Base64 Encoder/Decoder

Encode text to Base64 or decode Base64 back to readable UTF-8 text. Supports standard and URL-safe Base64, runs entirely in your browser, and never uploads your data.

Advertisement
Advertisement

Encode and decode Base64 without uploading your data

Full UTF-8 support, URL-safe mode, and real-time conversion — right in your browser. No uploads, no sign-up, no limits.

100% private
UTF-8 safe
Free forever

How to use

  1. 1

    Paste Your Text

    Enter plain text to encode, or paste an existing Base64 string to decode. The tool auto-detects the direction.

  2. 2

    Choose a Base64 Format

    Use standard Base64 for most files and data, or URL-safe Base64 for tokens, query strings, and web-safe identifiers.

  3. 3

    Encode, Decode, or Copy

    Run the conversion and copy the result when it is ready. Results update in real-time as you type.

Why use this Base64 tool?

Full-featured Base64 encoding and decoding with privacy-first design.

UTF-8 Safe

Handles international text without breaking characters. Correctly encodes emoji, CJK scripts, and other non-ASCII characters.

URL-Safe Mode

Converts plus and slash characters into web-safe alternatives (- and _) and manages padding automatically. Perfect for JWT tokens and data URIs.

Browser-Only

Your text is processed locally, which is useful for snippets, tokens, and private configuration values. No uploads, no storage, no logging.

Real-Time Conversion

Encoding and decoding happen instantly as you type. No buttons to click — results update on every keystroke.

Auto-Detect Mode

Paste a Base64 string and the tool automatically detects it and decodes. Type plain text and it encodes. No need to switch modes manually.

Free with No Limits

No registration, no API key, no daily quotas. Free for personal and commercial use, forever.

Advertisement

Understanding Base64 Encoding

What is Base64 and why use it?

Base64 is an encoding scheme that converts binary data into a text representation using 64 ASCII characters (A-Z, a-z, 0-9, +, /). The encoding process takes every 3 bytes of input and converts them into 4 Base64 characters. This ensures that any binary data — including images, executables, and encrypted bytes — can be safely transmitted through channels that only support text, such as email, JSON, XML, and URLs.

The most common use cases for Base64 are: embedding binary data in JSON or XML (where raw bytes would break the syntax), encoding images as data URIs in HTML/CSS, encoding JWT token payloads, transmitting credentials in HTTP Basic Auth headers, and storing binary data in text-based databases or configuration files.

Advertisement

Standard vs. URL-safe Base64

Standard Base64 uses + and / as two of its 64 characters. These characters have special meanings in URLs (+ means space, / is a path separator), which can cause problems when Base64 strings appear in URLs or file names. URL-safe Base64 (RFC 4648 §5) replaces + with - and / with _, and typically omits the = padding character.

JWT tokens use URL-safe Base64 for encoding the header and payload. If you try to decode a JWT payload with standard Base64, you may get an error because - and _ are not valid standard Base64 characters. Our tool handles both formats — simply toggle the URL-safe option to match your input.

Base64 is not encryption

Base64 provides no security or confidentiality. Anyone who has the Base64 string can decode it back to the original data in milliseconds. Never use Base64 to protect passwords, API keys, or other secrets. If you need to protect data, use a proper encryption algorithm like AES-256. Base64 is only useful for ensuring data compatibility across systems, not for security.

Advertisement

Common Use Cases

Real-world scenarios where a Base64 encoder/decoder is essential.

JWT Tokens

Decode JWT header and payload by Base64-decoding each part. Essential for debugging authentication flows.

Data URIs

Encode images, fonts, or small files as Base64 data URIs for embedding directly in HTML, CSS, or JSON.

Configuration Files

Encode binary data or special characters in YAML, JSON, or XML configuration files where raw bytes are not allowed.

API Credentials

Encode API keys and secrets for HTTP Basic Auth headers or other credential-passing mechanisms.

How does this compare to other Base64 tools?

A side-by-side comparison of popular Base64 encoding tools.

FeatureNovaToolsBase64Encode.orgBrowser btoa()
Privacy (no upload)100% localUploads to serverLocal
URL-safe modeManual
UTF-8 supportbtoa() fails on non-ASCII
Real-time conversionButton clickN/A
Auto-detect modeN/A
Mobile friendlyLimitedN/A
Works offlineAfter page load

Base64Encode.org uploads your data to their server. Our tool processes everything locally — your text never leaves your browser.

Base64 Quick Reference

Key facts about Base64 encoding.

Character Set

A-Z

Uppercase letters (26 characters).

Example:QUJDRA== (encodes ABCD)
a-z

Lowercase letters (26 characters).

Example:YWJjZA== (encodes abcd)
0-9

Digits (10 characters).

Example:MDEyMzQ= (encodes 01234)
+ /

Standard Base64 special characters. + becomes - and / becomes _ in URL-safe mode.

