01000011Base64 Encode and Decode
Type or paste text on the left to encode it; paste Base64 on the right to decode it. Handles any language, URL-safe Base64 and missing padding.
How Base64 regroups bits
Base64 takes the bits of your data 6 at a time instead of 8. Six bits can count from 0 to 63, and each of those 64 values has a printable character. Step through it with a short word.
011000010111010001000016Q1101105420001015F110100520Cut into 6-bit groups, each number picks a character from A–Z, a–z, 0–9, + and /. Three bytes (24 bits) always make exactly four characters, which is why Base64 grows by a third.
Where you meet Base64
- Email attachments — MIME encodes files in Base64 because the original email system only carried 7-bit text.
- Data URIs — small images inlined in HTML or CSS as
data:image/png;base64,…. See image to Base64. - HTTP Basic auth —
Authorization: Basic dXNlcjpwYXNzis justuser:passin Base64, which is why it must only be sent over HTTPS. - JSON Web Tokens — the header and payload are URL-safe Base64. The JWT decoder reads them for you.
The alphabet and padding rules are defined in RFC 4648, which also defines Base32 and Base16 (hex).
Questions people ask
Is Base64 encryption?
No. Base64 is an encoding with a public alphabet and no key, so anyone can decode it instantly. Never use it to hide passwords or secrets. It exists to carry binary data safely through systems that only handle text.
Why is Base64 output longer than the input?
Base64 turns every 3 bytes into 4 characters, so the result is about 33% larger (plus padding). Each character carries only 6 bits of data instead of 8.
What do the = signs at the end mean?
They are padding. When the input length is not a multiple of 3 bytes, one or two = characters are added so the output length is a multiple of 4. Many decoders, including this one, accept Base64 with the padding removed.
What is URL-safe Base64?
Standard Base64 uses + and /, which have special meanings in URLs. The URL-safe variant from RFC 4648 swaps them for - and _ and usually drops the padding. JWTs use this form.
Why does btoa() fail on accented characters?
JavaScript’s btoa only accepts characters in the Latin-1 range. This tool first converts text to UTF-8 bytes with TextEncoder, so any language and emoji encode correctly.