How to Encode and Decode Base64 Text Safely
Quick summary
Learn what Base64 is, when to use standard vs URL-safe Base64, and how to encode or decode text locally in your browser without uploading data.
Base64 is a way to represent binary or Unicode data as plain text. Developers often use it in API payloads, tokens, data URLs, configuration files, and quick debugging sessions.
The NeatForge Base64 Encoder/Decoder lets you encode and decode text in your browser, including URL-safe Base64 strings.
Standard Base64 vs URL-Safe Base64
Standard Base64 commonly uses +, /, and = padding. That works well in many files and API payloads, but those characters can be awkward inside URLs.
URL-safe Base64 replaces:
+with-/with_- optional padding
=may be removed
If you are working with query strings, JWT-like values, or route parameters, URL-safe mode is usually the better choice.
How to Encode Text
- Open the Base64 Encoder/Decoder.
- Choose Standard Base64 or URL-safe mode.
- Paste the text you want to encode.
- Click Encode.
- Copy the result.
How to Decode Base64
- Paste the Base64 string into the input field.
- Select the matching mode.
- Click Decode.
- Review the decoded text.
If decoding fails, check for missing characters, extra spaces, or the wrong mode. URL-safe Base64 often needs URL-safe mode because - and _ are interpreted differently from standard Base64.
Handling data URL prefixes
A data URL looks like data:image/png;base64,iVBORw0KGgo.... Only the part after the comma is Base64 — the data:*/*;base64, prefix describes the media type and must be stripped before decoding in most tools.
Practical workflow:
- Identify the prefix: everything from
data:up to the first comma is metadata, not payload. Common forms includedata:text/plain;base64,,data:image/svg+xml;base64,, anddata:application/pdf;base64,. - Split on the first comma: keep the tail as the value to decode. If you need the file type later, store the prefix separately instead of mixing it into the decoder input.
- Watch for whitespace: data URLs copied from HTML, CSS, or JSON sometimes contain line breaks or spaces. Remove them first, because strict decoders reject them.
- Re-encode correctly: when you build a data URL, encode the raw bytes first, then prepend
data:<mime>;base64,without adding spaces. Test the result in a browser address bar or an<img>tag before shipping.
If a decoder reports “invalid character”, the prefix is the most likely culprit. The NeatForge tool accepts pasted text with surrounding whitespace, but separating metadata from payload explicitly avoids silent errors in your own scripts.
Large files, binary data, and JWT parts
Base64 increases size by roughly one third because every 3 input bytes become 4 text characters, plus padding. That overhead matters for large files, and text encoders are the wrong tool for multi-megabyte binaries.
Follow these rules:
- Small text snippets: encode directly in the browser. API keys for examples, short JSON blobs, SVG icons, and config values are ideal candidates.
- Large files: use a file-aware workflow with streaming, chunking, or direct binary upload instead of pasting megabytes into a text box. Browsers can run out of memory, URLs have length limits, and JSON payloads become slow to parse.
- Binary safety: Base64 preserves bytes, but the decoded result is not always printable text. Images, PDFs, and archives must be written back as binary (Blob, Buffer, or file) rather than interpreted as UTF-8 strings, or they will corrupt.
- JWT and token-like values: a JWT has three dot-separated segments (header, payload, signature), each encoded with URL-safe Base64 without padding. Decode each segment separately in URL-safe mode. Add back
=padding until the length is a multiple of four when your library requires it. Never trust the payload without verifying the signature on the server, because Base64 decoding alone proves nothing about authenticity. - Character encoding: always encode the UTF-8 bytes of Unicode text, not UTF-16 code units. Emoji, CJK characters, and accented letters decode incorrectly when the encoder and decoder disagree on the text encoding. If you see replacement characters, check the UTF-8 round-trip first.
As a rule of thumb: text under a few hundred kilobytes is comfortable in an online encoder; anything larger, binary, or security-sensitive belongs in code with explicit byte handling.
Common Base64 pitfalls
Base64 is often confused with encryption because the output looks unreadable. It provides no confidentiality, integrity, or authentication. Do not place passwords, API keys, access tokens, or personal data in a Base64 value unless the surrounding system already protects it.
When a value comes from a URL or JWT-like token, check whether it uses the URL-safe alphabet. When a value is copied from a data URL, remove the data:*/*;base64, prefix before decoding if your tool expects only the encoded payload. For large binary files, use a file-aware workflow because Base64 increases the data size by roughly one third.
Privacy Note
Encoding can reveal sensitive data if you paste secrets into a third-party service. NeatForge processes the text locally in your browser, so the input is not uploaded to our server.
→ Open the free Base64 Encoder/Decoder