Skip to content

Base64 Encoder & Decoder

Paste text or pick a file and instantly see it in Base64. It works the other way too: Base64 turns back into text, an image or any other file.

Text and files are never uploaded, everything runs in your browser.

How to use the tool

How to encode and decode Base64

  1. 1 At the top, choose whether you are working with text or a file. Text can be encoded or decoded. A file, such as an image or a PDF, can be encoded to Base64 or straight to a data URI.
  2. 2 For text, choose Encode or Decode and enter your text. The result appears instantly as you type.
  3. 3 Copy the result with the Copy button. The Swap button moves it into the input and reverses the direction, for example to double-check it.

What the tool handles on its own

  • when decoding, it recognizes both standard Base64 and base64url and adds any missing = signs at the end
  • it reads a whole data URI, including the file type, and ignores spaces and line breaks
  • it recognizes images, PDFs and archives, shows a preview for images and offers a download
  • if the text is not UTF-8, it tries Windows-1250, the older Central European Windows code page, and tells you
  • when encoding text, it also shows the base64url version below the result for URLs and JWT
  • everything is processed right in your browser, nothing is sent to a server

How to convert an image to Base64 and back

Images are the most common use for Base64. You can encode a small image and embed it right in HTML or CSS, with no separate file. And when you receive an image as a Base64 string, for example from an API, you can turn it back into a file here and save it.

From image to Base64

  1. 1 At the top of the tool, switch to File and choose a PNG, JPG, GIF, WebP or SVG image.
  2. 2 Select the Data URI format if you want to embed it in HTML or CSS, or Base64 for APIs and JSON.
  3. 3 Copy the result and paste it into an src attribute, the CSS background property or your own code.

From Base64 to an image or PDF

  1. 1 Switch to Text and choose Decode.
  2. 2 Paste the Base64 string or the whole data URI. The tool recognizes from the content whether it is a PNG, JPEG, GIF, WebP or PDF.
  3. 3 Images get a preview. Click Download file to save it with the right file extension.

How to read a JWT token

A JWT token looks like one long string, but it consists of three parts separated by dots. The first two are plain JSON encoded in base64url, so you can read them without any key. Paste each part into the tool separately:

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjMiLCJuYW1lIjoiSmFuYSIsImV4cCI6MTc2NzIyNTYwMH0.signature

Header
{"alg":"HS256","typ":"JWT"}

the signing algorithm and the token type

Payload
{"sub":"123","name":"Jana","exp":1767225600}

the user ID, name and expiry time

Signature
signature

a binary signature that the server verifies, not text

The exp value is the expiry time in seconds since January 1, 1970, here exactly midnight UTC on January 1, 2026. Anyone who has the token can read its payload, so never put passwords or other secrets in it.

How to extract an attachment from an email source

In the raw source of a message, every attachment is stored as a long block of Base64 after the Content-Transfer-Encoding: base64 header. In Gmail, open the source with Show original, in Outlook with View message source. Copy the block without the headers, paste it here, choose Decode and download the file. This helps when an attachment will not open in your email client or the client has blocked it.

Random key in Base64

Secret keys for APIs, encryption and signatures are often written as random bytes in Base64. Laravel, for example, stores its application key as APP_KEY=base64: followed by 32 random bytes. You can generate a key here too, using a cryptographically secure generator right in your browser.

Base64
base64url

In a terminal, the command openssl rand -base64 32 does the same. The generated key is never sent or stored anywhere.

All about Base64

What Base64 is and what it is for

Base64 is a way to write any data, even an image or a PDF, using just 64 common characters: uppercase and lowercase letters, digits and the + and / signs. Data written this way can travel anywhere only text is allowed, such as email attachments, JSON API responses, HTML or CSS. Every three bytes become four characters, so the result is about a third longer than the original data.

characters in the Base64 alphabet
64
every three bytes become four characters
3 → 4
how much longer the output gets
+33%
the standard that defines Base64
RFC 4648

Examples

This is how common text looks before and after encoding:

InputBase64
Short text Hello SGVsbG8=
Text with accents Café crème Q2Fmw6kgY3LDqG1l
HTTP Basic login user:password dXNlcjpwYXNzd29yZA==

How Base64 works, step by step

  1. 1 First, the text is converted to bytes. In UTF-8, plain English letters take one byte, accented letters such as é or č take two, and emoji take four.
  2. 2 Each byte has eight bits. The bits are lined up one after another and split into groups of six.
  3. 3 Each group of six bits is a number from 0 to 63, which maps to one character of the Base64 alphabet: 0 is A, 26 is a, 52 is 0, 62 is + and 63 is /.
  4. 4 If there are not enough bits left to fill the last group, it is padded with zeros. Then = characters are added to the end so the length is divisible by four.

