Developer

Base64 Encoder & Decoder

Base64 is a binary-to-text encoding scheme that represents any byte sequence using 64 printable ASCII characters, defined by RFC 4648. This tool encodes text to Base64 or decodes Base64 back to readable text, instantly and in your browser. UTF-8 safe (emoji and non-Latin text work), with an optional URL-safe alphabet for tokens and query strings. Nothing is uploaded, no sign-up.

0 characters

Output appears here as you type.

Common uses

Data URIs

Embed a small image or font directly in CSS/HTML as data:...;base64,... to save a request.

JWT & tokens

JSON Web Tokens are URL-safe Base64. Decode the header/payload segments to inspect claims (they are not encrypted).

API payloads

Move binary data through JSON or XML fields that only accept text, without corruption.

Basic Auth headers

The Authorization: Basic header is base64("user:pass"). Decode one to see the credentials it carries.

Email attachments

MIME encodes attachments as Base64 so binary files survive text-only mail transport.

Config & secrets files

Kubernetes Secrets and many config formats store values as Base64. Decode to read, encode to set.

Standard vs URL-safe Base64

Both encode the same data; they differ only in three output characters. Decoding here accepts either, and restores missing padding automatically.

  • Standard

    Uses + and /, pads the end with =. The default for email, data URIs, and most APIs.

  • URL-safe

    Replaces + with -, / with _, and drops = padding, so it is safe in URLs, filenames, and JWTs.

How Base64 encoding works, a worked example

Base64 works in groups of 3 input bytes (24 bits), split into four 6-bit chunks. Each 6-bit chunk (a value from 0 to 63) maps to one of 64 characters. Encoding the text Hi! shows the mechanics:

  • H, i, and ! are ASCII bytes 72, 105, 33, or in binary 01001000 01101001 00100001. Regrouped into four 6-bit chunks that becomes 010010 000110 100100 100001, which as decimal is 18, 6, 36, 33. Looked up in the Base64 alphabet (A-Z = 0-25, a-z = 26-51, 0-9 = 52-61, + = 62, / = 63), that gives S G k h, soHi! encodes to SGkh.

  • Why the = padding: Base64 needs input in multiples of 3 bytes to fill four clean 6-bit chunks. When the input is not a multiple of 3, the last group is padded with zero bits and the output gets one = (2 bytes left over) or two == (1 byte left over) so the decoder knows exactly how many trailing bits to discard. A length that is a multiple of 3 needs no padding at all.

Frequently Asked Questions

What is Base64 and what is it used for?▾
Base64 is a way to represent binary data (or text) using only 64 printable ASCII characters (A-Z, a-z, 0-9, + and /). It is used to safely embed data in places that only accept text, for example data URIs for images in CSS/HTML, email attachments (MIME), JSON or XML payloads, and Basic Authentication headers. It is an encoding, not encryption, so it provides no security on its own.
How do I encode text to Base64?▾
Choose Encode, then type or paste your text. The Base64 output updates instantly as you type, no button needed. Text is treated as UTF-8, so emoji and non-Latin characters (e.g. 世界, café) encode correctly. Click Copy to grab the result.
How do I decode a Base64 string?▾
Choose Decode and paste the Base64 string. The decoded text appears immediately. The tool auto-detects URL-safe Base64 (using - and _) and restores missing padding, so it works whether or not the string ends in = signs. If the string is not valid Base64, you get a clear error instead of garbled output.
What is URL-safe Base64?▾
Standard Base64 uses + and / and pads with =, but those characters have special meaning in URLs and filenames. URL-safe Base64 replaces + with -, / with _, and drops the = padding, so the result can be dropped straight into a URL, query string, or JWT. Tick the URL-safe option when encoding; decoding handles both variants automatically.
Is my data sent to a server?▾
No. All encoding and decoding runs entirely in your browser using the built-in btoa/atob functions and the TextEncoder/TextDecoder APIs. Nothing you type is uploaded, logged, or stored. This matters when you are handling tokens, credentials, or private payloads.
Why does my Base64 look longer than the original text?▾
Base64 represents every 3 bytes of input as 4 output characters, so the encoded string is about 33% larger than the original. That overhead is the trade-off for being able to move binary-safe data through text-only channels.
Is Base64 encryption? Is it secure?▾
No. Base64 is reversible by anyone, it only changes the representation, not the meaning. Never use it to protect passwords or secrets. If you need confidentiality, use real encryption; if you need integrity, use a hash (see our Hash Generator).
Why does decoding fail with "invalid character" or "invalid length"?▾
Valid Base64 only contains A-Z, a-z, 0-9, and either +/ (standard) or -_ (URL-safe), plus optional = padding at the end. An "invalid character" error usually means a stray space, newline, or a character from the wrong alphabet got mixed in when the string was copied. An "invalid length" error means the string was truncated, Base64 length is always a multiple of 4 once padding is accounted for.
Can I decode Base64 back into an image or file, not just text?▾
This tool decodes Base64 to readable text (UTF-8), which covers the vast majority of use cases like JWTs, config values, and encoded strings in code. It is not built for reconstructing binary files like images from a data URI, for that, a dedicated Base64-to-image or Base64-to-file converter that writes raw bytes is a better fit.

By Toolember · Updated September 2026