Free Online Base64 Encoder & Decoder

Help

Full guide

What is Base64?

Base64 is a binary-to-text encoding. It converts bytes (binary data) into a limited set of readable ASCII characters:

  • A-Z, a-z, 0-9, +, / (and = padding)

Because the output is plain text, Base64 is often used in places where you can only safely transmit text, for example:

  • JSON / XML payloads
  • URLs (usually with Base64URL variant)
  • Email (MIME)
  • Embedding small files in text formats

How the 3-to-4 mapping actually works

The name comes from the alphabet size: 64 characters can each represent 6 bits of data (2⁶ = 64). The encoder works in groups:

  1. Take 3 bytes of input = 24 bits.
  2. Split them into four 6-bit groups.
  3. Map each 6-bit value (0–63) to one alphabet character.
"Man" = 0x4D 0x61 0x6E  (3 bytes, 24 bits)
 010011 010110 000101 101110  →  19, 22, 5, 46  →  T, W, F, u
Result: "TWFu"

When the input length is not a multiple of 3, the last group is padded:

  • 2 bytes left → one = (16 bits of data carried in 3 characters)
  • 1 byte left → two == (8 bits of data carried in 2 characters)

That is the entire origin of the = you see at the end of many strings — it exists purely so the output length is always a multiple of 4.

Why output is always 33% larger

Four 6-bit characters hold the same 24 bits as three bytes — but when transmitted, each character occupies a full 8-bit byte. So 3 bytes become 4 bytes: a fixed +33.3% overhead. This is why Base64-encoding a 3 MB attachment produces a 4 MB string, and why you should never Base64 large assets that will be transferred.

Base64 encodes bytes, not characters

The input to Base64 is always a byte sequence. When you encode text, the text is first converted to bytes using some encoding — virtually always UTF-8 on the web. "é" is 2 bytes in UTF-8 but 1 character; encoding tools that assume different encodings (or operate on UTF-16 code units) will disagree. This is also why decoding binary data (images, ZIP files) as text yields gibberish: the bytes were never UTF-8 text to begin with.

What this tool does

On the Base64 page (/en/base64) you can:

  • Encode text into Base64
  • Decode Base64 back to text
  • Quickly verify whether a string looks like Base64

How to use (examples)

Encode a string

Input:

hello world

Output (Base64):

aGVsbG8gd29ybGQ=

Decode a Base64 string

Input:

aGVsbG8gd29ybGQ=

Output:

hello world

Data URIs: Base64 in the wild

The most common place developers meet Base64 today is the data URI, which embeds a file inline:

<img src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUg..." />

When this pays off:

  • ✅ Small images (icons, logos) under ~2-4 KB — one fewer HTTP request
  • ✅ Single-file deliverables: HTML email, standalone reports, offline documents
  • ✅ Dynamically generated images from canvas, without a server round trip

When it backfires:

  • ❌ Large images — 33% size inflation with no compression benefit
  • ❌ Repeated across pages — the browser cannot cache the inlined asset independently
  • ❌ Critical CSS paths — a large base64 blob in CSS blocks parsing for all users

A frequently overlooked point: HTTP/2 and HTTP/3 multiplexing has removed much of the "one request per asset" cost that made inlining attractive. Measure before inlining.

Common pitfalls

1) Base64 is not encryption

Base64 does not protect your data. It only changes representation — decoding requires no secret. Anyone who intercepts a Base64 string reads it instantly.

If you need confidentiality, use real encryption (e.g. AES-GCM) and keep keys secure.

2) Padding and newlines

  • Many Base64 strings end with = or ==.
  • Some systems insert line breaks every 76 characters (email/MIME). You may need to remove whitespace before decoding.

3) Base64 vs Base64URL

When you put Base64 into URLs, + and / may be problematic.

Base64URL typically:

  • Replaces + with -
  • Replaces / with _
  • Removes = padding

If you see those characters, the input may be Base64URL rather than standard Base64. JWTs are the biggest consumer: all three segments of a JWT use Base64URL.

Where Base64 appears in real systems

ContextExample
HTTP Basic AuthAuthorization: Basic dXNlcjpwYXNz
JWTEach dot-separated segment is Base64URL
Email attachmentsMIME Content-Transfer-Encoding: base64
Data URIsdata:image/png;base64,...
Embedded keys/certsPEM files wrap Base64 between -----BEGIN----- markers
Git objectsInternal storage of blobs, commits, tags

Privacy & security

  • This tool is designed to run client-side (in your browser).
  • Your input should not be uploaded.

Even so:

  • Avoid pasting passwords, private keys, or personal data on public/shared computers.
  • If the data is highly sensitive, prefer offline tools.