What is Base64?
Base64 is an encoding that turns binary data into ASCII text using 64 printable
characters (A–Z, a–z, 0–9, plus + and /). It's used
to safely embed binary content (images, signatures, file uploads) in places
that only accept plain text — like JSON payloads, HTML data: URIs,
email attachments (MIME), and JWT tokens.
How to use this tool
- Pick Encode to turn text into Base64, or Decode to go the other way.
- Paste your input. The output updates as you type — no submit button needed.
- Click Copy to grab the result.
Is my data private?
Yes. Encoding and decoding happen entirely in your browser using the built-in
btoa / atob primitives with a UTF-8 layer for
non-ASCII text. Nothing is sent to a server. You can verify by opening DevTools
→ Network tab.
Common use cases
- Decoding the payload of a JWT (the middle segment is Base64-URL encoded).
- Embedding a small image as a
data:URI in CSS or HTML. - Inspecting API responses where binary blobs are encoded as Base64.
- Encoding HTTP Basic Auth credentials (
username:password).
URL-safe Base64 (Base64URL)
Standard Base64 uses + and /, which have special
meaning in URLs and filenames. The Base64URL variant
(RFC 4648 §5) swaps them for - and _ and usually
drops the trailing = padding. This is the form used in JWTs,
OAuth tokens, and anywhere a value rides in a query string or path. If a token
decodes fine in one tool but errors in another, a standard-vs-URL-safe mismatch
is the usual culprit.
Is Base64 the same as encryption?
No — and this is the most important thing to understand. Base64 is encoding, not encryption: it's fully reversible by anyone, with no key. It scrambles nothing and protects nothing. Never use it to "hide" passwords, API keys, or personal data. It exists only to make binary data survive text-only transport, not to keep secrets.
Why does my decoded text look like garbage?
Three common reasons: (1) the input wasn't actually Base64 to begin with; (2) it was binary (an image or compressed blob), so the bytes aren't printable text; or (3) it was URL-safe Base64 decoded as standard, or vice versa. For non-ASCII text, also confirm both ends agree on UTF-8 — this tool encodes and decodes UTF-8 correctly, but some older tools mangle multi-byte characters.
Do I need the = padding at the end?
The = characters pad the output to a multiple of four. Most
decoders (including this one) accept input with or without padding, but some
strict parsers reject unpadded input. When in doubt, keep the padding for
standard Base64 and omit it for Base64URL, which is the convention each expects.