Base64 preview

Base64

Encode text to Base64 or decode Base64 strings back to readable content. Supports full Unicode including accented characters, emoji, and non-Latin scripts. All processing happens in your browser.

Key features

  • Fast conversion from text to Base64 and vice versa
  • Smooth processing of large data loads
  • URL-friendly secure encoding support
  • One-touch copy of all content

Guide

Base64 encoding converts binary data into a text-safe format using 64 ASCII characters (A-Z, a-z, 0-9, +, /). It is one of the most widely used encoding schemes in software development, appearing in email attachments, data URIs, API authentication, JWT tokens, certificate files, and configuration systems. This tool encodes and decodes Base64 strings and files directly in your browser. ## What Base64 Is and Is Not Base64 is an encoding, not encryption. It transforms data into a different representation but provides zero security. Anyone can decode a Base64 string instantly. Never use Base64 to protect sensitive information. If you see a password or API key encoded in Base64, it is no more secure than storing it in plain text. A common misconception among junior developers is that encoding credentials in Base64 somehow hides them. It does not. The encoding works by taking every 3 bytes of input and converting them into 4 ASCII characters. Each character represents 6 bits of data (2^6 = 64 possible values). This means Base64 output is always about 33% larger than the input. A 3KB file becomes approximately 4KB when Base64-encoded. The padding character = appears at the end when the input length is not a multiple of 3. One byte of input (not divisible by 3) results in two Base64 characters plus == padding. Two bytes result in three Base64 characters plus = padding. The standard character set is: ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/. A variant called Base64URL replaces + with - and / with _ to make the output safe for URLs and filenames. This variant is used in JWT tokens and other URL-embedded data. The distinction matters because + and / have special meaning in URLs (+ is sometimes treated as a space, / is a path separator). ## The Encoding Process Step by Step To understand Base64, walk through encoding the string "Hi" (two bytes: 0x48 and 0x69). Step 1: Convert each byte to binary. H = 01001000, i = 01101001. Step 2: Concatenate all bits: 01001000 01101001. Step 3: Split into 6-bit groups: 010010 000110 1001. Since we only have 16 bits (not divisible by 6 evenly), pad the last group with zeros: 010010 000110 100100. Step 4: Map each 6-bit group to the Base64 alphabet. 010010 = S, 000110 = G, 100100 = k. Step 5: Add padding. We started with 2 bytes (not a multiple of 3), so add one = character. Result: SGk= This is exactly what btoa("Hi") returns. Understanding this process helps when you debug encoding mismatches. ## Encoding Text to Base64 The most basic operation: you have a string and need its Base64 representation. In JavaScript, this is btoa("Hello World") which returns "SGVsbG8gV29ybGQ=". The tool does this in real-time as you type. A critical detail: btoa() only handles ASCII characters (code points 0-255). If your string contains non-ASCII characters like emojis, accented letters (cafe), or CJK characters, btoa() throws an error. The correct approach in JavaScript is: For encoding: btoa(unescape(encodeURIComponent(text))) For decoding: decodeURIComponent(escape(atob(base64))) The modern approach uses TextEncoder: btoa(String.fromCharCode(...new TextEncoder().encode(text))). This tool handles Unicode correctly, so you can paste any text including non-Latin characters and emoji. Practical example: you need to set a Basic Authentication header. The format is Authorization: Basic base64(username:password). If your username is admin and password is s3cret, you encode admin:s3cret to get YWRtaW46czNjcmV0. The full header becomes Authorization: Basic YWRtaW46czNjcmV0. You can generate this directly in the tool. Every HTTP client that supports Basic Auth does this encoding internally, but when debugging raw HTTP traffic, you need to decode the header manually to see the credentials. ## Decoding Base64 to Text Paste a Base64 string and get the original text back. This is the operation you perform most often when debugging. You see a Base64 string in a log file, a JWT payload, an email header, or a config value, and you need to know what it says. For example, you receive a webhook payload where the body field is eyJldmVudCI6Im9yZGVyLmNyZWF0ZWQiLCJpZCI6MTIzfQ==. Decoding it reveals {"event":"order.created\

Frequently asked questions

Is Base64 an encryption?

No. Base64 is an encoding method that converts binary data to ASCII text. It does not provide security.

Does it support Unicode characters?

Yes. All character sets including accented letters, emoji, and non-Latin scripts convert correctly.

Related guides

Related WebRecast sections