Example:Pj8+Pw== (encodes >?>?)
=

Padding character (0-2 at end). Omitted in URL-safe mode.

Example:aGk= (encodes hi, 1 pad)

Key Facts

3 → 4

Every 3 input bytes become 4 Base64 characters.

Example:abc → YWJj (3 bytes → 4 chars)
33%

Base64 output is approximately 33% larger than input.

Example:300 bytes → 400 chars
UTF-8

Text is encoded as UTF-8 bytes before Base64 encoding.

Example:é → w6k= (2 UTF-8 bytes)
Not encryption

Base64 provides no security. Anyone can decode it.

Example:dGVzdA== → test (instantly reversible)

FAQ

What is Base64 encoding used for?
Base64 turns binary or text data into ASCII characters so it can safely travel through JSON, URLs, emails, tokens, and configuration files. It is commonly used to embed images in CSS/HTML (data URIs), encode JWT payloads, transmit binary data over text-only protocols, and store binary blobs in databases that only support text. Base64 is not encryption — it provides no security or confidentiality. Anyone can decode Base64 back to the original data.
Does this tool support Unicode text?
Yes. The encoder uses UTF-8, so text with accents, emoji, Chinese, Japanese, Korean, and other scripts can be encoded and decoded correctly. The tool first converts the input string to a UTF-8 byte sequence, then encodes those bytes to Base64. On decode, it reverses the process. This avoids the common 'btoa() does not work with non-ASCII characters' error that occurs when using the native browser btoa() function directly.
Is my text uploaded to a server?
No. Encoding and decoding happen locally in your browser with JavaScript. Your input never leaves your device. You can verify this by opening your browser's DevTools Network tab — no network requests are made when you encode or decode. This makes the tool safe for encoding API keys, tokens, credentials, and other sensitive data.
What is the difference between standard and URL-safe Base64?
Standard Base64 uses the characters A-Z, a-z, 0-9, +, and /, and pads the output with = characters. The + and / characters can cause problems in URLs and file names. URL-safe Base64 replaces + with - and / with _, and typically omits the = padding. URL-safe Base64 is used in JWT tokens, data URIs, and other contexts where the encoded string appears in a URL or file name. Our tool lets you toggle between standard and URL-safe modes.
Can I encode binary files (images, PDFs)?
This tool is designed for text encoding and decoding. For binary files, use a tool that reads the file as an ArrayBuffer and converts it to Base64. However, you can use this tool to decode a Base64 string that represents a binary file (like a data URI) and inspect the MIME type. For encoding images as Base64 data URIs, our Image Converter tool handles this automatically.
Why does my Base64 string not decode correctly?
The most common cause is a character encoding mismatch. If the original text was encoded as UTF-8 but decoded as Latin-1 (ISO 8859-1), non-ASCII characters will appear garbled. Another common issue is URL-safe Base64 being decoded as standard Base64 (or vice versa) — the - and _ characters are not valid in standard Base64. Make sure you select the correct mode (standard or URL-safe) for your input. Finally, check that the input string has the correct length — Base64 strings should have a length that is a multiple of 4 (after padding).
Is Base64 encryption?
No. Base64 is an encoding scheme, not encryption. Encoding converts data from one format to another using a publicly known algorithm, and anyone can decode it. Encryption uses a secret key to scramble data so that only someone with the key can read it. Never use Base64 to protect sensitive data — use proper encryption (AES, RSA) instead. Base64 is only useful for ensuring data compatibility across systems that handle text differently.
How much larger is Base64 compared to the original data?
Base64 encoding increases data size by approximately 33%. Every 3 bytes of input becomes 4 characters of Base64 output. For example, a 300-byte input produces a 400-character Base64 string. This overhead is the trade-off for ensuring the encoded data contains only ASCII characters that are safe to transmit over text-only channels. If bandwidth is critical, consider using a binary format instead of Base64.
Does the tool work on mobile devices?
Yes. The tool is fully responsive and works on iOS Safari and Android Chrome. The interface adapts to small screens with a stacked layout — input on top, output below, and mode controls accessible via toggle buttons. The encoding and decoding process runs locally on your phone, so it works even on slow network connections.
Can I use this for commercial projects?
Yes. The tool is free for both personal and commercial use with no watermarks, no attribution required, and no usage limits. You retain full ownership of your data. There is no registration, no API key, and no subscription required.

Private by Design

This Base64 encoder and decoder runs completely in your browser.

  • We do not upload, store, or inspect the text you process.
  • All encoding and decoding is performed locally using JavaScript — no network requests are made.
  • You can safely use this tool with API keys, JWT tokens, credentials, and other sensitive data.

Even if your internet connection drops mid-conversion, your data remains safe on your device.

You might also like

Helpful guides

Advertisement