Base64 Encoder / Decoder
Encode and decode Base64 in your browser: UTF-8 text, emoji, Basic auth headers and JWT segments. Nothing you paste is uploaded or logged.
Encode text to Base64 or decode Base64 back to text, with full UTF-8 support so accented characters, CJK text and emoji survive the round trip. Conversion is instant as you type, and the byte counter shows exactly how much the encoding costs you.
// Base64 Encoder / Decoder: Features
When you reach for this
A log line contains a long run of letters ending in one or two equals signs and you want to know what is inside it. An API needs an Authorization header built from a username and password. A colleague pasted a JWT and you want to read the payload without a library to hand. A config file stores a value as Base64 and you need to check it matches what you expect. Each of these is a few seconds of work once the conversion is in front of you, and a surprising amount of guesswork without it.
How Base64 actually works
Base64 takes the input three bytes at a time, splits those 24 bits into four groups of six, and maps each group to one character from a 64-character alphabet: A to Z, a to z, 0 to 9, plus and slash. Four output characters for every three input bytes is where the well-known overhead comes from, so encoded data is about one third larger than what went in. When the input length is not a multiple of three, the last group is padded with one or two equals signs to keep the output a multiple of four.
UTF-8 is handled correctly
Base64 encodes bytes, not characters, so the result depends entirely on which encoding turned your text into bytes first. This tool always uses UTF-8, which is what every modern system expects. That means accented Latin characters, Greek, Cyrillic, Chinese, Japanese, Korean and emoji all encode and decode without loss. If you are interoperating with an old system that encoded its text as Shift_JIS or Latin-1 before encoding to Base64, the bytes will not match and the decoded text will look like mojibake; that is an encoding mismatch rather than a Base64 problem.
Standard and URL-safe alphabets
The standard alphabet defined in RFC 4648 section 4 uses plus and slash, both of which cause trouble inside a URL or a filename. The URL-safe variant in section 5 substitutes hyphen for plus and underscore for slash, and usually drops the padding. JWT, OAuth, PKCE and AWS signatures all use the URL-safe form. This tool produces and reads the standard alphabet; to move between the two, substitute the two characters and add or remove padding so the length is a multiple of four.
Safe to decode a production token
Encoding and decoding run as JavaScript in your browser, using the built-in btoa and atob functions. The text you paste is never transmitted, stored or logged, which is what makes it reasonable to decode a production Bearer token or build an Authorization header from real credentials here. Closing the tab is enough to discard everything. To inspect a token's claims in a more readable form, the JWT Decoder breaks the three segments out for you.
// Base64 Encoder / Decoder: FAQ
What is Base64 encoding?
- Base64 is a way of representing arbitrary binary data using only 64 printable ASCII characters, standardised in RFC 4648. It exists because many protocols and formats can carry text safely but mangle raw bytes: email attachments, JSON string fields, URL parameters, HTTP headers and Data URIs all rely on it. The transformation is completely reversible, so decoding returns the original bytes exactly.
Is Base64 a form of encryption?
- No, and treating it as one is a genuine security mistake. Base64 uses no key and anyone can reverse it with a single line in any language, including this page. A password stored as Base64 is stored in plain text as far as an attacker is concerned. If you need secrecy, encrypt with something like AES; if you need to store a password, use a slow one-way hash such as bcrypt or Argon2.
Does it handle non-English text and emoji?
- Yes. Text is converted to bytes as UTF-8 before encoding, so accented characters, Greek, Cyrillic, Chinese, Japanese, Korean and emoji all work. Note that multi-byte characters cost more: a character that takes three bytes in UTF-8 becomes four Base64 characters, so a line of CJK text grows considerably more than the same number of ASCII letters.
How much larger does Base64 make my data?
- About one third larger, because every three bytes become four characters. A precise figure is four times the input length rounded up to a multiple of four, so a 1 MB file becomes roughly 1.37 MB. The byte counter under the output shows the real before-and-after size, which is worth checking before you inline a large image as a Data URI.
What is URL-safe Base64, and does this tool produce it?
- URL-safe Base64, from RFC 4648 section 5, replaces plus with hyphen and slash with underscore so the result can sit in a URL or filename unescaped, and it commonly omits the trailing padding. JWT, OAuth and PKCE all use it. This tool works with the standard alphabet. Converting is mechanical: swap those two characters in either direction, and pad the string with equals signs until its length is a multiple of four before decoding.
Why do some Base64 strings end in one or two equals signs?
- That is padding. Base64 output comes in groups of four characters representing three input bytes, so when the input length leaves a remainder the final group is short. One leftover byte produces two equals signs, two leftover bytes produce one, and an exact multiple of three produces none. Padding carries no data; it only tells a strict decoder where the input ended.
How do I build an HTTP Basic auth header?
- The header is Authorization: Basic followed by the Base64 encoding of the username, a colon, and the password. Encode the string admin:secret here and you get YWRtaW46c2VjcmV0, which gives Authorization: Basic YWRtaW46c2VjcmV0. Remember that this is encoding, not protection: anyone who sees the header can read the password, so Basic auth is only acceptable over HTTPS.
Why does my Base64 fail to decode?
- Almost always because the string is not quite what the decoder expects. The usual culprits are a trailing space or newline picked up when copying, a plus sign that was turned into a space by URL decoding somewhere upstream, missing or excess padding, and a URL-safe string with hyphens and underscores being fed to a standard decoder. Trim the whitespace, restore any plus signs, and make the alphabet consistent before trying again.
Can I encode a file or produce a Data URI?
- This tool works with text. For files, the Image to Base64 converter accepts a dropped image and emits a complete data: URI with the right media type, ready to paste into HTML, CSS or Markdown. That is the form you want when a content security policy blocks external resources, or when an HTML email needs its images inline.
Is the string I encode sent to a server?
- No. Everything runs as JavaScript in your browser, and the text you paste is never transmitted, stored or logged. API keys, OAuth tokens, internal credentials and personal data can all be converted here without leaving your machine, and nothing survives closing the tab.
// How to Use Base64 Encoder / Decoder
-
Paste the string to encode
Put whatever you want to convert into the input box: plain text, a username and password separated by a colon, a JWT segment, or an existing Base64 string. Text in any language is accepted and is treated as UTF-8.
-
Choose encode or decode
Use the ENCODE button to turn text into Base64 and DECODE to go the other way. The SWAP button moves the current output into the input and flips the mode, which is handy for checking that a value round-trips exactly.
-
Copy the Base64
The output updates as you type. Copy it with one click, and check the byte counter underneath if the size matters, for example before inlining a value into a header or a Data URI.
Category Encoding