Base64 Encode and Decode

Turn text into Base64 or Base64 back into text. Handles accents and emoji properly, reads URL-safe Base64, and never sends what you paste anywhere.

A to Z, a to z, 0 to 9, + and /, padded with = (RFC 4648).

42 characters, 47 bytes
64 characters

Base64 examples

TextEncoded
Hello

SGVsbG8=

Standard: Five bytes need one = of padding

Hello!

SGVsbG8h

Standard: Six bytes divide evenly, so no padding

café

Y2Fmw6k=

Standard: é is two bytes in UTF-8

user:p@ss

dXNlcjpwQHNz

Standard: The form used by HTTP Basic auth

??>>

Pz8+Pg==

Standard: Uses + and /

??>>

Pz8-Pg

URL-safe: Swaps them for - and _ and drops the =

Encoding guides

How each one works, with worked examples.

Everything happens in your browser. What you type or paste is never uploaded, stored or added to the share link, so it is safe to use with tokens, keys and customer data.

What Base64 is for

Base64 writes any sequence of bytes using only 64 safe characters: A to Z, a to z, 0 to 9, plus + and /. It exists because many systems were built to carry text and will corrupt raw bytes: email bodies, JSON, XML, URLs, HTTP headers and environment variables among them.

It works by taking three bytes (24 bits) at a time and splitting them into four groups of six bits, each of which picks one character from the alphabet. When the input does not divide into threes, the last group is padded with one or two = signs. The result is always about 33% larger than the input.

Base64 is an encoding, not encryption. Anyone can decode it, so it hides nothing. A Base64 string in a config file or an Authorization header is exactly as secret as the plain text would be.

Text, UTF-8 and why other tools mangle accents

Base64 encodes bytes, so text has to be turned into bytes first. This tool uses UTF-8, the encoding of practically every modern system. That is why é becomes two bytes and an emoji four.

JavaScript's built-in btoa function only accepts characters up to code 255 and throws an error on anything else, and tools built directly on it either fail on emoji or silently produce Latin-1 output that decodes to the wrong characters elsewhere. If a decoded string shows é where é should be, it was decoded as Latin-1 instead of UTF-8.

Standard and URL-safe Base64

The + and / of standard Base64 both have meanings inside a URL, and = has one in a query string. URL-safe Base64 (base64url in RFC 4648) swaps + for - and / for _, and usually leaves off the padding. It is what JSON Web Tokens, many API keys and signed URLs use.

When decoding you do not need to say which one you have: both alphabets are accepted, with or without padding, and line breaks are ignored, so Base64 wrapped at 64 or 76 characters (PEM files, MIME email) can be pasted as it is.

Frequently asked questions

Is Base64 secure?
No. Base64 is a way of writing bytes as text, not a way of protecting them. Anyone can decode it instantly without a key, so never treat a Base64 string as hidden.
Why does my Base64 end in = or ==?
Base64 works on groups of three bytes. If the input has one byte left over the output ends in ==, with two left over it ends in =, and with none there is no padding.
Why does decoding say the result is not valid text?
The Base64 decoded correctly but the bytes are not UTF-8 text. It is most likely a file such as an image, a certificate, a key or compressed data, which cannot be shown as text.
How much bigger does Base64 make things?
Four characters are written for every three bytes, so the output is one third larger than the input, plus up to two padding characters.

More bits and bobs