Base64 encoder and decoder
Encode text to Base64 or decode it back.
What Base64 is for
Base64 represents binary data using 64 printable characters, so that data can travel through channels which only handle text — email bodies, JSON fields, HTTP headers, data URIs, environment variables.
It is worth being clear about what it is not: Base64 is not encryption. It is a reversible representation with no key and no secret. Anyone can decode it in one step. A credential stored as Base64 is a credential stored in plain text with an extra step, and treating it as protection is a genuine and common security mistake.
Unicode is handled properly
The browser's built-in btoa throws on any character above U+00FF, which is why so many web-based encoders fail on accented letters, emoji, or any non-Latin script. Text here is converted to UTF-8 bytes first, so héllo, 日本語 and 🎉 all encode and decode correctly.
URL-safe Base64
Standard Base64 uses + and /, which have meanings inside URLs, and pads with =, which is also awkward. The URL-safe alphabet substitutes - and _ and drops the padding. This is what JWTs use, and it is why a token pasted into a standard decoder often fails — decoding here handles either.
Size
Encoded output is about 33% larger than the input, since three bytes become four characters. That overhead is the price of passing binary through a text channel.
Related
For files rather than text, Image to Base64 produces a data URI. For tokens, the JWT decoder splits and decodes all three segments at once.
Common questions
Is Base64 encryption?
No. It is a reversible representation with no key. Anyone can decode it instantly — never use it to protect a secret.
Why do other tools fail on accented characters?
They call btoa directly, which throws above U+00FF. Text here is converted to UTF-8 bytes first.
What is URL-safe Base64?
It swaps + and / for - and _ and drops the padding, so the result is safe inside a URL. JWTs use it.
Why is the output larger?
Three bytes become four characters — about 33% overhead.
Is my text uploaded?
No. Encoding and decoding happen in your browser.