Base64 Encode and Decode

Encode text to Base64 or decode it back. The browser's own btoa accepts Latin-1 only and throws on anything outside it, so text is converted to UTF-8 first — which means non-Latin scripts and emoji make the round trip unchanged.

Mode

What you enter never leaves your device. Everything runs in your browser; nothing is sent or stored anywhere.

Base64 is not encryption

It is a notation: every three bytes are split into four six-bit groups, and each group is mapped to one of sixty-four characters — A–Z, a–z, 0–9, + and /. There is no key, so anyone can reverse it, and it must not be used to hide anything. Its job is to carry bytes through channels that only accept text: mail attachments, binary data inside JSON, images embedded as data: URLs, and the user:password pair in HTTP Basic authentication.

`=` padding and the URL-safe variant

Characters come in groups of four, so the end is padded with = until the length is a multiple of four. The URL-safe variant swaps + and / for - and _ and drops that padding. Decoding accepts either form: - and _ are mapped back, the missing = are counted and restored, and only then is the text decoded. That is why a JWT segment with its padding stripped can be pasted as is. Mail-style Base64 wrapped every 76 characters works too — spaces and line breaks are ignored while reading.

How non-Latin text makes the trip

The browser's btoa takes bytes dressed as characters and throws on anything outside Latin-1. Here the text is converted to UTF-8 first: the Korean syllable 가 becomes the three bytes EA B0 80, which come out as the four characters 6rCA. Decoding reads UTF-8 as well, so a value produced in a legacy encoding such as EUC-KR or Shift_JIS decodes to garbled text rather than an error. Binary data like an image decodes to unreadable characters for the same reason, so keep this tool for text.

Input that fails to decode

Whitespace at either end is trimmed; beyond that only the sixty-four alphabet characters plus -, _ and = are allowed. Paste a data:image/png;base64, prefix along with the value and decoding fails at the : and the , — paste only what follows the comma. A value wrapped in quotes fails the same way. On failure you get a note that this does not look like Base64. If it decodes but the bytes were not UTF-8, there is no error, just garbled text.

The length can be predicted

Three bytes become four characters, so the output length is the byte count over three, rounded up, times four. A Korean or Japanese character is exactly three UTF-8 bytes, so text made only of them ends without =: 한글 is the eight characters 7ZWc6riA. The URL-safe form drops the padding, so the same text is at most two characters shorter.

Frequently asked questions

What is the URL-safe variant?

The + and / characters that Base64 produces mean something else inside a URL or a filename. The URL-safe variant replaces them with - and _ and drops the trailing = padding. JWTs use this variant. Decoding accepts either form without being told which.

My decoded text comes out as garbage

If the value came from another tool, that tool may have used an encoding other than UTF-8. Encoding and decoding here are both UTF-8.

I heard URL Base64 is different.

Because + and / mean something else in a URL, the URL-safe variant swaps them for - and _, and often drops the trailing =. Match whichever the other end expects.

Why does Base64 make things bigger?

Three bytes become four characters, so it grows by about a third. Embedding an image as Base64 in HTML saves a request but inflates the document, so it only pays off for small icons.

I pasted a whole `data:` URL and it failed.

Everything up to and including data:image/png;base64, is the URL's header, not Base64. Paste what follows the comma. If that is an image, decoding gives only unreadable characters — this tool turns text back into text. To see the picture, paste the whole URL into the address bar instead.

Does anything I paste get sent to a server?

No. Everything runs inside your browser and nothing is uploaded or stored. That is why you can use it on things you would not normally paste into a web page, like an internal config file or a production query. It also works with your network disconnected.