Technology & Developers
Free Base64 Encoder and Decoder
Encode text to Base64 or decode it back, including Unicode and emoji.
Free to useNo sign-up requiredNo watermarkRuns in your browser
This free Base64 tool encodes text to Base64 and decodes it back, in both directions, with results appearing as you type. It handles any language - Arabic, Hindi, Chinese and emoji all round-trip correctly, which many browser-based encoders get wrong.
There is also a URL-safe mode that swaps the + and / characters for - and _ and drops the padding, which is what you need for tokens, query strings and filenames.
How this tool works
Pick a direction
Text to Base64, or Base64 back to text.
Paste your input
The result appears immediately. Decoding accepts padded, unpadded and URL-safe input without you having to say which.
Copy the result
Or press "Send result back" to feed it into the opposite direction and confirm the round trip.
How it works
Base64 represents binary data using 64 printable characters, so it can travel safely through systems that only handle text - email bodies, JSON payloads, data URLs and HTTP headers.
Encoding groups the input into three-byte blocks and rewrites each as four Base64 characters. That is why Base64 output is always about a third larger than the input, and why it ends with one or two = signs when the length is not a multiple of three.
Text is UTF-8 encoded before it is converted. Without that step, any character above the Latin-1 range throws an error - which is why some tools simply fail on Arabic text or an emoji.
Decoding restores the padding automatically and accepts the URL-safe alphabet, so you can paste a token straight out of a URL without editing it first.
Base64 is not encryption
This is the single most important thing to understand about Base64, and it is misunderstood constantly. Base64 is an encoding, not a cipher. There is no key and no secret. Anyone who sees the string can decode it in a second - with this page, in fact.
It is for making binary data survive a text-only channel. If you need something kept private, encrypt it. Base64-encoding a password protects nothing at all.
Where you will meet it
- Data URLs: an image embedded directly in HTML or CSS as data:image/png;base64,…
- HTTP Basic authentication, where username:password is Base64-encoded in the header - encoded, and therefore not secure without HTTPS.
- JSON Web Tokens: the header and payload are URL-safe Base64, which is why you can read a JWT payload without any key.
- Email attachments, which have been Base64-encoded since long before the web.
- Configuration files and Kubernetes secrets, where values are frequently stored Base64-encoded for transport reasons rather than for security.
Worked examples
Hello
"Hello" encodes to "SGVsbG8=". The trailing = is padding, because five bytes is not a multiple of three.
Reading a JWT payload
Take the middle section of a JWT, between the dots, and decode it as URL-safe Base64 to see the claims as JSON.
Non-Latin text
Arabic and emoji encode and decode correctly here because the text is UTF-8 encoded first.
Frequently asked questions
Is this Base64 tool free?
Yes, free with no sign-up and no limit on how much you encode or decode.
Is my data sent to a server?
No. Everything runs in your browser, so whatever you paste never leaves your device. That matters here more than on most tools - people paste API keys, tokens and customer records into encoders and formatters without thinking about it.
Is Base64 secure?
No. It is an encoding, not encryption - anyone can decode it instantly, with no key. Never use it to protect a secret. If you need confidentiality, encrypt the data.
What is URL-safe Base64?
A variant that replaces + with - and / with _, and usually drops the = padding, so the result can appear in a URL, a query string or a filename without being escaped. JWTs use it.
Why does my Base64 end in = signs?
Padding. Base64 works in three-byte groups; when the input does not divide evenly, one or two = characters are added to complete the final group. Decoders here accept the string with or without them.
Does it work with emoji and other languages?
Yes. The text is UTF-8 encoded first, so Arabic, Hindi, Chinese, Cyrillic and emoji all encode and decode without loss.
Guides for this tool
Is it safe to decode a JWT online?
What decoding a JWT online actually does with your token, why a production auth token deserves caution, and how to check whether a decoder tool is genuinely processing it locally.
How to validate JSON online for free
Check whether a piece of JSON is valid and find exactly where it breaks - free, no signup, and processed entirely in your browser rather than sent to a server.
How to generate a SHA-256 checksum online
Generate a SHA-256, SHA-384 or SHA-512 hash from text, entirely in your browser - plus why MD5 and SHA-1 are no longer the right choice for anything security-related.