How Base64 turns three bytes into four characters

Encoding the text Man in Base64 The three bytes of the text Man have 24 bits. They are split into four groups of 6 bits, which become the characters TWFu. The text Ma is padded with zeros and an = sign to TWE=. Characters (ASCII) Bits Groups of 6 bits Base64 M 77 a 97 n 110 0 1 0 0 1 1 0 1 0 1 1 0 0 0 0 1 0 1 1 0 1 1 1 0 19 T 22 W 5 F 46 u M 77 a 97 0 1 0 0 1 1 0 1 0 1 1 0 0 0 0 1 0 0 19 T 22 W 4 E = A-Z = 0-25 · a-z = 26-51 · 0-9 = 52-61 · + = 62 · / = 63

Base64 works on groups of three bytes. The letters M, a and n have the ASCII codes 77, 97 and 110.

Each byte has 8 bits, 24 bits in total.

The 24 bits are split into 4 groups of 6. Each group is a number from 0 to 63.

Each number is replaced with a character from the 64-character alphabet. 3 bytes become 4 characters, which is why Base64 is about a third longer.

When the last group is incomplete, as with the text "Ma", the third byte is missing.

There are only 16 bits, not enough for three full groups of 6.

The third group is filled up with two zero bits. No bits are left for the fourth one.

The missing group is written as =. It tells the decoder how many bytes were really there at the end.

The breakdown shows the first six bytes of your text.

Character Byte Bits
H7201001000
e10101100101
l10801101100
l10801101100
o11101101111
6-bit group Value Base64 character
01001018S
0001106G
01010121V
10110044s
01101127b
0001106G
111100608
=

= SGVsbG8=

The Base64 alphabet (character table)

Base64 uses exactly 64 characters. Each one stands for a number from 0 to 63, which is one group of six bits. The = sign is not part of the alphabet. It only pads the length at the end.

  1. 0 A
  2. 1 B
  3. 2 C
  4. 3 D
  5. 4 E
  6. 5 F
  7. 6 G
  8. 7 H
  9. 8 I
  10. 9 J
  11. 10 K
  12. 11 L
  13. 12 M
  14. 13 N
  15. 14 O
  16. 15 P
  17. 16 Q
  18. 17 R
  19. 18 S
  20. 19 T
  21. 20 U
  22. 21 V
  23. 22 W
  24. 23 X
  25. 24 Y
  26. 25 Z
  27. 26 a
  28. 27 b
  29. 28 c
  30. 29 d
  31. 30 e
  32. 31 f
  33. 32 g
  34. 33 h
  35. 34 i
  36. 35 j
  37. 36 k
  38. 37 l
  39. 38 m
  40. 39 n
  41. 40 o
  42. 41 p
  43. 42 q
  44. 43 r
  45. 44 s
  46. 45 t
  47. 46 u
  48. 47 v
  49. 48 w
  50. 49 x
  51. 50 y
  52. 51 z
  53. 52 0
  54. 53 1
  55. 54 2
  56. 55 3
  57. 56 4
  58. 57 5
  59. 58 6
  60. 59 7
  61. 60 8
  62. 61 9
  63. 62 +
  64. 63 /

Why Base64 ends with = or ==

Base64 works on data three bytes at a time. When fewer bytes are left at the end, the = sign fills the missing space. One leftover byte adds two = signs, two bytes add one, and three bytes add none. Some systems, such as JWT, leave out the = signs because the decoder can work out the length on its own.

T
VA==
Te
VGU=
Tes
VGVz
Test
VGVzdA==

How big will the Base64 be

Every three bytes become four characters, so the Base64 output is 4 × ⌈n ÷ 3⌉ characters long, where n is the number of bytes and the brackets mean rounding up. That makes it roughly 33% longer. In emails, Base64 is also wrapped into lines of 76 characters, each ending with CR LF, so an attachment grows by about 37%. Going the other way, a Base64 string of length d holds 3 × d ÷ 4 bytes, minus the number of = signs at the end.

Original fileBase64Base64 in an email (MIME)
1.00 KB1.34 KB1.37 KB
10.00 KB13.34 KB13.69 KB
100 KB133 KB137 KB
1.00 MB1.33 MB1.37 MB
10.00 MB13.33 MB13.68 MB

Base64 variants

All variants share the same first 62 characters. They differ in the last two characters, in padding and in whether the output is wrapped into lines.

