Developer Tools

Base64 Encoder / Decoder

Encode text or files to Base64, or decode Base64 strings back to plain text. URL-safe mode, line wrapping, file support, and data URI generation. 100% private: nothing sent to servers.

Last updated

Encode & Decode
URL-Safe Mode
File & Image Support
100% Private
Our networkLegalCost.usWhat will your legal case cost?Official formulas for all 50 states. Free, no signup.Check your state
B64
Base64 Encoder / Decoder
100% local · Nothing transmitted · Works offline
Plain Text Input empty
Drop a file here or click to select
Any file type · Converts to Base64 automatically
Base64 Output ready
Input: 0 chars
Output: 0 chars
Size ratio: —

How Base64 Works

Base64 turns every 3 bytes into 4 characters, so the output is about 33% larger: "Man" becomes TWFu and "Hello, World!" becomes SGVsbG8sIFdvcmxkIQ==. This tool encodes text as UTF-8 first, so accents, symbols and emoji come out right. Paste text or drop a file to encode it, or switch to Decode to read a Base64 string.

  1. Type or paste text, or drop a file, in Encode mode. Text is turned into UTF-8 bytes first.
  2. Each group of 3 bytes (24 bits) is split into four 6-bit values from 0 to 63.
  3. Each value is looked up in the alphabet A to Z, a to z, 0 to 9, + and /.
  4. If the last group has only 1 or 2 bytes, the output is padded with == or =.

Switch to Decode to reverse it. Encoding and decoding run in your browser with JavaScript; the text and files you use are not uploaded.

Base64 Examples You Can Check

Type any of these into the tool to confirm the output. The last column is the URL-safe variant with padding removed, the form used in JWTs.

InputUTF-8 bytesStandard Base64URL-safe, no padding
Man3TWFuTWFu
Ma2TWE=TWE
M1TQ==TQ
Hello, World!13SGVsbG8sIFdvcmxkIQ==SGVsbG8sIFdvcmxkIQ
user:pass9dXNlcjpwYXNzdXNlcjpwYXNz
héllo6aMOpbGxvaMOpbGxv
€34oKs4oKs
😀 (emoji)48J+YgA==8J-YgA
Hi?>4SGk/Pg==SGk_Pg

Notice that "héllo" has 5 letters but 6 bytes: é takes two bytes in UTF-8. The emoji and "Hi?>" rows show where the URL-safe alphabet swaps + for - and / for _.

How Much Bigger Base64 Makes Data

The encoded length is 4 × (bytes ÷ 3, rounded up). Line breaks, if you turn on wrapping, come on top.

Input sizeBase64 charactersGrowth
1 byte44.00×
3 bytes41.33×
10 bytes161.60×
100 bytes1361.36×
1,000 bytes1,3361.34×
1 MiB (1,048,576 bytes)1,398,1041.33×

Wrapped at 76 characters with CRLF line endings, as MIME email does, that 1 MiB file becomes 18,397 lines and 1,434,896 characters. This is why a 10 MB attachment can push an email past a 13 MB limit.

Why btoa() Fails on Unicode Text

The browser's btoa() only accepts characters with codes 0 to 255, so btoa('€') throws an InvalidCharacterError. Encode the text to UTF-8 bytes first:

  • Browser: btoa(String.fromCharCode(...new TextEncoder().encode(text))) for short strings.
  • Node.js: Buffer.from(text, 'utf8').toString('base64'), and 'base64url' for the URL-safe form.
  • Python: base64.b64encode(text.encode('utf-8')).

The character set matters. "é" is w6k= in UTF-8, 6Q== in Latin-1 and 6QA= in UTF-16LE. All three are valid Base64, but only the first decodes to "é" in this tool and in most web APIs.

Common Errors and How to Fix Them

  • "Invalid Base64 string": the input has characters outside the alphabet. A frequent cause is pasting a whole data URI; delete everything up to and including base64, first. Spaces and line breaks are fine, the tool strips them.
  • Wrong length: after removing whitespace, a length that leaves a remainder of 1 when divided by 4 is never valid. Part of the string was cut off when it was copied.
  • "Not UTF-8 text": the Base64 is fine but holds binary data, such as a PNG or a zip file. Decode it with a file tool instead of reading it as text.
  • Encoded twice: if the output of a decode still looks like Base64, it was encoded twice. "Hello" once is SGVsbG8=, twice is U0dWc2JHOD0=. Decode again.
  • Garbled accents such as é: UTF-8 bytes were read as Latin-1 somewhere along the way. Re-encode from the original text as UTF-8.
Method and sources. Encoding follows RFC 4648 (sections 4 and 5 for the standard and URL-safe alphabets) and RFC 2045 for 76-character MIME lines. Text is converted to bytes with UTF-8 (RFC 3629). Every example and size in the tables was generated with Node.js Buffer and checked against the tool.

Base64 Explained

Base64 is an encoding scheme that converts binary data into a text format using 64 printable ASCII characters: A-Z, a-z, 0 to 9, +, and /. It was invented to safely transmit binary data (images, files) through systems designed only for text, like email (MIME). Common uses today: embedding images directly in HTML/CSS as data URIs (data:image/png;base64,...), encoding binary attachments in emails, passing data through JSON APIs that only accept strings, HTTP Basic Authentication (Authorization: Basic dXNlcjpwYXNz), and storing binary data in databases. Base64 increases data size by about 33%.

