How to encode or decode Base64
- Choose Encode or Decode. Encode turns text into Base64. Decode turns Base64 back into text.
- Paste your input. The result updates as you type. When decoding, the tool checks the input and explains any error, such as a stray character or a wrong length.
- Tick URL-safe if the Base64 goes into a URL, a file name or a JSON Web Token (JWT). Decoding accepts both alphabets, with or without padding.
- Copy or download the result. If the decoded data is a file rather than text, use Download decoded file. The tool guesses the type (PNG, JPEG, PDF and others) from the first bytes.
Everything runs locally in your browser. Nothing you paste or drop is uploaded, and your input is never saved. That matters, because Base64 strings often hold API keys, tokens and passwords.
How Base64 works
Base64 represents any bytes using 64 safe characters: A–Z, a–z, 0–9, + and /. It takes the input three bytes (24 bits) at a time and splits them into four groups of 6 bits. Each 6-bit group is a number from 0 to 63, which picks one character.
Worked example: "Man" → "TWFu"
| Step | M | a | n |
|---|---|---|---|
| ASCII code | 77 | 97 | 110 |
| Bits | 01001101 | 01100001 | 01101110 |
Join the 24 bits and cut them into four 6-bit groups:
010011 010110 000101 101110 19 22 5 46 T W F u
In the alphabet, 0–25 are A–Z, 26–51 are a–z, 52–61 are 0–9, 62 is + and 63 is /. So 19 is T, 22 is W, 5 is F and 46 is u.
Padding
When the input length isn't a multiple of three, the last group is short. Standard Base64 fills it out with =: Ma becomes TWE= and M becomes TQ==. The padding carries no data. URL-safe Base64 usually drops it.
Size overhead
Every 3 bytes become 4 characters, so Base64 is about 33% larger than the original. A 30 KB image becomes about 40 KB of text. A data URI adds a short prefix such as data:image/png;base64,. For that reason, embed only small images, icons and fonts as data URIs.
Standard vs URL-safe Base64
| Standard (RFC 4648 §4) | URL-safe (RFC 4648 §5) | |
|---|---|---|
| Character 62 | + | - |
| Character 63 | / | _ |
| Padding | = required | Usually left out |
| Used in | Email (MIME), data URIs, PEM keys | JWTs, URLs, file names |
In a URL, + can be read as a space and / as a path separator, which is why the URL-safe alphabet exists.
Unicode text and UTF-8
Base64 encodes bytes, not letters. Text must first be turned into bytes, and this tool uses UTF-8, the encoding of almost every web page and API. "é" is two bytes in UTF-8, and "₹" is three. The browser's built-in btoa() fails on such characters, which is a common bug. This tool encodes the text to UTF-8 first, so नमस्ते or an emoji decode back exactly.
Base64 is encoding, not encryption
Anyone can decode Base64. There is no key and no secret. It only makes data safe to send through systems built for text. Never use it to hide passwords or personal data. To protect data, use real encryption. To check that a file hasn't changed, use a hash generator. To put text in a URL, use the URL encoder instead.
Frequently asked questions
Is Base64 encryption?
Why does my decoded text look garbled?
How much bigger does Base64 make a file?
What is URL-safe Base64?
- and _ instead of + and /, and usually drops the = padding. JSON Web Tokens use it. This decoder accepts both forms.Is it safe to paste a token or key here?
How do I convert an image to Base64?
data:image/png;base64,iVBOR… that you can use in HTML img src or in CSS url().Last updated . How we check our tools.