How to use
- Type or paste text to encode, or a Base64 string to decode, into the input box.
- Press Encode or Decode. Tick URL-safe output if the result goes into a URL or a JWT-style token.
- Copy the result. If decoding fails, the message says whether the input is not Base64 or not valid UTF-8 text.
Examples
Hello
→ SGVsbG8=Encode. The = at the end is padding.
안녕
→ 7JWI64WVEncode. Each Korean character is 3 bytes in UTF-8, so 6 bytes become 8 Base64 characters.
SGVsbG8
→ HelloDecode. Missing padding is accepted.
How it works
Text is first converted to bytes with UTF-8, then each group of 3 bytes is written as 4 characters from the alphabet A-Z, a-z, 0-9, + and /. If the last group is short, = characters pad it out.
Going through UTF-8 first is what makes non-English text work. The browser’s plain btoa function only handles single-byte characters, so text such as Korean fails without this step.
Decoding reverses the process. Whitespace in the input is ignored, URL-safe characters are converted back to + and /, missing padding is added, and the resulting bytes must form valid UTF-8 text.
Sources
Frequently asked questions
- Is Base64 encryption?
- No. Base64 is only a way to write bytes as text. Anyone can decode it, so never use it to protect secrets.
- Why is the Base64 text longer than the original?
- Base64 turns every 3 bytes into 4 characters, so the output is about one third longer than the input.
- What is URL-safe Base64?
- It replaces + with - and / with _, and usually leaves out the = padding, so the text can be used in URLs and file names without escaping. The decoder accepts both forms.
- Why does decoding say the bytes are not valid UTF-8?
- The input is valid Base64, but the bytes it contains are not text, for example an image or a compressed file. This tool decodes to text only.
- Is my text uploaded?
- No. Encoding and decoding run in your browser and the text is never sent to a server.