Base64 encoder and decoder

Type text to encode it as Base64, or paste Base64 to decode it. Text is handled as UTF-8, so accents, Hindi and emoji survive the round trip. Switch on URL-safe mode for JWTs and URLs. You can also turn a file into Base64 or a data URI, and save decoded Base64 as a file.

Free, no sign-up Runs in your browser

File to Base64

No file chosen.

How to encode or decode Base64

  1. Choose Encode or Decode. Encode turns text into Base64. Decode turns Base64 back into text.
  2. Paste your input. The result updates as you type. When decoding, the tool checks the input and explains any error, such as a stray character or a wrong length.
  3. Tick URL-safe if the Base64 goes into a URL, a file name or a JSON Web Token (JWT). Decoding accepts both alphabets, with or without padding.
  4. Copy or download the result. If the decoded data is a file rather than text, use Download decoded file. The tool guesses the type (PNG, JPEG, PDF and others) from the first bytes.

Everything runs locally in your browser. Nothing you paste or drop is uploaded, and your input is never saved. That matters, because Base64 strings often hold API keys, tokens and passwords.

How Base64 works

Base64 represents any bytes using 64 safe characters: A–Z, a–z, 0–9, + and /. It takes the input three bytes (24 bits) at a time and splits them into four groups of 6 bits. Each 6-bit group is a number from 0 to 63, which picks one character.

Worked example: "Man" → "TWFu"

StepMan
ASCII code7797110
Bits010011010110000101101110

Join the 24 bits and cut them into four 6-bit groups:

010011 010110 000101 101110
  19     22      5     46
   T      W      F      u

In the alphabet, 0–25 are A–Z, 26–51 are a–z, 52–61 are 0–9, 62 is + and 63 is /. So 19 is T, 22 is W, 5 is F and 46 is u.

Padding

When the input length isn't a multiple of three, the last group is short. Standard Base64 fills it out with =: Ma becomes TWE= and M becomes TQ==. The padding carries no data. URL-safe Base64 usually drops it.

Size overhead

Every 3 bytes become 4 characters, so Base64 is about 33% larger than the original. A 30 KB image becomes about 40 KB of text. A data URI adds a short prefix such as data:image/png;base64,. For that reason, embed only small images, icons and fonts as data URIs.

Standard vs URL-safe Base64

Standard (RFC 4648 §4)URL-safe (RFC 4648 §5)
Character 62+-
Character 63/_
Padding= requiredUsually left out
Used inEmail (MIME), data URIs, PEM keysJWTs, URLs, file names

In a URL, + can be read as a space and / as a path separator, which is why the URL-safe alphabet exists.

Unicode text and UTF-8

Base64 encodes bytes, not letters. Text must first be turned into bytes, and this tool uses UTF-8, the encoding of almost every web page and API. "é" is two bytes in UTF-8, and "₹" is three. The browser's built-in btoa() fails on such characters, which is a common bug. This tool encodes the text to UTF-8 first, so नमस्ते or an emoji decode back exactly.

Base64 is encoding, not encryption

Anyone can decode Base64. There is no key and no secret. It only makes data safe to send through systems built for text. Never use it to hide passwords or personal data. To protect data, use real encryption. To check that a file hasn't changed, use a hash generator. To put text in a URL, use the URL encoder instead.

Frequently asked questions

Is Base64 encryption?
No. Base64 is a reversible encoding with no key, so anyone can decode it in a second. It is meant for moving binary data through text-only channels, not for keeping it secret.
Why does my decoded text look garbled?
The data was probably encoded from a different text encoding, such as Windows-1252, or it is a binary file. This tool decodes as UTF-8 and tells you when the bytes are not valid UTF-8 text. In that case, download the result as a file.
How much bigger does Base64 make a file?
About 33%. Every 3 bytes become 4 characters, plus up to two padding characters. If the text is wrapped onto lines, as in email, the line breaks add a little more.
What is URL-safe Base64?
A variant defined in RFC 4648 that uses - and _ instead of + and /, and usually drops the = padding. JSON Web Tokens use it. This decoder accepts both forms.
Is it safe to paste a token or key here?
Yes. Encoding and decoding run entirely in your browser. Nothing is sent to a server, and your input is not stored. Only settings such as Encode or Decode are remembered on this device.
How do I convert an image to Base64?
Drop the image onto the file box and choose Data URI. You get a string such as data:image/png;base64,iVBOR… that you can use in HTML img src or in CSS url().

Last updated . How we check our tools.