VariantCharacters 62 and 63Padding =LinesWhere it is used
Standard Base64 (RFC 4648) + / yes no line breaks APIs, JSON, data URIs
base64url (RFC 4648) - _ usually not no line breaks JWT, OAuth, URLs, file names
MIME (RFC 2045) + / yes every 76 characters email attachments
PEM (RFC 7468) + / yes every 64 characters certificates and cryptographic keys

Base64 and base64url

Standard Base64 contains the characters +, / and =, which have their own meaning in URLs. The base64url variant uses - and _ instead and drops the trailing = signs. It is used by JWT tokens, OAuth and signed URLs, for example.

An image as a data URI

A data URI puts a file straight into HTML or CSS, for example <img src="data:image/png;base64,…">. It works well for small icons, because the browser does not have to download them separately. For larger images it is not worth it: they are a third bigger and the browser cannot cache them separately. Do not use data URIs in emails, as Gmail does not display such images and spam filters often treat them as suspicious.

Where Base64 is used in practice

Images right in HTML and CSS

You can embed a small icon or logo in a page as a data URI, with no separate file and no extra request to the server.

<img src="data:image/png;base64,iVBORw0KGgo…" alt="Logo">

.icon {
  background: url("data:image/svg+xml;base64,PHN2Zy…");
}

Email attachments

Email can only carry text, so every attachment is encoded in Base64. The attachment header tells the email client how to decode it.

Content-Type: application/pdf; name="invoice.pdf"
Content-Transfer-Encoding: base64

JVBERi0xLjcKJeLjz9MK…

HTTP Basic authentication

The browser joins the username and password with a colon and sends them in Base64. This is not encryption. Only an HTTPS connection protects the credentials.

Authorization: Basic dXNlcjpwYXNzd29yZA==

JWT tokens

A token has three parts separated by dots: the header, the payload and the signature. The first two are JSON encoded in base64url, so anyone can read them. The signature guarantees nobody has changed them, but it does not hide them.

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjMiLCJuYW1lIjoiSmFuYSJ9.signature

Certificates and keys

SSL certificates and private keys are stored as Base64 between BEGIN and END lines. This format is called PEM.

-----BEGIN CERTIFICATE-----
MIIDdzCCAl+gAwIBAgIE…
-----END CERTIFICATE-----

Files in APIs and JSON

JSON cannot hold binary data, so APIs send files as a Base64 string in an ordinary text field.

{
  "name": "contract.pdf",
  "content": "JVBERi0xLjcKJeLjz9MK…"
}

Kubernetes Secrets

Kubernetes stores values in Secret objects as Base64 so they can contain binary data too. But this is not protection: anyone with access to the object can simply decode the value. Real protection only comes from encryption at rest and access controls.

apiVersion: v1
kind: Secret
data:
  password: dGFqbmVoZXNsbw==

How to identify a file from the start of its Base64

Most formats start with typical bytes, so their Base64 always starts the same way too. The first few characters often tell you the file type before you even decode it. Rows marked with an asterisk only show the most common start, not a fixed rule.

Base64 starts withFile typeMIME type
iVBORw0KGg…PNGimage/png
/9j/…JPEGimage/jpeg
R0lGO…GIFimage/gif
UklGR…RIFF (WebP, WAV, AVI)image/webp, audio/wav
PHN2Z…SVG*image/svg+xml
JVBERi…PDFapplication/pdf
UEsDB…ZIP, DOCX, XLSXapplication/zip
H4sI…GZIPapplication/gzip
PD94bW…XML*application/xml
ey…JSON, JWT*application/json

Base64 compared with other encodings

Base64 is not the only way to write bytes as text. Other encodings are either longer but easier to read and type, or shorter but use less common characters.

EncodingCharactersSize increaseTypical use
Hex (Base16) 0-9, A-F 100% hashes, colors, byte dumps
Base32 A-Z, 2-7 60% two-factor authentication keys (TOTP)
Base58 58 characters, without 0, O, I and l about 37% cryptocurrency addresses, short IDs
Base64 A-Z, a-z, 0-9, + / 33% attachments, data URIs, APIs, JWT
Base85 (Ascii85) 85 characters 25% PDF, PostScript, binary diffs in Git

Base64 is not encryption

Anyone can decode Base64, no key required. It does not protect passwords, personal data or secret keys. It only writes them in a different form. Scammers love to abuse it, though: phishing emails and malicious scripts use it to hide links and code from simple filters. If you come across an unusually long Base64 string, feel free to decode it here and see what is inside. Nothing gets executed when you decode it.

A short history of Base64

  1. 1987

    The encoding first appeared in the Privacy-Enhanced Mail (PEM) specification, RFC 989, under the name printable encoding.

  2. 1992

    The MIME standard (RFC 1341) adopted it for email attachments, introduced 76-character lines and gave it the name Base64.

  3. 2003

    RFC 3548 described Base64 on its own, outside of email, and added a variant for URLs and file names.

  4. 2006

    RFC 4648 replaced the previous document and is still in force today.

For developers

Base64 in programming languages and on the command line

Here is how to encode and decode the text "Hello" in common languages. Always convert text with accented or other non-ASCII characters to UTF-8 bytes first, or you will get an error or a different result.

JavaScript

const base64 = btoa(String.fromCharCode(...new TextEncoder().encode('Hello')));
const text = new TextDecoder().decode(Uint8Array.from(atob(base64), (c) => c.charCodeAt(0)));

On its own, btoa('€') throws an InvalidCharacterError, because btoa only accepts characters up to U+00FF (Latin-1). The latest browsers also support Uint8Array.prototype.toBase64().

Node.js

Buffer.from('Hello', 'utf8').toString('base64');
Buffer.from('SGVsbG8=', 'base64').toString('utf8');
Buffer.from('Hello').toString('base64url');

Node.js supports the base64url encoding out of the box, so you do not need a library.

PHP

base64_encode('Hello');
base64_decode('SGVsbG8=', true);

With the second parameter set to true, the function returns false on invalid input. Without it, PHP silently skips characters that are not allowed.

Python

import base64

base64.b64encode('Hello'.encode()).decode()
base64.b64decode('SGVsbG8=').decode()
base64.urlsafe_b64encode(b'Hello')

An Incorrect padding error means the string is missing the = signs at the end.

Java

Base64.getEncoder().encodeToString("Hello".getBytes(StandardCharsets.UTF_8));
new String(Base64.getDecoder().decode("SGVsbG8="), StandardCharsets.UTF_8);

For base64url, use Base64.getUrlEncoder(). For email, use Base64.getMimeEncoder().

C#

Convert.ToBase64String(Encoding.UTF8.GetBytes("Hello"));
Encoding.UTF8.GetString(Convert.FromBase64String("SGVsbG8="));

The same methods work in both .NET and PowerShell.

Linux and macOS

printf 'Hello' | base64
echo 'SGVsbG8=' | base64 -d
base64 < file.pdf > file.txt

The echo command adds a newline at the end, so use printf or echo -n for encoding. Older versions of macOS use -D instead of -d.

Windows PowerShell

[Convert]::ToBase64String([Text.Encoding]::UTF8.GetBytes('Hello'))
[Text.Encoding]::UTF8.GetString([Convert]::FromBase64String('SGVsbG8='))
[Convert]::ToBase64String([IO.File]::ReadAllBytes('file.pdf'))

In the classic Command Prompt, certutil -encode file.pdf file.txt also works, but it wraps the output in BEGIN and END lines.

Images and SVG in code

Image to Base64 in JavaScript

const file = document.querySelector('input[type=file]').files[0];
const reader = new FileReader();

reader.onload = () => console.log(reader.result);
reader.readAsDataURL(file);

The readAsDataURL method returns a complete data URI including the file type, for example data:image/png;base64,iVBORw0KGg….

A tip for SVG icons

SVG is text, so you do not need to encode it in Base64 to use it in CSS. Just URL-encode it, for example url("data:image/svg+xml,%3Csvg…"). The result is usually shorter, and you can still easily edit the icon in it, for example to change its color. Base64 only makes sense for SVG when a system will not accept any other form.

Decoding a Base64 file on the command line

When you have Base64 saved in a file, for example from an API or a log, you can decode it straight back to the original file:

Linux
base64 -d image.txt > image.png
macOS
base64 -d -i image.txt -o image.png
Windows (Command Prompt)
certutil -decode image.txt image.png
Windows PowerShell
[IO.File]::WriteAllBytes('image.png', [Convert]::FromBase64String((Get-Content image.txt -Raw)))
OpenSSL
openssl base64 -d -A -in image.txt -out image.png

If the file starts with a data URI header such as data:image/png;base64,, delete it first. The certutil command also handles files with BEGIN and END lines.

Common errors and how to fix them

Accented letters turn into ÄŤ and similar gibberish

The text was encoded in UTF-8 but is being read as Windows-1250, or the other way around. A Czech or Slovak word like čaj, saved in UTF-8 and displayed as Windows-1250, comes out as ÄŤaj. If the text is not UTF-8, this tool tries reading it as Windows-1250 and lets you know.

InvalidCharacterError in JavaScript

The btoa function only accepts characters up to U+00FF (Latin-1), so it fails on characters like €, č or emoji. Convert the text to bytes with TextEncoder first, as in the example above.

