LocalDevTools

Base64 Encode / Decode

Convert text to Base64 and back with proper UTF-8, so emoji and accented characters survive the round trip. Supports URL-safe Base64URL and files.

Runs entirely in your browser. Your input is never uploaded or stored on a server.

How to encode or decode Base64

  1. To encode, type or paste text and click Encode. Text is converted to UTF-8 bytes first, which is what almost every API and language expects.
  2. To decode, paste a Base64 string and click Decode. Spaces and line breaks are ignored, missing = padding is added automatically, and both standard and URL-safe alphabets are accepted.
  3. Tick URL-safe when the result goes into a URL, a filename or a JWT. It replaces + with - and / with _.
  4. To embed an image or font in CSS or HTML, choose a file. The output is a ready-to-use data: URI.

Examples

Hello, world!     →  SGVsbG8sIHdvcmxkIQ==
café ☕            →  Y2Fmw6kg4piV
user:pass         →  dXNlcjpwYXNz   (HTTP Basic auth header value)

The last example is how HTTP Basic authentication works: the header is Authorization: Basic dXNlcjpwYXNz. That is also why Basic auth must only be used over HTTPS, since anyone can decode it.

What Base64 is (and is not)

Base64 represents binary data using 64 printable characters (A–Z, a–z, 0–9, + and /). Every 3 bytes become 4 characters, so encoded data is about 33% larger. It exists so that binary data such as images, keys and attachments can travel through systems that only handle text, like JSON, email (MIME) and URLs.

Base64 is not encryption. It has no key, and anyone can reverse it instantly. If you find a password or API key "protected" by Base64 in a config file, treat it as plain text.

Why other decoders show garbled characters

The browser's built-in btoa() and atob() only work with Latin-1 characters. Encoding "café" with btoa throws an error, and decoding UTF-8 Base64 with atob produces text like café. This tool uses TextEncoder and TextDecoder to handle UTF-8 correctly. In your own JavaScript you can do the same:

// encode
const b64 = btoa(String.fromCharCode(...new TextEncoder().encode(text)));
// decode
const text = new TextDecoder().decode(Uint8Array.from(atob(b64), c => c.charCodeAt(0)));

Frequently asked questions

What is the difference between Base64 and Base64URL?

Base64URL (RFC 4648 §5) swaps + for - and / for _, and usually drops the = padding, so the result is safe in URLs and filenames. JWTs use Base64URL.

Why does my Base64 string end with = or ==?

Padding. Base64 encodes 3 bytes into 4 characters; when the input length is not a multiple of 3, one or two = characters fill the last group. Many decoders, including this one, accept input without padding.

Can I decode Base64 that contains binary data, like an image?

Yes. If the decoded bytes are not valid UTF-8 text, the tool tells you and shows a hex preview instead of garbled characters. For images, a data URI is easiest to view.

Is Base64 safe for storing passwords?

No. Base64 is reversible by anyone. Passwords should be hashed with a slow algorithm such as Argon2, bcrypt or scrypt on the server.

Are my files uploaded when I encode them?

No. The file is read by your browser with the FileReader API and encoded locally.

Related tools

Last updated: