Skip to content

Runs entirely in your browser. Nothing you paste leaves this page.

Free / No sign-up

Base64 encoder and decoder.

Encode and decode Base64 or Base64URL with full UTF-8 support, or turn an image or any other file into a data URL. Free, and files are read locally, never uploaded.

Input type
Direction

Base64

SGVsbG8sIHdvcmxkLiDDnG7Dr2PDtmTDqSB0ZXh0IHN1cnZpdmVzIHRoZSByb3VuZCB0cmlwIOKckw==

58 B in, 80 B out. Base64 adds about a third to the size.

How to use it.

  1. 01

    Choose Text or File, then Encode or Decode.

  2. 02

    Type or paste text, or drop a file to convert it.

  3. 03

    Copy the result, the full data URL or the raw Base64.

What it does.

Everything this tool handles, all of it inside your browser tab.

  • Encode and decode text with full UTF-8 support
  • URL-safe Base64URL output with one tick
  • Decodes standard or URL-safe input, with or without padding
  • Ignores whitespace and line breaks, and accepts data: URLs
  • Any file to a data URL, up to 10 MB, by drag and drop
  • Image preview, plus separate copy for the data URL and raw Base64
  • Input and output sizes shown as you type
  • Switching direction moves the result into the input for round trips
  • Files are read locally and never uploaded

Worked examples.

  • Base64 encode a string

    Hello, World!
    
    > SGVsbG8sIFdvcmxkIQ==

    13 bytes in, 20 characters out. The == shows the last group held only one byte.

  • Base64 encode UTF-8 text with accents and emoji

    café ☕
    
    > Y2Fmw6kg4piV

    é is two UTF-8 bytes and ☕ is three. btoa("café ☕") would throw an InvalidCharacterError instead.

  • Base64 vs Base64URL output

    👍
    
    Base64:    8J+RjQ==
    Base64URL: 8J-RjQ

    Same four bytes. Base64URL swaps + for - (and / for _) and drops the padding so the value is URL-safe.

  • Encode an image to a Base64 data URL

    logo.png (image/png)
    
    > data:image/png;base64,iVBORw0KGgo...
    
    <img src="data:image/png;base64,iVBORw0KGgo..." alt="Logo">
    .icon { background-image: url("data:image/png;base64,iVBORw0KGgo..."); }

    File signatures show up at the start: PNG data begins iVBORw0KGgo, JPEG /9j/, GIF R0lGOD and PDF JVBERi0.

  • HTTP Basic authentication header

    user:pass
    
    > dXNlcjpwYXNz
    
    Authorization: Basic dXNlcjpwYXNz

    Basic auth is just Base64 of username:password. It is readable by anyone who sees the header, so only send it over HTTPS.

How Base64 encoding works

Base64, defined in RFC 4648, represents any bytes using 64 characters that survive text-only systems: A-Z, a-z, 0-9, + and /. It takes the input three bytes (24 bits) at a time and splits them into four 6-bit groups, each of which picks one character. "Man" becomes TWFu.

When the input length is not a multiple of three, the last group is padded with = so the output length stays a multiple of four: one leftover byte gives two characters and ==, two leftover bytes give three characters and =. The output is always about a third larger than the input, exactly 4 characters for every 3 bytes, rounded up.

Base64 exists so binary data can travel through channels built for text: JSON and XML payloads, email attachments (MIME), HTML and CSS data URLs, HTTP Basic authentication and environment variables.

Base64 vs Base64URL

The standard alphabet uses + and /, which have special meanings in URLs and file paths. Base64URL (RFC 4648, section 5) replaces them with - and _ and usually drops the = padding, so the value can sit in a query string, a filename or a cookie without further escaping.

Every part of a JWT is Base64URL, which is why the JWT decoder can read them. Tick URL-safe when encoding to get Base64URL. When decoding, this tool accepts either alphabet and restores missing padding automatically. If you must put standard Base64 in a URL, percent-encode it with the URL encoder, because an unescaped + is often read as a space.

Why UTF-8 matters (and why btoa fails)

Base64 encodes bytes, not characters, so text must first be turned into bytes. The browser's built-in btoa assumes each character is a single Latin-1 byte. It throws an InvalidCharacterError for anything above U+00FF, such as emoji, Chinese, Arabic or Devanagari, and it encodes é as one byte (6Q==) where a UTF-8 server expects two (w6k=).

This tool encodes text as UTF-8 first, the same as TextEncoder, Node.js Buffer, Python's str.encode() and virtually every API, so any language round-trips exactly. When decoding, it insists on valid UTF-8 and tells you if the bytes are something else.

