How to Base64 encode and decode online
- Encode text: type or paste it. Auto-detect encodes anything that is not valid Base64; choose Encode to force it. Text is converted to UTF-8 bytes first, so emoji, Hindi, Chinese and accented letters work.
- Decode Base64: paste the string, a Base64URL value from a JWT or URL, or a whole
data:URI. Whitespace, line breaks and missing=padding are fine. - Decode to a file: if the bytes are an image, a preview appears; PDFs, ZIPs and other binary data get a Download decoded file button with the right extension.
- Encode an image or file: switch to File or image and drop it in to get a data URI, raw Base64, an
<img>tag and a CSSbackground-imageline.
How Base64 works, byte by byte
Base64 takes the input 3 bytes (24 bits) at a time and splits them into four 6-bit groups. Each 6-bit value (0–63) is looked up in the alphabet A–Z a–z 0–9 + /. Encoding Man:
| Step | M | a | n |
|---|---|---|---|
| Byte (decimal) | 77 | 97 | 110 |
| Bits | 01001101 | 01100001 | 01101110 |
| Regrouped as 6 bits | 010011 010110 000101 101110 → 19, 22, 5, 46 | ||
| Base64 | T W F u → TWFu | ||
When the last group is short, zero bits fill it and = marks the missing bytes: Ma → TWE=, M → TQ==. That is why Base64 output is always a multiple of four characters and about 33% larger than the input. Press Show bit-level breakdown in the tool to see this for your own input.
Base64 vs Base64URL
| Standard Base64 (RFC 4648 §4) | Base64URL (RFC 4648 §5) | |
|---|---|---|
| Characters 62 and 63 | + and / | - and _ |
| Padding | = required | Usually omitted |
| Used in | Email (MIME), data URIs, PEM certificates, Basic Auth, most JSON APIs | JWTs, URL parameters, file names, WebAuthn, Kubernetes secrets in URLs |
Encoding JSON, XML, HTML, CSS, CSV, SVG and other text
Any text format is encoded the same way: its UTF-8 bytes become Base64. What changes is where the result goes, so the Output selector can wrap it in a data URI with the right MIME type:
| Content | Typical use of the Base64 | Data URI prefix |
|---|---|---|
| Plain text / ASCII | Config values, env vars, Basic Auth. ASCII is a subset of UTF-8, so text-to-Base64 and ASCII-to-Base64 give identical output. | data:text/plain;base64, |
| JSON | Kubernetes secrets, JWT parts, API fields that must be opaque | data:application/json;base64, |
| XML | SAML assertions, SOAP attachments | data:application/xml;base64, |
| HTML | Email bodies, iframes built from strings | data:text/html;base64, |
| CSS / JavaScript | Inlined stylesheets or bookmarklets | data:text/css;base64, / data:text/javascript;base64, |
| CSV / TSV | Spreadsheet exports embedded in JSON or a download link | data:text/csv;base64, |
| YAML | CI variables, Helm values | data:application/yaml;base64, |
| SVG | Icons inlined in CSS or <img> (SVG can also be URL-encoded instead, which is often smaller) | data:image/svg+xml;base64, |
Decoding works the other way round: paste the Base64 and the tool detects whether the bytes are JSON (offering Pretty-print JSON), XML, HTML, SVG, an image, a PDF or another binary format. To tidy decoded markup, use the XML formatter or the HTML formatter.
The Unicode trap in JavaScript
The browser’s btoa("é") works but btoa("😀") throws “The string to be encoded contains characters outside of the Latin1 range”, because btoa maps each character to one byte. Convert to UTF-8 bytes first — this tool does it for you:
// Encode any string (UTF-8)
const b64 = btoa(String.fromCharCode(...new TextEncoder().encode(str)));
// Decode back to a string
const text = new TextDecoder().decode(Uint8Array.from(atob(b64), c => c.charCodeAt(0)));
// Modern browsers and Node 22+: Uint8Array.prototype.toBase64 / Uint8Array.fromBase64
Base64 in other languages
Python
import base64
base64.b64encode("Café ☕".encode()).decode() # 'Q2Fmw6kg4piV'
base64.b64decode("Q2Fmw6kg4piV").decode() # 'Café ☕'
base64.urlsafe_b64encode(b"\xfb\xff").rstrip(b"=") # b'-_8'
Bash / Linux / macOS
printf '%s' 'user:pass' | base64 # dXNlcjpwYXNz
echo 'dXNlcjpwYXNz' | base64 --decode # macOS: base64 -D on older versions
base64 -w 0 image.png > image.b64 # GNU: no line wrapping
openssl base64 -A -in image.png # portable alternative
Java
Base64.getEncoder().encodeToString("Café ☕".getBytes(StandardCharsets.UTF_8));
new String(Base64.getDecoder().decode("Q2Fmw6kg4piV"), StandardCharsets.UTF_8);
Base64.getUrlEncoder().withoutPadding().encodeToString(bytes); // Base64URL
Base64.getMimeDecoder().decode(wrappedText); // ignores line breaks
Go
base64.StdEncoding.EncodeToString([]byte("Café ☕"))
base64.RawURLEncoding.EncodeToString(b) // Base64URL, no padding
data, err := base64.StdEncoding.DecodeString("Q2Fmw6kg4piV")
PHP
base64_encode("Café ☕"); // Q2Fmw6kg4piV
base64_decode("Q2Fmw6kg4piV", true); // strict: false on invalid input
rtrim(strtr(base64_encode($bytes), '+/', '-_'), '='); // Base64URL
Common questions
Why does my Base64 fail to decode?
Usually a character outside the alphabet (a stray quote, or -/_ fed to a strict decoder), a truncated string, or a length that is not a multiple of four. This decoder accepts both alphabets, ignores whitespace and restores padding; if the result is not valid UTF-8 it is shown as a file or hex instead of garbled text.
What is the difference between Base64 and Base64URL?
Base64URL swaps + and / for - and _ and usually drops =, so it is safe in URLs, headers and file names. JWTs use it. Tick URL-safe to produce it; decoding accepts either.
Why is Base64 output about 33% larger?
Three bytes become four characters, so output is 4/3 the input size, rounded up to a multiple of four. A 30 KB image becomes about 40 KB of Base64.
What do the trailing = signs mean?
Padding: one = when the last group had two bytes, two when it had one. It carries no data, which is why Base64URL often omits it.
How do I build an HTTP Basic Auth header?
Encode username:password and prefix it with Basic: user:pass → Authorization: Basic dXNlcjpwYXNz. It is not encryption, so only send it over HTTPS.
Is Base64 encryption?
No. It is reversible with no key; anyone can decode it. Use it to move binary through text-only channels, never to hide secrets.
Is my text or file uploaded?
No. Everything uses TextEncoder, TextDecoder, btoa, atob and FileReader in your browser.