Base64 Encode/Decode
Encode text to Base64 and decode it back — Unicode-safe, entirely in your browser.
How to use base64 encode/decode
- Paste the text you want to encode — or the Base64 string you want to decode — into the input box.
- Click Encode to turn the text into Base64, or Decode to turn Base64 back into text.
- If the input is not valid Base64, the status bar explains what is wrong; fix it and try again.
- Click Copy output to copy the result to your clipboard.
Examples
Encode "Hello, World!"
The classic greeting becomes SGVsbG8sIFdvcmxkIQ==. The Try it button fills the input and clicks Encode for you.
Decode a Base64 string
SGVsbG8sIFdvcmxkIQ== decodes back to the original text "Hello, World!".
Encode non-Latin text
UTF-8 encoding means accents and CJK characters survive intact — "Café 東京" encodes without errors.
What is Base64?
Base64 is an encoding scheme that represents arbitrary data using 64 safe ASCII characters: the letters A–Z and a–z, the digits 0–9, and the symbols + and /. It exists because many systems — email servers, URLs, JSON, early web protocols — were built to carry text, not raw bytes. By mapping every three bytes to four printable characters, Base64 lets binary data travel through text-only channels without corruption.
You encounter Base64 constantly, usually without noticing. Data URIs embed small images directly in CSS or HTML as Base64 strings. JSON Web Tokens (JWTs) are three Base64URL-encoded segments joined by dots. HTTP Basic authentication sends credentials as a Base64 username:password pair, and every email attachment is Base64-encoded MIME content. It is everywhere — and it is not encryption. Base64 has no key: anyone with any decoder can reverse it instantly. Treat it as a transport format, never as a way to protect secrets.
Many online Base64 tools quietly break on anything beyond plain ASCII because they call the browser’s btoa() directly, which throws on emoji, accents and non-Latin scripts. This tool encodes text as UTF-8 bytes first using TextEncoder, so Japanese, Arabic or accented characters all round-trip correctly.
Privacy matters here more than for most tools, because the things people Base64 are often sensitive: API tokens, session cookies, Basic auth headers. Everything on this page runs locally in your browser — there is no server round-trip, so you can decode a production token without it ever leaving your machine.
Frequently asked questions
Is Base64 encryption?
No. Base64 is an encoding, not a cipher — it uses no key, and anyone can decode it instantly. It exists so binary data can pass through text-only systems, not to hide content. If you need secrecy, use real encryption.
Why does Base64 output end with "="?
The equals sign is padding. Base64 encodes three bytes into four characters, so when the input length is not a multiple of three, one or two placeholder characters are appended to complete the final group.
Why do some Base64 tools break on emoji or Chinese text?
Naive tools pass text straight into the browser’s btoa(), which only accepts characters in the Latin-1 range and throws on everything else. This tool first converts your text to UTF-8 bytes with TextEncoder and encodes those bytes, so any Unicode text works.
Can I paste Base64 with line breaks or spaces?
Yes. Whitespace is ignored when validating and decoding, so Base64 copied from an email or a terminal with line wrapping still decodes correctly.
Is my input sent to a server?
No. Encoding and decoding run entirely in your browser. This matters because people often paste API tokens and credentials here — nothing you type ever leaves your machine.
Why won’t my JWT segment decode?
JWTs use Base64URL, a variant that replaces + and / with - and _ and omits padding. This tool expects standard padded Base64; convert the characters and append "=" signs to a multiple of four characters before decoding.