Skip to main content

Base64 encoder and decoder

Paste text or drop a file to get Base64; paste Base64 to get the bytes back. URL-safe alphabet, MIME wrapping and data:URI prefixes are handled, and a binary result is offered as a download. Everything is computed in the page.

runs in your browser · the file never leaves your device

Drop any file here, or click to pick one

    

How to use it

  1. Pick the mode: Encode (text or file → Base64) or Decode (Base64 → text or file).
  2. Paste into the left pane or drop a file on the dropzone — the result appears as you type, and Run recomputes it by hand.
  3. When encoding, tick URL-safe if the string goes into a link or a JWT, and wrap at 76 when you need the MIME or PEM shape.
  4. When decoding, a data:…;base64, prefix is stripped for you. A binary result is described by size and first bytes, with Download as file next to it.
  5. Swap sends the result back into the input — the quick way to check that a round trip survives.

What the tool does

Base64 writes arbitrary bytes with 64 printable characters: Latin letters, digits, + and / (or - and _ in the URL-safe variant). Three bytes become four characters, so encoded data always runs 33 to 37 percent longer than the original. The encoder here takes text, which is turned into UTF-8 bytes first, so accented letters, emoji and CJK characters survive, or a file of any type — an image, a PDF, a font, an archive.

The decoder goes the other way and deals with the shapes Base64 arrives in: it drops newlines and spaces, restores stripped = padding, accepts the URL-safe alphabet and cuts off a data:image/png;base64, prefix. When the decoded bytes are not text, you get the format recognised by its signature — PNG, JPEG, GIF, WebP, PDF, ZIP, GZIP — and a download button, instead of a screen of replacement characters.

Where Base64 turns up at work

  • Data URI — images and fonts inlined into HTML or CSS: <img src="data:image/png;base64,iVBOR…">. Paste one in and the tool hands the file back.
  • Basic Auth: the header Authorization: Basic bG9naW46cGFzcw= is login:pass in Base64. Not encryption, just notation, and one paste tells you what is in the header.
  • JWT, OAuth state, signed tracker links use the URL-safe variant without = so the string can sit in an address untouched.
  • Postbacks and affiliate network APIs sometimes carry the payload in Base64 to avoid escaping JSON inside a URL.
  • Email: MIME stores attachments in lines of 76 characters, which is what the wrapping checkbox is for.

Where people trip

Base64 is neither encryption nor compression: anyone decodes it in a second, and the volume grows rather than shrinks. The standard alphabet contains +, / and =, which a URL turns into a space and %2F, which is why links use the URL-safe variant from RFC 4648 §5. Text is always encoded as UTF-8, so a string produced from a legacy codepage — Windows-1251, Shift_JIS — decodes into the wrong letters; the bytes are fine, the reading is not, and the fix is to download the result and open it with the right encoding.

The ceiling on size is the memory of your tab. Files up to 20 or 50 MB encode in seconds, and the Base64 string then runs a third longer than the file, at which point pasting it anywhere is already awkward — take the download instead.

Questions

Are my files and text uploaded?

No. Both directions run in JavaScript in the page, and files are read locally through FileReader. Cut the network after the page loads and the tool keeps working.

How do I decode Base64 into a file — an image, a PDF?

Switch to Decode and paste the string, with or without a data:URI prefix. If the result is binary, the format is read from the first bytes and Download as file appears with the matching extension.

How does URL-safe Base64 differ from the standard one?

The URL-safe variant swaps + and / for - and _, and usually drops the = padding, so the string goes into an address or a file name without percent-encoding. The decoder recognises both alphabets on its own.

Why does the decoded text come out wrong?

The bytes are read as UTF-8, the standard for the web and for JSON. If the source text was in a legacy single-byte encoding, the same bytes mean different letters: download the result and open it in an editor set to that encoding.

Is Base64 encryption?

No. It is a reversible way of writing bytes with printable characters, with no key and no secret. The login and password in a Basic Auth header, or a token in a link, are readable by anyone who cares — protecting data takes TLS and real cryptography.

Project sponsors

Companies that keep this analytics open