DeveloperUtilityEducation

Base64 Encoder / Decoder

Encode text to Base64 and decode Base64 to text. Supports UTF-8 and URL-safe Base64. Free, client-side, no data sent to server.

Mode

What is Base64?

Base64 is a way to represent binary data using only 64 printable ASCII characters: letters A–Z, a–z, digits 0–9, and two symbols (usually + and /). A 65th character, =, is used as padding so the length is a multiple of 4.

Because Base64 uses only characters that are safe in almost every system (no control characters or high bytes), it is widely used to embed binary data inside text-based formats—for example in data URLs, email (MIME), JSON, XML, or URLs and cookies when binary or special characters must be avoided.

Why use Base64?

Many protocols and formats were designed for 7-bit or ASCII text. Sending raw binary (images, PDFs, or arbitrary bytes) can break them or be altered by legacy systems. Encoding the binary as Base64 turns it into a safe string that can be stored or transmitted wherever plain text is allowed. The tradeoff is size: Base64 output is typically about 33% larger than the original binary because every 3 bytes become 4 characters.

How Base64 encoding works

The input is treated as a sequence of 8-bit bytes. These bytes are grouped into blocks of 3 (24 bits). Each 24-bit block is split into four 6-bit values; each 6-bit value (0–63) is mapped to one of the 64 characters in the Base64 alphabet. If the input length is not a multiple of 3, padding bytes (zeros) are added and the last one or two characters are replaced with = so the decoder knows how many bits were real data.

When the input is text, it must first be converted to bytes using a character encoding. This tool uses UTF-8, so any Unicode character (including emoji and non-Latin scripts) is correctly encoded to bytes, then to Base64. Decoding reverses the process: Base64 → bytes → UTF-8 text.

URL-safe Base64

Standard Base64 uses + and /, which have special meaning in URLs (e.g. + as space in query strings). URL-safe Base64 (RFC 4648) replaces + with - and / with _, and often omits padding. Use the URL-safe option when the result will go in a URL or cookie.

Common uses

  • Data URLs — Embed small images or fonts as data:image/png;base64,... in HTML or CSS.
  • APIs and JSON — Send binary or sensitive strings (e.g. tokens) as Base64 in JSON payloads.
  • Email (MIME) — Attachments and non-ASCII content are often encoded in Base64.
  • Basic auth — HTTP Basic Authentication sends username:password as Base64 in the Authorization header (encoding only; it is not encryption).
  • Hashing and signatures — Many tools output hashes or signatures in Base64 (e.g. SHA-256, JWT).

Security note

Base64 is encoding, not encryption. Anyone can decode it without a key. Do not use it to hide secrets. For confidential data, use proper encryption (e.g. AES) and key management. This tool runs entirely in your browser; nothing is sent to a server.