Free Base64 Encoder and Decoder Online

Encode text to Base64 or decode Base64 back to readable text in your browser. UTF-8 safe, so accents and emoji work. Your text is not sent to our server.

No login. Files processed for your request and discarded. Unlimited use. Files processed & discarded →

Compress PDF — it's free or choose from 164+ tools

164+ Free Tools
— Files Processed
— Happy Visitors
— Pages Explored
0 Files Stored

Base64 Encode and Decode Online

Part of Text tools: See all Text tools.

What is Base64 Encoder and Decoder?

This free Base64 tool converts text to Base64 and Base64 back to text. Text is encoded as UTF-8 first, so accented letters, non-Latin scripts and emoji survive the round trip. Decoding ignores spaces and line breaks in the input. Everything runs in your browser, so the text is not sent to our server.

How to use Base64 Encoder and Decoder

  1. Paste plain text, or a Base64 string, into the Input box.
  2. Click Encode to Base64 to turn text into Base64, or Decode from Base64 to turn Base64 back into text.
  3. Read the result in the Output box. If the input is not valid standard Base64 text, you will see Invalid Base64 string.
  4. Select the output and copy it where you need it.

Why use this tool?

Base64 appears in data URLs, email source, API payloads, configuration files and token headers. A quick encoder and decoder lets you read or build those strings without writing code. Because it runs locally, you can inspect a header or payload without pasting it into a server-side tool.

Where you'll see it: Base64 shows up in data URLs, embedded payloads, and debugging contexts where you need text-safe encoding.

When decoding, treat output as text if it's UTF-8; if you're working with binary content, you may need a different workflow.

What this Base64 tool does

Encode to Base64 takes your text, converts it to UTF-8 bytes and writes those bytes in standard Base64, using the characters A–Z, a–z, 0–9, + and /, with = padding at the end. Decode from Base64 does the reverse. It removes any spaces and line breaks, converts the Base64 back to bytes, and shows them as UTF-8 text. Both run in your browser. Some examples we checked in the tool:

TextBase64
HelloSGVsbG8=
hélloaMOpbGxv
Hi 😀SGkg8J+YgA==
{"alg":"HS256"}eyJhbGciOiJIUzI1NiJ9

The decoder is forgiving about formatting. SGVsbG8 without its padding, and Base64 wrapped across several lines as it appears in email source, both decode to “Hello”.

How Base64 encoding works

Base64 turns any sequence of bytes into a short alphabet of 64 characters that are safe to put in text-only places, such as email bodies, JSON strings, URLs (in the URL-safe variant) and HTML attributes. It takes the input three bytes (24 bits) at a time and splits them into four groups of six bits. Each six-bit number, from 0 to 63, maps to one character. When the input length is not a multiple of three, the output is padded with one or two = signs. That is why “Hello” (5 bytes) becomes 8 characters ending in =.

One consequence is size: Base64 output is about one third larger than the input, because every 3 bytes become 4 characters. That is fine for small values and headers, but wasteful for large files.

Where you see Base64

  • Data URLs in HTML and CSS, such as data:image/png;base64,…, which embed small images in the page.
  • Email (MIME) attachments and non-ASCII message bodies, usually wrapped at 76 characters per line.
  • HTTP Basic authentication, which sends username:password encoded in Base64. That is encoding, not protection, which is why it must only be used over HTTPS.
  • JSON Web Tokens (JWTs), whose header and payload are URL-safe Base64.
  • Configuration and secrets files, such as Kubernetes Secrets, which store values in Base64. Anyone who can read the file can decode them.

Standard vs URL-safe Base64

Standard Base64 uses + and /, which have special meanings in URLs. The URL-safe variant (Base64url) swaps them for - and _ and often drops the = padding. This tool encodes and decodes standard Base64 only. To decode a Base64url value, such as a JWT segment, replace every - with + and every _ with / first. Missing padding is fine. To produce Base64url, encode here and make the opposite swap, then remove trailing = signs.

Reading a JWT header or payload

A JWT looks like xxxxx.yyyyy.zzzzz. Copy the first part (the header) or the second part (the payload), make the URL-safe swap described above, and click Decode from Base64. You will see JSON such as {"alg":"HS256"}. To lay out a long payload neatly, paste it into the JSON Formatter. The third part is the signature. It is binary, so it will not decode to readable text, and decoding a token does not verify it. Only the server holding the key can verify the signature.

Base64 is not encryption

Because Base64 output looks scrambled, it is often mistaken for protection. It is not: there is no key, and anyone can reverse it in a second, as this page shows. If you need to keep something secret, use real encryption. If you need a one-way fingerprint to compare values, use a hash such as SHA-256 from the Hash Generator.

Limits

  • Text only. There is no file upload, and decoding Base64 that represents an image or other binary data shows an error, because the bytes are not valid UTF-8 text.
  • Standard alphabet only. URL-safe input needs the character swap described above.
  • Errors clear the output. If decoding fails, the output box is emptied and Invalid Base64 string is shown, so you never mistake an old result for a new one.

Privacy

Encoding and decoding use the browser's built-in functions. Your input and output stay in the tab and are not sent to our server. Related tools: the Password Generator makes random secrets, and the Regex Tester checks whether a string matches the Base64 alphabet.

Frequently asked questions

Is Base64 encryption?
No. Base64 is an encoding, not encryption. Anyone can decode it instantly without a key, so never use it to hide passwords or personal data.
Why does decoding say Invalid Base64 string?
The decoder accepts standard Base64 (A–Z, a–z, 0–9, + and /, with optional = padding). It shows this message if the input contains other characters, including the - and _ used by URL-safe Base64, or if the decoded bytes are not valid UTF-8 text, for example an image or other binary data.
Does it handle accents, non-Latin text and emoji?
Yes. Text is converted to UTF-8 bytes before encoding, and decoded bytes are read as UTF-8. For example, héllo encodes to aMOpbGxv and decodes back to héllo.
Can I decode a JWT with this tool?
You can read the header and payload. JWTs use URL-safe Base64 without padding, so first replace each - with + and each _ with /, then decode. For example, eyJhbGciOiJIUzI1NiJ9 decodes to {"alg":"HS256"}. The signature part is binary and will not decode to text.
Can I encode an image or file?
No. This tool works with text only and has no file upload. Decoding Base64 that represents an image or other binary file shows an error, because the result is not text.
Is my text uploaded?
No. Encoding and decoding use your browser's built-in functions, and the input and output are not sent to our server.

Step-by-step guides

Also try

Related tools that work well with this one: