What is Base64?

Base64 is an encoding scheme that maps arbitrary binary bytes to a 64-character ASCII alphabet (A-Z, a-z, 0-9, +, /, plus = for padding). It exists because many transport channels, email headers, URLs, JSON strings, XML attributes, were designed for printable text and choke on raw bytes like 0x00 or 0xFF. Base64 is the universal "wrap any bytes in a safe string" envelope.

Base64 is encoding, not encryption. Anyone holding the string can decode it back to the original bytes without a key. Use it to transport data, never to hide it.

The output is always about 33 % larger than the input (3 input bytes → 4 output chars). That overhead is the cost of restricting yourself to a printable alphabet.

How to use this tool

The toolbar has three modes, pick the one that matches what you're doing:

  • Encode, type or paste plain text, get standard Base64 back. UTF-8 input works (emoji, accented characters, Asian scripts).
  • Decode, paste a Base64 string, get the original text back. The decoder strips whitespace and accepts both standard and URL-safe variants automatically.
  • URL-safe, same as Encode but produces URL-safe Base64: + becomes -, / becomes _, padding = is dropped.

Hit Sample to load a known-good string for the active mode, then hit ↕ Swap to flip input and output (handy when you want to round-trip-verify a value). Output updates on every keystroke after a short debounce.

Standard vs URL-safe Base64

Standard Base64 (RFC 4648 §4) uses + and / in its alphabet, which collide with reserved characters in URLs and filenames. URL-safe Base64 (RFC 4648 §5) substitutes - for + and _ for /, then drops the trailing = padding because URLs hate it too.

You'll see URL-safe Base64 in:

  • JWTs, header, payload, and signature segments are all URL-safe Base64
  • OAuth 2.0 PKCE, the code_challenge is a URL-safe Base64 SHA-256 of the verifier
  • Web Push, VAPID keys and endpoint payloads
  • data: URLs with binary content embedded in HTML/CSS

Standard Base64 is what you get from btoa() in JavaScript, base64 on the command line, and most language standard libraries by default.

UTF-8 and the `btoa` gotcha

JavaScript's built-in btoa() only accepts strings where every character has a code point ≤ 255. Pass it "héllo" and it throws InvalidCharacterError. The fix is to encode the string to UTF-8 bytes first, then Base64 those bytes, which is exactly what this tool does internally. Your input is treated as UTF-8 throughout, so emoji, RTL scripts, and CJK characters round-trip cleanly.

If you're decoding a string produced by a non-UTF-8 system (some legacy Windows-1252 emails), the bytes will decode but the resulting characters may be mojibake. That's a charset problem, not a Base64 problem.

Common gotchas

  • Whitespace inside the string, newlines and spaces are not part of the alphabet but are commonly inserted for line-wrapping (PEM keys, MIME bodies). The decoder strips them before decoding. Most tools should.
  • Missing or wrong padding, standard Base64 pads to a multiple of 4 with =. If you decode SGVsbG8 (no padding) some libraries reject it. The decoder here re-adds padding when missing.
  • Mixing standard and URL-safe in one string, the decoder handles either, but if a string contains both + and - something has gone wrong upstream.
  • It's not a checksum, Base64-encoding a value doesn't detect corruption. Pair it with a hash if integrity matters.
  • Don't Base64 large files in the browser tab, for files over a few megabytes, use a streaming command-line tool. This page lives in your tab's memory.

Privacy

Encoding and decoding both run entirely in your browser using the native btoa / atob and TextEncoder / TextDecoder APIs. Nothing is uploaded to any server. Recent inputs are saved only to your browser's local storage and can be cleared from the "Recent" card.

Frequently asked

Is Base64 a form of encryption?

No. Base64 is an encoding — a deterministic mapping from bytes to a printable alphabet. Anyone who has the string can decode it back to the original bytes without any key. Use Base64 to safely transport binary data through text channels, not to hide secrets. If you need confidentiality, encrypt the data first, then Base64 the ciphertext.

Why does my encoded output have '=' signs at the end?

That's padding. Standard Base64 produces output in multiples of 4 characters, so when the input length isn't a multiple of 3 bytes, the encoder appends '=' (one or two) to fill the last group. URL-safe Base64 typically drops padding because '=' is a reserved character in URLs.

Why does encoding a 100-byte file produce a 136-byte string?

Base64 maps every 3 input bytes to 4 output characters, so the output is always about 33% larger than the input (plus padding). For 100 bytes: ceil(100 / 3) × 4 = 136 characters. This is unavoidable overhead — the cost of restricting yourself to a 64-character alphabet.

What's the difference between standard and URL-safe Base64?

Standard Base64 (RFC 4648 §4) uses '+' and '/' in its alphabet. URL-safe Base64 (RFC 4648 §5) replaces '+' with '-' and '/' with '_', and usually drops the '=' padding. URL-safe is what you'll see in JWTs, OAuth PKCE, and anywhere the value is dropped into a URL or filename.

Does this tool support Unicode and emoji?

Yes. Input is treated as UTF-8 throughout — your text is encoded to UTF-8 bytes first, then those bytes are Base64-encoded. Emoji, accented characters, and non-Latin scripts all round-trip correctly. The tool fixes the classic JavaScript btoa() limitation that only accepts code points ≤ 255.

Why does my decode fail with 'Invalid Base64'?

Common causes: the string contains non-alphabet characters (curly quotes, smart dashes from a word processor), padding is wrong, or you're trying to decode something that was never Base64 in the first place. The decoder strips whitespace and accepts both standard and URL-safe alphabets, but it can't fix corruption.

Can I Base64 a file with this tool?

This tool is text-in / text-out. To Base64 a file, drop the file's contents into the input — works for small text files. For binary files use a command-line tool: 'base64 file' on macOS/Linux, '[Convert]::ToBase64String((Get-Content file -Raw -Encoding Byte))' in PowerShell.

Is anything I encode or decode sent to a server?

No. Encoding and decoding run entirely in your browser via native APIs (btoa, atob, TextEncoder, TextDecoder). The text never leaves the device. Recent inputs live in your browser's localStorage and can be cleared from the Recent card.