Skip to content
HNarzędzia
en
Categories

Base64 encode and decode online (UTF-8, URL-safe)

Convert text to Base64 and back with proper UTF-8 handling, so accented letters, non-Latin scripts and emoji survive the round trip. The URL-safe variant used in JWTs and URLs is supported too.

  • Free
  • No sign-up
  • Private
  • Runs locally

Need to convert an image to Base64? Use the Image to Base64 tool.

How to encode or decode Base64

  1. 1.

    Choose the mode

    “Encode to Base64” turns text into Base64; “Decode from Base64” does the opposite.

  2. 2.

    Paste your data

    Type text or paste a Base64 string. The decoder accepts padded and unpadded input, the URL-safe alphabet, line breaks and even a data:…;base64, prefix.

  3. 3.

    Set the options

    When encoding, pick the URL-safe variant or wrap lines at 76 characters (MIME format).

  4. 4.

    Copy the result

    The output updates as you type. Use “Swap” to check the conversion in the other direction.

How Base64 works

Base64 (RFC 4648) represents any binary data with 64 safe characters: A-Z, a-z, 0-9, + and /. Every 3 bytes (24 bits) are split into 4 groups of 6 bits, and each group maps to one character. When the input length is not a multiple of three, the output is padded with = or ==.

Example: “Man” is the bytes 77, 97, 110 = 01001101 01100001 01101110 → groups 19, 22, 5, 46 → TWFu. That is why Base64 output is always about 33% larger than the original: 4 characters for every 3 bytes. The exact length is 4 × ⌈n ÷ 3⌉ characters for n bytes, so 100 bytes become 136 characters.

Unicode, emoji and the btoa() problem

The browser function btoa() only accepts Latin-1 characters, so btoa("€") or btoa("😀") throws an error. This tool first converts text to UTF-8 bytes with TextEncoder and only then encodes those bytes, which is what every server-side language does. Accented letters take 2 bytes in UTF-8 and emoji take 4: “café” (4 letters, 5 bytes) becomes Y2Fmw6k=.

When decoding, the tool checks that the bytes form valid UTF-8. If they do not, you most likely pasted an encoded binary file such as an image or a PDF, and the tool tells you so instead of showing garbage.

Base64 vs Base64URL

Base64Base64URL
Character 62+-
Character 63/_
Padding =yesusually omitted
Used inemail (MIME), data URIs, APIsJWTs, URLs, file names

Base64 is not encryption. Anyone can decode it without a key, so never use it to hide passwords. To check integrity, use a hash such as SHA-256 from the hash generator; to protect data, use real encryption.

Where you meet Base64 and common decoding errors

  • Data URIs - data:image/png;base64,iVBORw0… embeds a file directly in HTML or CSS; convert a picture with Image to Base64.
  • HTTP Basic Auth - Authorization: Basic dXNlcjpwYXNz is simply user:pass encoded.
  • JSON Web Tokens - three Base64URL parts separated by dots; read them comfortably in the JWT decoder.
  • Email attachments (MIME) - Base64 with lines wrapped at 76 characters.

The most common decoding problems are a truncated string (length not divisible by 4 even after padding), spaces or line breaks copied from a document, mixing up Base64 and Base64URL, and trying to read a binary file as text. This decoder normalises whitespace, padding and both alphabets automatically, so only genuinely broken input produces an error. For query strings and form data you want percent-encoding instead - see the URL encoder.

Frequently asked questions

Is Base64 encryption?

+
No. Base64 is just a way to write binary data as text. Decoding needs no key, so it provides no confidentiality at all.

Why is the encoded text longer than the original?

+
Base64 uses 4 characters for every 3 bytes, so the output is about 33% larger, plus padding and any line breaks.

What do the = signs at the end mean?

+
They are padding. One = means the last group had 2 bytes, == means it had 1 byte. The URL-safe variant usually drops the padding.

How do I decode a JWT?

+
A JWT has three parts separated by dots. Paste the first (header) or second (payload) part into the decoder - it is Base64URL without padding, which the tool handles automatically. The signature cannot be verified this way.

Why does decoding say the data is not UTF-8 text?

+
The Base64 string is valid, but the bytes inside are not text - usually an image, a PDF or compressed data. Decode it with a tool that saves the result as a file.

Is my text sent to a server?

+
No. Encoding and decoding happen in your browser, so you can safely paste tokens, credentials or private data.

Updated: