text required default (required)The plaintext to encrypt. Any string; an empty string is allowed (it still yields a valid token).
key required default (required)The password used as the encryption key. Any length is accepted - it is derived into a fixed 32-byte AES-256 key. You must pass the exact same key to decrypt; a wrong key makes decrypt fail and return an empty string.
output_type optional default (none - parameter is ignored)Obsolete and ignored. In older AA this was set to url to request URL-safe output; today the result is ALWAYS URL-safe Base64url, so this parameter has no effect. Leave it out.
{decrypt:{encrypt:Hello world:my-secret-key}:my-secret-key}
{decrypt:{encrypt:42:pass123}:pass123}
[{decrypt:{encrypt::pass123}:pass123}]
[{decrypt:{encrypt:secret message:right-key}:wrong-key}]
{encrypt:Hello world:my-secret-key}
{encrypt:user-42:server-secret}