Base64 Encode / Decode

Encode text to Base64 or decode Base64 strings back to plain text instantly. Free, browser-based, no data sent to servers.

  • Runs in your browser
  • Your data never leaves your browser
  • Free · No Sign-Up
Text uses UTF-8. Typing converts after 0.3 seconds; changing Encode or Decode converts the current text immediately. Decoding displays UTF-8 text only. A lone surrogate is rejected with its position.
Standard uses + and / with = padding. URL-safe uses - and _ and removes trailing =. Switching updates the current text or encoded file. A file still being read uses the latest selection.
Exchange the current input and output. The mode stays the same. Swap cancels a pending text conversion and leaves the exchanged values as they are.
Drop any file here, or click to select
Choose or drop any file in Encode mode to encode its raw bytes. Files over 5 MiB show a warning and are still processed. The whole file and Base64 result are held in memory.
Copy the complete displayed output, including the Data URI prefix when enabled. If copying fails, select the output and copy it manually.
Examples, details and FAQ Worked examples, how it compares with other tools, and answers to common questions.

Examples

These outputs come from the tool’s own encode and decode functions.

ModeInputOutput
Encode, StandardHello, 世界SGVsbG8sIOS4lueVjA==
Encode, URL-safeHello, 世界SGVsbG8sIOS4lueVjA
Encode, Standardsubjects?_dc3ViamVjdHM/X2Q=
Encode, URL-safesubjects?_dc3ViamVjdHM_X2Q
Encode, Standarduser:passdXNlcjpwYXNz
Decode, URL-safeeyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6Ikpvc8OpIn0{"sub":"1234567890","name":"José"}

Text is encoded as UTF-8 first, so 世界 takes six bytes and eight Base64 characters. The subjects?_d row shows the only difference between the two alphabets: Standard uses + and / (RFC 4648 §4), URL-safe uses - and _ and drops the = padding (RFC 4648 §5). JWT segments use the URL-safe form without padding (RFC 7515 §2), which is why the last row decodes a JWT payload in URL-safe mode. The user:pass row is the credential part of an HTTP Basic header (RFC 7617 §2); the Basic Auth Header Generator builds the whole header.

What the Decoder Accepts

  • Missing padding. SGVsbG8 decodes to Hello. The browser’s atob() follows the WHATWG forgiving-base64 decode, which does not require =.
  • Line breaks and spaces. MIME bodies wrap Base64 at 76 characters (RFC 2045 §6.8). Tabs, line breaks and spaces are removed before decoding in both Standard and URL-safe mode, so wrapped text works as pasted.
  • Standard input in URL-safe mode. URL-safe mode maps - and _ back to + and /, so a Standard string also decodes there. The reverse fails: c3ViamVjdHM_X2Q in Standard mode gives Position 12: "_" is from the URL-safe alphabet. Select URL-safe to decode this string.

Limits

  • Decode output is UTF-8 text only. Bytes that are not valid UTF-8 give an error. Example: gqCCog== is あい in Shift_JIS (bytes 82 A0 82 A2) and is rejected: Byte 1 of the decoded data (82) is not valid UTF-8. Decode shows UTF-8 text only; binary data and text in GBK, Shift_JIS or EUC-KR cannot be shown here. Use Text to Binary to inspect raw bytes.
  • A = in the middle of the string, or a length that leaves one character after the last group of four, is an error; the status line gives the position of the = or the number of characters.
  • File encoding has no fixed size limit. Above 5 MiB (5,242,880 bytes) the tool shows “Large file — encoding may take a few seconds.” The whole Base64 string is put into the output box, so very large files can make the page slow.
  • Text with a lone UTF-16 surrogate (half of an emoji, left when a string is cut in the middle of one) cannot be encoded as UTF-8; the tool names its position. Switching Standard / URL-safe converts the current output to the other alphabet.
  • Base64 is an encoding, not encryption. Anyone can decode it. For confidential data use AES Encryption.

Common Use Cases

  • API authentication: Basic Auth headers use Base64-encoded credentials.
  • Data URIs: Inline images and fonts in CSS/HTML are Base64-encoded. For images, Image to Base64 detects the type from the file bytes and can output CSS or HTML.
  • JWT tokens: The header and payload sections are Base64url-encoded.
  • Email: MIME attachments are Base64-encoded.

FAQ

What is Base64?

Base64 is an encoding scheme that converts binary data to ASCII text using 64 printable characters. It's commonly used in data URIs, email attachments, and API tokens.

Is my data sent to any server?

No. Encoding and decoding run in your browser with the built-in JavaScript functions btoa and atob, and neither the text nor a chosen file is sent anywhere. The last text you typed is kept in this browser's local storage so it is still there when you come back; files are not kept, and Clear removes the saved text.

Can I encode binary files?

Yes. In Encode mode, drop a file on the drop zone or click it to choose one. Any file type works: the tool reads the raw bytes, outputs Base64, and can add a data:<mime>;base64, prefix. Decode mode shows the result as UTF-8 text only, so Base64 of an image or other binary data gives an error and cannot be saved as a file. To turn an image into a data URI, use Image to Base64 Converter.

Why does decoding fail?

There are three causes: a character outside the Base64 alphabet (for example - or _ from URL-safe Base64 while Standard is selected), a truncated string that leaves one extra character after groups of four, or decoded bytes that are not valid UTF-8, such as binary data or Shift_JIS text. A missing = at the end is not a problem. The status line names the cause and its position: the character position in the input, or the byte number in the decoded data.