Base64 Encoder / Decoder
Encode text to Base64 or decode Base64 back to plain text.
Everything runs locally in your browser — your text is never uploaded.
Encode plain text to Base64, or decode a Base64 string back to readable text — the encoding used to safely represent binary or arbitrary data as plain ASCII text in places like URLs, JSON payloads, and email attachments.
Both directions happen instantly as you type, with clear feedback if the input isn't valid Base64 to decode.
How the encoding works
Base64 takes three bytes (24 bits) at a time and re-splits them into four 6-bit groups, each mapped to one character from a 64-character alphabet: A–Z, a–z, 0–9, plus + and /. Four output characters for every three input bytes is where the roughly 33% size increase comes from.
When the input isn't a multiple of three bytes, the final group is padded with = characters so the output always divides cleanly into four-character blocks. That's why encoded strings so often end in = or ==.
Base64 is not security
- It is an encoding, not encryption. Anyone can decode it instantly — there is no key and no secret.
- A JWT's payload is Base64-encoded, not encrypted. Never put anything confidential in one.
- Basic HTTP authentication sends credentials as Base64. Over plain HTTP that is effectively sending them in the clear.
- Obfuscating a string with Base64 protects against nothing except a casual glance.
- Its actual purpose is transport safety: getting arbitrary bytes through channels that only reliably carry text.
Base64url, the URL-safe variant
Standard Base64 uses + and /, both of which have special meaning in URLs, and = which is a query-string separator. The base64url variant substitutes - for + and _ for /, and usually drops the padding entirely.
This is what JWTs use, and what you'll find in URL parameters and filenames. If a decode fails on a token that looks like Base64, check for - and _ characters — the string is base64url and needs converting first.
Frequently asked questions
- Is Base64 encryption?
- No — Base64 is an encoding, not encryption. It's fully reversible by anyone and provides no confidentiality; it's meant for safely representing data as text, not for hiding it.
- Why does Base64 output end with = or == sometimes?
- The = characters are padding, added when the input length isn't a multiple of 3 bytes, so the encoded output aligns to a valid 4-character block boundary.
- Can this encode non-text data like images?
- This tool is built for text input/output. For encoding binary files like images, use the dedicated Image to Base64 converter instead.
- What is base64url and how is it different?
- A URL-safe variant that replaces + with - and / with _, and usually omits the = padding, so the result can sit in a URL or filename unescaped. JWTs use it.
- Why does my decoded text show strange characters?
- Usually a character-encoding mismatch. Base64 decodes to bytes; those bytes then need interpreting as UTF-8. If the original was encoded from a different character set, the result will be garbled.