Base64 Encode & Decode Online — Text, Files and Data URLs
Encode text or files to Base64 and decode back, with correct UTF-8 handling and data-URL output. Nothing leaves your browser.
UGluZSAmIEJpcmNoIOKAlCBCYXNlNjQgZW5jb2RlcyBieXRlcywgbm90IGNoYXJhY3RlcnMuIMOJbW9qaXMgd29yazog8J+Msg==
Runs entirely in your browser. Nothing you enter is sent to us or stored. Embedding assets, signing requests or wiring up an API that moves encoded payloads? Our developers build that.
Found a problem, or something that could be better? We read every message and we fix things quickly.
This free Base64 encoder and decoder converts text and files to Base64 and back, in your browser. It handles UTF-8 correctly, so accented characters, Chinese text and emoji round-trip intact, which is where most quick online converters silently fail. Drop in an image or a font to get a data URL you can paste straight into CSS or HTML.
Base64 is not encryption and not compression; it is a way to carry binary data through channels that only accept text, such as JSON, email and URLs, at the cost of about 33 percent more bytes. Knowing that is most of knowing when to use it, and the notes below cover the rest.
How to use
- Choose Encode or Decode. For encoding, type or paste text; the Base64 appears as you type.
- Turn on URL-safe when the value will go in a URL or a JWT: + and / become - and _, and padding is dropped.
- To encode a file, pick it under “Encode a file”. Copy the raw Base64 or the complete data URL.
- To decode to a file, paste Base64 or a data URL in Decode mode and press Decode to file; the browser downloads it with the right type.
- Check the size line: if the encoded output is heading into megabytes, a plain file reference is almost always the better design.
Frequently asked questions
Is Base64 secure? Can I use it to hide data?
No. Base64 is an encoding, not encryption: anyone can decode it instantly, including with this page. It exists to make binary data safe to carry as text. If you need confidentiality, encrypt first and then Base64 the ciphertext if a text channel requires it.
Why does my decoded text show strange characters?
Usually because the original was not UTF-8, or because the Base64 was produced by a tool that encoded each character's code point instead of its UTF-8 bytes (the classic btoa() bug). This tool always encodes and decodes UTF-8 bytes. If the source was Latin-1 or UTF-16, the bytes are still correct; only the text rendering differs.
What is URL-safe Base64?
Standard Base64 uses + and /, both of which have meaning inside URLs, and pads with =, which URL encoders mangle. The URL-safe variant (RFC 4648 section 5) swaps them for - and _ and usually omits padding. JWTs, OAuth state values and many API tokens use it. The decoder here accepts both forms.
Should I embed images as Base64 data URLs?
For tiny assets (icons under a few kilobytes, a small inline SVG, a font subset) a data URL saves a round trip and is worth it. For anything larger, no: the file grows by a third, it cannot be cached separately from the page, and it blocks parsing of the HTML or CSS it lives in. A normal file reference wins above roughly 5 to 10 KB.
Is anything uploaded?
No. Text is converted with the browser's TextEncoder and btoa/atob, and files are read locally with the File API. Nothing is sent to a server.
How Base64 works, in one paragraph
Every three bytes of input (24 bits) are split into four 6-bit groups, and each group is written as one of 64 characters: A–Z, a–z, 0–9, + and /. That is why output length is always a multiple of four and roughly 4/3 of the input, and why = padding appears when the input is not a multiple of three bytes. Decoding reverses it exactly; there is no loss.
Where you meet Base64
• HTTP Basic authentication: the Authorization header carries user:password in Base64 (not encrypted, which is why it needs HTTPS).
• JWTs: header and payload are URL-safe Base64 JSON; decode one with our JWT decoder.
• Email attachments (MIME) and embedded images in HTML email.
• Data URLs in CSS and HTML, and image fields in some JSON APIs.
• Binary values in JSON and XML, which have no native byte type.
Related free tools
- JSON Formatter — Pretty-print, minify and validate JSON, with parse errors located by line and column. In your browser, no upload.
- JWT Decoder — Decode a JWT's header and payload, read the expiry in plain language, and verify an HMAC signature. Tokens never leave your browser.
- Image Converter — Convert between AVIF, HEIC, TIFF, PNG, JPG, WebP, GIF, BMP and SVG. Most conversions never leave your browser.