About this base64 encoder and decoder
Base64 turns binary data into plain text made of 64 safe characters so that it can travel through systems built for text, such as email, JSON and URLs. This tool encodes text to Base64 and decodes Base64 back to text, with full support for Unicode characters such as accents, non-Latin scripts and emoji.
Everything happens in your browser. The text you paste is not sent to any server.
How to use it
- Type or paste your text (to encode) or your Base64 string (to decode) into the input box.
- Press “Encode to Base64” or “Decode from Base64”.
- Tick “URL-safe output” if the result will be used in a URL, filename or JWT-style token.
- Copy the result, or use “Use result as input” to chain another operation.
What Base64 is and how it works
Base64 reads input three bytes (24 bits) at a time and splits them into four 6-bit groups. Each 6-bit value maps to one of 64 characters: A–Z, a–z, 0–9, plus and slash. If the input length is not a multiple of three, = padding characters are added at the end. Because every three bytes become four characters, Base64 output is roughly one third larger than the original.
The standard is defined in RFC 4648. A variant called Base64URL replaces + with - and / with _ and usually drops the padding so that the string can be used safely inside URLs and filenames. JSON Web Tokens use this URL-safe form.
Where you will meet Base64
Base64 is used for email attachments (MIME), for data URIs that embed small images directly in HTML or CSS, for HTTP Basic authentication headers, for storing binary values in JSON or XML, and in the segments of a JWT. It is also a common way to carry certificates and keys in PEM files.
It is not encryption. Anyone can decode Base64 instantly, so it provides no secrecy. Never rely on it to hide passwords or personal data; use proper encryption and secure transport for that.
Unicode, emoji and common errors
The browser’s built-in btoa function only accepts characters up to code point 255, so a naive encoder fails on text like “héllo 世界 😀”. This tool first converts your text to UTF-8 bytes, then encodes those bytes, so any Unicode text round-trips correctly. When decoding, it reads the bytes back as UTF-8.
If decoding fails, the usual causes are stray characters (the string must use only A–Z, a–z, 0–9, +, /, = or - and _ in the URL-safe form), a truncated string, or Base64 that represents binary data such as an image rather than text. In the last case the bytes are not valid text, and the tool will say so instead of showing garbage.
Frequently asked questions
Is Base64 encryption?
No. It is an encoding that anyone can reverse, so it offers no security.
Why does Base64 end with = signs?
They are padding that makes the length a multiple of four. URL-safe Base64 often leaves the padding out; the decoder here accepts both forms.
What is URL-safe Base64?
A variant that uses - and _ instead of + and / so the string can appear in URLs and filenames without percent-encoding. JWTs use this form.
Can I decode an image or file?
This tool is for text. If the decoded bytes are not valid UTF-8 text, it tells you so rather than showing unreadable characters.
Why is the encoded text longer than the original?
Every three bytes become four characters, so the output is about 33% larger, plus padding.
Is my text sent to a server?
No. Encoding and decoding run locally in your browser.
Related tools
- URL Encoder & DecoderPercent-encode or decode URLs and query strings, and break a URL into its parts.
- JWT DecoderDecode a JSON Web Token locally to read its header, payload and expiry without sending it anywhere.
- JSON to CSV ConverterConvert JSON arrays and objects to clean, correctly escaped CSV for Excel or Google Sheets.
- Secure Password GeneratorCreate strong random passwords using your browser’s cryptographic random number generator.