Base64 turns any sequence of bytes into plain letters, digits and two symbols, so binary data can travel through channels built for text: email attachments, JSON payloads, HTTP Basic authentication headers, data: URIs in CSS and the three parts of a JSON Web Token. This tool encodes text to Base64 and decodes it back, treating text as UTF-8 so that accented letters, symbols and emoji survive the round trip — a common failure of quick JavaScript snippets that use btoa() directly.
How to use the Base64 encoder and decoder
- Choose Encode or Decode.
- Type or paste the input. When decoding, line breaks and spaces are ignored, and both the standard and URL-safe alphabets are accepted, with or without = padding.
- When encoding, optionally switch on the URL-safe alphabet, omit padding or wrap lines at 76 characters for MIME email bodies.
- Copy the result from the output box under the calculator. The tape shows byte counts and size growth; Show the work walks through the first 3-byte group bit by bit.
How Base64 works
Base64 (RFC 4648) reads the input 3 bytes at a time:
Each 6-bit group (0–63) indexes the alphabet A–Z (0–25), a–z (26–51), 0–9 (52–61), + (62) and / (63). If the last group has only 1 or 2 bytes, it is padded with zero bits and the output ends in == or =.
Text must first become bytes. This tool uses UTF-8, the encoding of the modern web: ASCII characters take 1 byte, accented Latin letters 2, most other scripts 3 and emoji 4.
Worked example
Encode the word Man.
Bytes: M = 77 = 01001101, a = 97 = 01100001, n = 110 = 01101110.
Regroup into 6 bits: 010011 010110 000101 101110 = 19, 22, 5, 46.
Look up: 19 = T, 22 = W, 5 = F, 46 = u → TWFu.
With only two bytes, Hi becomes 01001000 01101001, which is 16 bits; padded to 18 bits it splits into 010010 000110 100100 = S, G, k, and one = fills the missing character: SGk=.
A UTF-8 case: é is the two bytes C3 A9, which encode to w6k=. Code that treats é as a single Latin-1 byte (E9) would produce 6Q== instead, which decodes to garbage elsewhere — the classic Base64 mojibake bug.
Where you meet Base64
| Use | Detail |
|---|---|
| Email attachments | MIME bodies in Base64, lines of at most 76 characters |
| HTTP Basic auth | Authorization: Basic + Base64 of user:password (encoded, not encrypted — HTTPS is what protects it) |
| Data URIs | data:image/png;base64,iVBORw0KGgo… embeds a file in HTML or CSS |
| JSON Web Tokens | Header, payload and signature in URL-safe Base64 without padding |
| PEM certificates and keys | Base64 between -----BEGIN …----- lines |
A PNG file always starts with the bytes 89 50 4E 47, so Base64 image data starts with iVBORw0KGgo; JPEG data starts with /9j/. Recognizing those prefixes tells you a decode will produce binary, not text.
Troubleshooting decoding errors
- “Not a Base64 character” — the text contains something outside the alphabet, often a stray quote, a % escape or a character added by a chat app.
- Invalid length — a valid Base64 body never has a remainder of 1 character after dividing by 4. Part of the string was probably cut off when copied.
- Mixed alphabets — + or / together with - or _ means two different encodings were pasted together.
For percent-encoding in URLs, use the URL encoder and decoder. To see each character’s code point and UTF-8 bytes, try the text to ASCII converter, and for checksums of the same text, the hash generator.
Frequently asked questions
Is Base64 encryption?
No. Base64 is a reversible encoding with no key, so anyone can decode it. It exists to carry binary data through systems that only handle text, such as email, JSON and URLs. Never use it to hide passwords or secrets.
Why is Base64 output about 33% larger?
Every 3 bytes (24 bits) become 4 characters of 6 bits each, so the output is 4/3 the size of the input, plus up to two = padding characters. MIME line breaks add a little more.
What is URL-safe Base64?
A variant defined in RFC 4648 that replaces + with - and / with _, so the result can sit in a URL or file name without percent-encoding. JSON Web Tokens use it, usually without = padding.
Why does decoding give strange characters?
Either the original data was not text (an image, a zip file, encrypted bytes) or it was text in an encoding other than UTF-8. The decoder shows non-UTF-8 data as hexadecimal bytes instead of garbled characters.
Can I decode a data: URI?
Yes. Paste the whole data:...;base64,... string and the decoder skips the header and decodes the payload after the comma.