AES-256-GCM encryption with passphrase or key-based auth, portable ciphertext packages, and one-click export.
If empty, a random 256-bit key is generated.
Exactly 32 bytes (base64). Overrides passphrase.