadded.

Fernet Token Structure

  • Version (1 byte): Always 0x80 (128), identifying this as a version 2 Fernet token. Future versions may use different values.
  • Timestamp (8 bytes): Big-endian Unix timestamp indicating when the token was created. Useful for expiry checks and auditing.
  • IV (16 bytes): Random initialization vector for AES-128-CBC. A different IV is generated for every encryption, ensuring identical plaintexts produce different tokens.
  • Ciphertext (variable): The PKCS7-padded plaintext encrypted with AES-128-CBC using the 16-byte encryption key derived from your password.
  • HMAC (32 bytes): SHA-256 HMAC over the version, timestamp, IV, and ciphertext, computed using the 16-byte signing key. This prevents undetected tampering.

Privacy, Security & Usage Notes

The Fernet token encoder/decoder processes all data entirely in your browser using the Web Crypto API. No data is ever uploaded to any server, stored in any database, or shared with any third party. The cryptographic operations - PBKDF2 key derivation, AES-128-CBC encryption/decryption, and HMAC-SHA256 signing/verification - all use the browser's native cryptographic primitives for maximum security. Keep your password safe: there is no password recovery mechanism. The combined key+token output format allows you to share both the key material and the token in a single string.

Frequently Asked Questions About Fernet Token Encoder/Decoder

A Fernet token is a symmetric encryption format defined by Python's cryptography library that combines AES-128-CBC encryption with HMAC-SHA256 authentication. Each token contains a version byte, a Unix timestamp, a random IV, the ciphertext, and an HMAC signature - all packed into a Base64-encoded string that can be safely transmitted or stored.

Yes. Our Fernet token encoder/decoder is fully compatible with Python's cryptography.fernet module. Tokens generated in the browser can be decrypted in Python, and tokens generated by Python's Fernet module can be decrypted here, as long as the same key/password is used. However, note that our tool uses PBKDF2 + HKDF for password-to-key derivation, while Python's Fernet typically uses a raw 32-byte key.

Your password is converted into a 32-byte Fernet key using PBKDF2 with 480,000 iterations of SHA-256, followed by HKDF expansion. The first 16 bytes become the HMAC signing key and the last 16 bytes become the AES encryption key. For convenience, our combined output format prepends the PBKDF2 salt to the key, making the output self-contained for decryption.

The combined format is a convenience feature that prepends the salt-encoded key material to the Fernet token, separated by a dot. You can paste the entire string to decrypt later - the decoder will extract the salt, regenerate the key from your password, and decrypt the token. Alternatively, you can split at the dot and use the second part as a standalone Fernet token.

Yes, completely. All cryptographic operations - PBKDF2 key derivation, AES-128-CBC encryption/decryption, and HMAC-SHA256 signing/verification - use the Web Crypto API and run entirely in your browser. Your password and plaintext never leave your device. No data is uploaded, stored, or shared with any server.

The HMAC-SHA256 signature will fail verification, and the decoder will report an error. The HMAC is computed over the version byte, timestamp, IV, and ciphertext, so any modification to any part of the token will cause the HMAC check to fail. This prevents undetected tampering and ensures the integrity of your encrypted data.

No. A password is required for both encryption and decryption. The Fernet specification requires a 32-byte key, and our tool derives this key from your password using PBKDF2. The password is the only way to encrypt or decrypt tokens - there is no password recovery mechanism, so keep your password safe.

Fernet tokens have a fixed overhead of 57 bytes (version 1 + timestamp 8 + IV 16 + HMAC 32) before the ciphertext. Your plaintext is padded to the nearest 16-byte boundary and encrypted. A 10-byte message produces approximately 92 bytes of Base64-encoded token. There is no practical size limit since all processing is local.

Yes, 100% free. There is no signup, no premium tier, and no usage cap. The tool runs entirely in your browser using the Web Crypto API and will always be free to use on Aback Tools.