Standard Base64 uses + and / which have special meaning in URLs (+ means space, / separates path segments). URL-safe Base64 (RFC 4648 Section 5) replaces + with - and / with _, making the output safe to include directly in URLs and filenames without percent-encoding. The = padding characters can also be removed since the length is usually known in context. URL-safe Base64 is used in JWT (JSON Web Tokens), OAuth 2.0 PKCE, URL shorteners, file naming, and any context where the Base64 string appears in a URL. Toggle the URL-safe checkbox above to use this variant.

No. Base64 is an encoding, not an encryption. Anyone can decode a Base64 string instantly: there is no key, no password, and no secret involved. It provides zero security. Seeing SGVsbG8gV29ybGQ= decoded immediately to Hello World illustrates this clearly. Base64 only converts binary data to a text-safe format for transmission. For actual security, use encryption algorithms like AES-256 or RSA on top of Base64 if needed. Never use Base64 alone to "hide" or "protect" sensitive information like passwords, tokens, or personal data.

Base64 works by taking 3 bytes (24 bits) of input at a time and splitting them into four 6-bit groups. Each 6-bit group (values 0 to 63) maps to a character in the Base64 alphabet. Since there are only 64 characters needed, any printable ASCII subset works. If the input length is not divisible by 3, padding = or == is added. Example: "Man" (0x4D 0x61 0x6E = 01001101 01100001 01101110) becomes four 6-bit groups: 010011 010110 000101 101110 = indices 19, 22, 5, 46 = "TWFu". This is why Base64 output is always about 4/3 (≈133%) the size of the input.

A data URI (or data URL) embeds file content directly into HTML or CSS using the format data:[mediatype];base64,[data]. Example: <img src="data:image/png;base64,iVBOR...">. This eliminates an HTTP request for that resource. Use cases: embedding small icons, logos, or background images in CSS to reduce HTTP requests; embedding assets in email HTML where external URLs may be blocked; single-file HTML documents that include all assets. Avoid for large files: a 100KB image becomes ~133KB in Base64, and the browser cannot cache it separately. Best used for assets under 5 to 10KB. This tool generates the data URI automatically when you drop an image file.

Browser JavaScript: btoa(text) encodes a string to Base64, atob(base64) decodes it. Important: btoa() only handles Latin-1 characters. For Unicode/UTF-8 strings: btoa(unescape(encodeURIComponent(str))) to encode, and decodeURIComponent(escape(atob(b64))) to decode. In Node.js: Buffer.from(text).toString('base64') to encode, Buffer.from(b64, 'base64').toString('utf8') to decode. For URL-safe Base64 in Node.js, use base64url package or replace + with -, / with _, and remove = padding manually.

Base64 encodes 3 bytes into 4 characters. If the input length is not a multiple of 3, one or two = characters are appended to make the output length a multiple of 4. One = means 1 byte of padding; == means 2 bytes. The padding makes the length unambiguous for decoders. Padding can be safely omitted when the length is known from context: for example, in JWT tokens and URL-safe Base64, the = is typically stripped since the parser knows the total length. The "No padding" checkbox above removes the trailing = characters. Most modern decoders can handle unpadded Base64, but some strict implementations require padding.

MIME (RFC 2045) Base64 requires that encoded output be wrapped at 76 characters per line with CRLF (\r\n) line endings. This originated from limitations in early email software and telecommunications that could not handle very long lines. Modern systems generally do not require line wrapping, but it is still standard in PEM-encoded certificates and some email contexts. The "Line wrap" selector above lets you choose 64 characters (PGP/SSH standard), 76 characters (MIME email standard), 128 characters, or no wrapping. For most web and API uses, no wrapping is preferable.

Drop your image file on the drop zone above. The tool encodes it to Base64 and generates a complete data URI in the Data URI section below the output. Copy it and use directly in CSS: background-image: url('data:image/png;base64,iVBOR...');. Or in HTML: <img src="data:image/svg+xml;base64,PHN2Zy...">. For SVG files, you can often embed them without Base64 by URL-encoding the SVG text: url("data:image/svg+xml,%3Csvg..."). Base64 images increase HTML/CSS file size and disable browser caching for that asset separately, so use them only for very small images (icons under 1 to 2KB).

Base32 uses 32 characters (A-Z, 2 to 7) and is case-insensitive, producing larger output (60% overhead) but safer for case-insensitive contexts like TOTP authentication codes (Google Authenticator). Base58 (used in Bitcoin addresses) removes visually similar characters (0, O, I, l) to avoid human transcription errors. Base85 (Ascii85) uses 85 characters for 25% overhead vs Base64's 33%, used in PDF and PostScript. Base64 is the universal standard for web and email because its 33% overhead is acceptable and it is natively supported in all browsers and most languages. This tool handles standard Base64 and URL-safe Base64 (RFC 4648).

On Linux and macOS, run echo 'SGVsbG8=' | base64 --decode, which prints Hello. To encode, use printf 'Hello' | base64; printf avoids the trailing newline that echo adds, which would change the output to SGVsbG8K. In PowerShell: [Text.Encoding]::UTF8.GetString([Convert]::FromBase64String('SGVsbG8=')). On Windows Command Prompt, certutil -decode in.txt out.bin decodes a file.

Usually the text was encoded with a different character set. Base64 only stores bytes, so if the sender encoded Latin-1 or UTF-16 and you read the bytes as UTF-8, accents and symbols come out wrong or the decode fails. Ask for UTF-8, or decode the bytes with the matching character set in code. If the output is mostly unreadable symbols, the data is probably a binary file, not text.