Skip to content
MoneyDeck

Base64 Encode / Decode

Convert text to Base64 and back instantly, with full UTF-8 and URL-safe support

Updated · Free, no signup

Uses - and _ instead of + and / and drops = padding. Decoding accepts both alphabets automatically.

Result

SGVsbG8sIFdvcmxkIQ==

Status

Encoded

Input characters

13

Decoded data size

13 bytes

Number of raw bytes represented (UTF-8 bytes of the text).

Output characters

20

  • 13 bytes became 20 Base64 characters — about 54% larger, since every 3 bytes are written as 4 characters.

About the Base64 Encode / Decode

This Base64 encoder and decoder turns any text into Base64 and converts Base64 strings back into readable text. Text is first converted to UTF-8 bytes, so accented letters, non-Latin scripts and emoji round-trip correctly — a common failure point of quick btoa() snippets. Switch on URL-safe mode to get base64url output (using - and _ with no = padding), the variant used in JWTs, URL parameters and file names.

Developers use it to inspect JWT segments, build HTTP Basic Authorization headers, embed small payloads in JSON or data URIs, and debug API responses that arrive Base64-encoded. When decoding, whitespace and line breaks are ignored and both the standard and URL-safe alphabets are accepted, with or without padding.

Everything runs locally in your browser; nothing you paste is uploaded. Remember that Base64 is an encoding, not encryption — anyone can decode it, so never rely on it to hide passwords or secrets.

How to use the base64 encode / decode

  1. 1Choose Encode to turn text into Base64, or Decode to turn Base64 back into text.
  2. 2Paste or type your input in the box.
  3. 3For JWTs, URLs or file names, switch on URL-safe output.
  4. 4Copy the result with the copy button.
  5. 5If decoding fails, check for characters outside the Base64 alphabet or a truncated string.

Formula and method

Output length = 4 × ⌈bytes ÷ 3⌉ (with padding)

Base64 reads the input three bytes (24 bits) at a time and splits those bits into four 6-bit groups. Each 6-bit value (0–63) is mapped to a character from the alphabet A–Z, a–z, 0–9, + and /. When the final group has only one or two bytes, the output is padded with = so the length is always a multiple of four.

Text is converted to UTF-8 before encoding, so a character such as ü (2 bytes) or 👋 (4 bytes) contributes more than one byte. The base64url variant defined in RFC 4648 §5 swaps + for - and / for _ and usually omits padding so the result is safe in URLs and file names. Decoding reverses the process and then interprets the bytes as UTF-8.

bytes
Number of UTF-8 bytes in the input text
⌈ ⌉
Round up to the next whole number

Worked examples

Encode "Hello, World!"

"Hello, World!" is 13 bytes. Four full 3-byte groups produce 16 characters, and the last single byte produces 2 characters plus "==" padding, for 20 characters in total: SGVsbG8sIFdvcmxkIQ==.

Decode a JWT header

The first segment of a JSON Web Token is base64url-encoded JSON. Decoding its 36 characters gives 27 bytes: {"alg":"HS256","typ":"JWT"}, which tells you the token is signed with HMAC-SHA256.

URL-safe encoding of "<<???>>"

Standard Base64 of these 7 bytes is PDw/Pz8+Pg== which contains / and + — both special in URLs. URL-safe mode swaps them for _ and - and drops the padding, giving PDw_Pz8-Pg.

Encode text with an accent and emoji

The 7 visible characters are 12 UTF-8 bytes (ü and ß take 2 bytes each and the emoji takes 4). Twelve bytes divide evenly into four 3-byte groups, so the output is 16 characters with no padding.

Frequently asked questions

Is Base64 encryption?+

No. Base64 is a reversible encoding that anyone can decode without a key. It makes binary data safe to send as text, but it provides no confidentiality — use real encryption such as AES for secrets.

Why does Base64 make data about 33% bigger?+

Every 3 bytes of input become 4 output characters, so the output is 4/3 the size of the input, plus up to two padding characters. Line breaks added by some tools (e.g. MIME every 76 characters) add a little more.

What is the difference between Base64 and base64url?+

base64url (RFC 4648 section 5) replaces + with - and / with _, and usually omits the = padding, so the output can go straight into URLs, cookies and file names. JWTs always use base64url.

What do the = signs at the end mean?+

They are padding. One = means the last group held 2 bytes, == means it held 1 byte. Padding keeps the length a multiple of 4; many decoders, including this one, accept input without it.

Why does my decoded text look like gibberish?+

The Base64 probably holds binary data such as an image, a compressed file or an encrypted blob rather than text. This tool shows non-UTF-8 results as hexadecimal bytes so you can still inspect them.

How do I create an HTTP Basic Authorization header?+

Encode "username:password" to Base64 and send it as "Authorization: Basic <result>". For example user:p@ssw0rd becomes dXNlcjpwQHNzdzByZA==. Only use Basic auth over HTTPS.

Related tools