Convert an image or file to a Base64 data URL

Switch to File and drop an image, PDF, font or any other file up to 10 MB. The browser reads it locally with FileReader and produces a data URL in the RFC 2397 format, data:<media type>;base64,<data>. Copy the whole data URL for an img src or a CSS url(), or copy only the raw Base64 for a JSON field or an API that wants the bare string. Images get a small preview so you can check you picked the right file.

Inlining saves an HTTP request but makes the file about 33% larger, cannot be cached separately, and makes the HTML or CSS file that contains it heavier, which delays everything else in that file. It suits tiny icons and one-off images. For anything bigger, a normal image file served from a CDN is usually faster; our guide to Core Web Vitals explains why it matters for LCP.

The decoder is for text. If you paste the Base64 of an image or PDF, it decodes the bytes and tells you they are not UTF-8 text rather than showing garbage.

Common Base64 errors and how to fix them

"Invalid character" errors usually mean the value contains something outside the alphabet: quotes copied from code, a data: prefix in a decoder that does not expect it, or URL-escaped sequences such as %2B. This tool strips a data: URL prefix and all whitespace, including the line breaks MIME inserts every 76 characters, before decoding.

A value whose length leaves a remainder of 1 when divided by 4 is truncated and cannot be decoded. Text that decodes to more Base64 was encoded twice; decode again. Text that turns into odd symbols such as é was decoded as Latin-1 instead of UTF-8 somewhere along the way.

How to Base64 encode and decode in code

In JavaScript, turn text into UTF-8 bytes first: new TextEncoder().encode(text) gives the bytes, and btoa on a binary string of those bytes gives Base64, which is what this tool does. Recent browsers and runtimes also provide Uint8Array.prototype.toBase64() and Uint8Array.fromBase64(), which convert bytes directly and can use the Base64URL alphabet; check support if you target older browsers. In Node.js, Buffer.from(text).toString("base64") and Buffer.from(value, "base64") are the standard approach, and "base64url" works as an encoding name too.

Python's base64 module has b64encode and b64decode, plus urlsafe_b64encode and urlsafe_b64decode for the URL-safe alphabet. They take and return bytes, so call .encode() and .decode() at the edges. On the command line, base64 encodes a file and base64 --decode reverses it. Whatever the language, decode with the same alphabet you encoded with, and add back missing padding if the value came from a URL or a JWT.

Base64 is not encryption

Anyone can decode Base64 instantly; it hides nothing. HTTP Basic authentication sends user:password in Base64, which is why it is only safe over HTTPS. Kubernetes Secrets are stored as Base64 too, so treat the manifest as sensitive.

For confidentiality you need encryption. To check integrity or fingerprint a file, use a hash such as SHA-256 from the hash generator. Like every tool on this page, the encoder runs in your browser, so the text and files you convert never leave your device.

Questions, answered

Something else on your mind? Ask a consultant and get a reply within one business day.

Is Base64 encryption?

No. Anyone can decode it instantly. Use it to move data safely through text-based systems, never to hide secrets.

Are my files uploaded?

No. Files are read with the browser's FileReader and converted in memory. Nothing leaves your device.

Why does Base64 make data bigger?

Every 3 bytes become 4 characters, so the output is about 33% larger, plus up to two padding characters. MIME email adds line breaks on top of that.

What does the = at the end of Base64 mean?

It is padding. It keeps the length a multiple of four when the input is not a multiple of three bytes. Base64URL usually leaves it off, and this decoder works either way.

What is the difference between Base64 and Base64URL?

Base64URL replaces + with - and / with _, and normally omits padding, so values can go in URLs and filenames unescaped. The data is the same; only the alphabet differs.

Why does btoa throw "InvalidCharacterError"?

btoa only accepts characters up to U+00FF. Encode the text to UTF-8 bytes first, for example with TextEncoder, or use this tool, which does that for you.

Why does decoding say the result is not text?

The Base64 decoded to bytes that are not valid UTF-8, which usually means it encodes a file such as an image or PDF rather than text.

When should I inline images as data URLs?

For small icons or images used once, it saves a request. For anything larger than a few kilobytes, a normal image file is usually better because it can be cached and is not inflated by a third.

How do I decode Base64 on the command line?

On Linux and macOS, run base64 --decode on a file or piped input. In PowerShell, use [Text.Encoding]::UTF8.GetString([Convert]::FromBase64String($value)).

Is there a size limit?

Text has no fixed limit beyond your browser's memory. Files are limited to 10 MB, because larger data URLs make the page sluggish and are rarely a good idea to inline.

More free tools.

All tools

Need tooling like this inside your product?

We build internal tools, developer platforms and APIs. Tell us what your team keeps doing by hand.