0
Input Characters
0
Input Bytes (UTF-8)
0
Output Characters
Encode
Current Mode
⚙️ Options
📝 Plain Text Input 0 characters
✅ Base64 Output 0 characters

What Is Base64?

Base64 is a binary-to-text encoding scheme that represents binary data using only 64 printable ASCII characters: A–Z, a–z, 0–9, +, and /, with = used for padding. It's designed to safely transmit data over channels that only support text — like email (MIME), JSON, XML, or URLs.

How Base64 Works

Every 3 bytes (24 bits) of input are split into four 6-bit groups. Each 6-bit group maps to one of the 64 Base64 characters. If the input isn't a multiple of 3 bytes, the last group is padded with = characters. That's why Base64 output is always about 33% larger than the original binary.

Input:  "Man"
Bytes:  01001101 01100001 01101110  (3 bytes)
6-bit:  010011 010110 000101 101110
Index:  19     22     5      46
Base64: T      W      F      u
Output: "TWFu"

How to Use This Tool

  • Choose a mode: Encode (text → Base64) or Decode (Base64 → text).
  • Type or paste your input into the first box.
  • Click "Encode to Base64" or "Decode from Base64" — the result appears instantly.
  • Copy or download the output as a `.txt` file.

Auto-detect mode is enabled by default. When on, the tool looks at your input and switches modes automatically if it looks like Base64.

URL-Safe Base64

Standard Base64 uses + and /, which conflict with URL and filename syntax. URL-safe Base64 (defined in RFC 4648) replaces them:

  • + → -
  • / → _
  • Padding = is often removed entirely

Enable the URL-safe checkbox to use this variant — ideal for JWT tokens, query strings, and safe filenames.

Common Use Cases

  • Email attachments — MIME encoding uses Base64 for attachments.
  • Data URIs — embed images directly in HTML/CSS: data:image/png;base64,...
  • API payloads — JSON often uses Base64 to carry binary data safely.
  • JWT tokens — the header and payload are URL-safe Base64-encoded JSON.
  • Basic Auth headers — username:password is Base64-encoded in HTTP headers.
  • Encoding API keys — safe storage of credentials in config files.
  • Obfuscating text — a simple way to make text unreadable at a glance (not secure, but useful).

Security Note

Base64 is NOT encryption. It's an encoding — anyone can decode it trivially. Never use Base64 to protect passwords, API keys, or sensitive data. For actual security, use AES, RSA, or another proper encryption algorithm.

Related Tools

Privacy Note

All encoding and decoding happens in your browser. Your input is never uploaded to a server, never stored, and never shared. Files you upload are read locally using the FileReader API and never leave your device.