Incorrect padding in Python

Base64 taken from a JWT token or a URL has no = signs at the end. Add them back so the length is divisible by four. This tool adds them for you.

Plus signs turned into spaces

If you put Base64 into a URL without encoding it, the server reads + as a space and decoding fails. Encode the value with the URL Encoder or use base64url.

The decoded result is Base64 again

The text was encoded twice, for example Hello → SGVsbG8= → U0dWc2JHOD0=. Decode it once more: click Swap to move the result into the input, then choose Decode again.

The image does not show up

The string is truncated, is missing its beginning or contains the data URI prefix twice. Compare the first characters with the table above: a PNG must start with iVBORw0KGg and a JPEG with /9j/.

When to use Base64 and when not to

Good for

  • small icons and images of a few kilobytes embedded right in CSS or HTML
  • binary data in JSON, XML or a configuration file
  • keys, tokens and signatures that have to be plain text
  • sending data through systems that only handle text, such as email

Not good for

  • large images and videos on the web, which become a third bigger and cannot be cached separately
  • images in emails, because Gmail does not display them
  • files in a database with binary (BLOB) columns, where Base64 takes up a third more space
  • protecting passwords and sensitive data, which is what encryption and hashing are for

Glossary

Bit
The smallest unit of data, with a value of 0 or 1.
Byte
A group of eight bits, which is a number from 0 to 255.
UTF-8
A way to write text characters as bytes. Plain English letters take one byte, accented letters such as é or č take two.
Padding
The = signs added to the output to make its length divisible by four.
base64url
A Base64 variant that uses - and _ instead of + and /, suitable for URLs and file names.
MIME
The email standard that uses Base64 for attachments.
Data URI
A way to write a file directly in text, in the form data:type;base64,content.
PEM
A format for certificates and keys: Base64 between BEGIN and END lines.
RFC 4648
The document that officially defines Base64, Base32 and Base16 today.

FAQ

What is Base64?

Base64 is a way to write any data with 64 characters that pass safely through text-based systems: A to Z, a to z, 0 to 9 and the + and / signs. The = sign at the end only pads the length. It is neither compression nor encryption, just another way of writing the same bytes.

Is Base64 encryption?

No. Anyone can decode Base64 without a password or key, so it does not protect sensitive data. If you see a password encoded in Base64, for example in an HTTP Basic header, only the encrypted HTTPS connection protects it.

Why is Base64 longer than the original text?

Base64 splits data into groups of three bytes and writes each group as four characters. The result is therefore about 33% longer. With accented text the difference is even bigger, because letters such as é take two bytes in UTF-8.

What is base64url and when should I use it?

base64url is a variant for URLs and file names. It uses - and _ instead of + and / and drops the trailing =. JWT tokens, OAuth and URL signatures use it. When decoding, this tool recognises it automatically.

How do I decode Base64 to an image or a PDF?

Paste the Base64 string or the whole data URI and choose Decode. If the result is not text, the tool detects the file type from its content, shows a preview for images and offers a download button.

Why do I get an error when decoding?

Base64 may only contain letters, digits and + / =, plus - _ for base64url. Spaces and line breaks are fine. Any other character or an incompletely copied string causes an error. A JWT token has three parts separated by dots, so decode each part separately.

Is my text or file sent to a server?

No. Encoding and decoding happen right in your browser, and neither the text nor the file leaves your computer.

How do I convert an image to Base64?

Switch to File, choose an image and select the Data URI format. You can paste the result straight into an src attribute or into CSS. This works well for images of a few kilobytes. Larger ones are better kept as separate files.

Why does Base64 end with one or two = signs?

The = signs pad the length to a multiple of four. Two = signs mean the last group had only one byte, one = sign means it had two. They do not affect the content, and base64url often leaves them out.

How do I decode a JWT token?

Split the token at the dots and paste in the first or second part. You will get JSON with the token header or its payload. The third part is the signature and contains no readable text.

Why was the text shown with a Windows-1250 notice?

The decoded bytes were not valid UTF-8 but looked like text, so the tool tried reading them as Windows-1250, the older Central European Windows code page. It is only a guess. If the result makes no sense, download the original data as a file.

Why are Kubernetes Secret values in Base64 if it is not encryption?

Base64 is there so that a YAML file can hold binary data too, such as certificates. It provides no protection, and anyone with access to the object can read the value. To protect it, turn on encryption at rest and restrict access permissions.

How do I generate a random key in Base64?

Use the generator above on this page or the command openssl rand -base64 32. Both use a cryptographically secure source of randomness. Do not use ordinary random number generators in programming languages, such as Math.random(), for secret keys.