Base64 Encoder & Decoder
Paste text or pick a file and instantly see it in Base64. It works the other way too: Base64 turns back into text, an image or any other file.
The result is a file, not text
The decoded data is not readable text, but you can download the file.
How to use the tool
How to encode and decode Base64
- 1 At the top, choose whether you are working with text or a file. Text can be encoded or decoded. A file, such as an image or a PDF, can be encoded to Base64 or straight to a data URI.
- 2 For text, choose Encode or Decode and enter your text. The result appears instantly as you type.
- 3 Copy the result with the Copy button. The Swap button moves it into the input and reverses the direction, for example to double-check it.
What the tool handles on its own
- when decoding, it recognizes both standard Base64 and base64url and adds any missing = signs at the end
- it reads a whole data URI, including the file type, and ignores spaces and line breaks
- it recognizes images, PDFs and archives, shows a preview for images and offers a download
- if the text is not UTF-8, it tries Windows-1250, the older Central European Windows code page, and tells you
- when encoding text, it also shows the base64url version below the result for URLs and JWT
- everything is processed right in your browser, nothing is sent to a server
How to convert an image to Base64 and back
Images are the most common use for Base64. You can encode a small image and embed it right in HTML or CSS, with no separate file. And when you receive an image as a Base64 string, for example from an API, you can turn it back into a file here and save it.
From image to Base64
- 1 At the top of the tool, switch to File and choose a PNG, JPG, GIF, WebP or SVG image.
- 2 Select the Data URI format if you want to embed it in HTML or CSS, or Base64 for APIs and JSON.
-
3
Copy the result and paste it into an
srcattribute, the CSSbackgroundproperty or your own code.
From Base64 to an image or PDF
- 1 Switch to Text and choose Decode.
- 2 Paste the Base64 string or the whole data URI. The tool recognizes from the content whether it is a PNG, JPEG, GIF, WebP or PDF.
- 3 Images get a preview. Click Download file to save it with the right file extension.
How to read a JWT token
A JWT token looks like one long string, but it consists of three parts separated by dots. The first two are plain JSON encoded in base64url, so you can read them without any key. Paste each part into the tool separately:
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjMiLCJuYW1lIjoiSmFuYSIsImV4cCI6MTc2NzIyNTYwMH0.signature
- Header
-
{"alg":"HS256","typ":"JWT"}the signing algorithm and the token type
- Payload
-
{"sub":"123","name":"Jana","exp":1767225600}the user ID, name and expiry time
- Signature
-
signaturea binary signature that the server verifies, not text
The exp value is the expiry time in seconds since January 1, 1970, here exactly midnight UTC on January 1, 2026. Anyone who has the token can read its payload, so never put passwords or other secrets in it.
How to extract an attachment from an email source
In the raw source of a message, every attachment is stored as a long block of Base64 after the Content-Transfer-Encoding: base64 header. In Gmail, open the source with Show original, in Outlook with View message source. Copy the block without the headers, paste it here, choose Decode and download the file. This helps when an attachment will not open in your email client or the client has blocked it.
Random key in Base64
Secret keys for APIs, encryption and signatures are often written as random bytes in Base64. Laravel, for example, stores its application key as APP_KEY=base64: followed by 32 random bytes. You can generate a key here too, using a cryptographically secure generator right in your browser.
In a terminal, the command openssl rand -base64 32 does the same. The generated key is never sent or stored anywhere.
All about Base64
What Base64 is and what it is for
Base64 is a way to write any data, even an image or a PDF, using just 64 common characters: uppercase and lowercase letters, digits and the + and / signs. Data written this way can travel anywhere only text is allowed, such as email attachments, JSON API responses, HTML or CSS. Every three bytes become four characters, so the result is about a third longer than the original data.
- characters in the Base64 alphabet
- 64
- every three bytes become four characters
- 3 → 4
- how much longer the output gets
- +33%
- the standard that defines Base64
- RFC 4648
Examples
This is how common text looks before and after encoding:
| Input | Base64 | |
|---|---|---|
| Short text | Hello |
SGVsbG8= |
| Text with accents | Café crème |
Q2Fmw6kgY3LDqG1l |
| HTTP Basic login | user:password |
dXNlcjpwYXNzd29yZA== |
How Base64 works, step by step
- 1 First, the text is converted to bytes. In UTF-8, plain English letters take one byte, accented letters such as é or č take two, and emoji take four.
- 2 Each byte has eight bits. The bits are lined up one after another and split into groups of six.
- 3 Each group of six bits is a number from 0 to 63, which maps to one character of the Base64 alphabet: 0 is A, 26 is a, 52 is 0, 62 is + and 63 is /.
- 4 If there are not enough bits left to fill the last group, it is padded with zeros. Then = characters are added to the end so the length is divisible by four.
How Base64 turns three bytes into four characters
Base64 works on groups of three bytes. The letters M, a and n have the ASCII codes 77, 97 and 110.
Each byte has 8 bits, 24 bits in total.
The 24 bits are split into 4 groups of 6. Each group is a number from 0 to 63.
Each number is replaced with a character from the 64-character alphabet. 3 bytes become 4 characters, which is why Base64 is about a third longer.
When the last group is incomplete, as with the text "Ma", the third byte is missing.
There are only 16 bits, not enough for three full groups of 6.
The third group is filled up with two zero bits. No bits are left for the fourth one.
The missing group is written as =. It tells the decoder how many bytes were really there at the end.
The breakdown shows the first six bytes of your text.
| Character | Byte | Bits |
|---|---|---|
| H | 72 | 01001000 |
| e | 101 | 01100101 |
| l | 108 | 01101100 |
| l | 108 | 01101100 |
| o | 111 | 01101111 |
| 6-bit group | Value | Base64 character |
|---|---|---|
| 010010 | 18 | S |
| 000110 | 6 | G |
| 010101 | 21 | V |
| 101100 | 44 | s |
| 011011 | 27 | b |
| 000110 | 6 | G |
| 111100 | 60 | 8 |
| = |
= SGVsbG8=
The Base64 alphabet (character table)
Base64 uses exactly 64 characters. Each one stands for a number from 0 to 63, which is one group of six bits. The = sign is not part of the alphabet. It only pads the length at the end.
- 0 A
- 1 B
- 2 C
- 3 D
- 4 E
- 5 F
- 6 G
- 7 H
- 8 I
- 9 J
- 10 K
- 11 L
- 12 M
- 13 N
- 14 O
- 15 P
- 16 Q
- 17 R
- 18 S
- 19 T
- 20 U
- 21 V
- 22 W
- 23 X
- 24 Y
- 25 Z
- 26 a
- 27 b
- 28 c
- 29 d
- 30 e
- 31 f
- 32 g
- 33 h
- 34 i
- 35 j
- 36 k
- 37 l
- 38 m
- 39 n
- 40 o
- 41 p
- 42 q
- 43 r
- 44 s
- 45 t
- 46 u
- 47 v
- 48 w
- 49 x
- 50 y
- 51 z
- 52 0
- 53 1
- 54 2
- 55 3
- 56 4
- 57 5
- 58 6
- 59 7
- 60 8
- 61 9
- 62 +
- 63 /
Why Base64 ends with = or ==
Base64 works on data three bytes at a time. When fewer bytes are left at the end, the = sign fills the missing space. One leftover byte adds two = signs, two bytes add one, and three bytes add none. Some systems, such as JWT, leave out the = signs because the decoder can work out the length on its own.
How big will the Base64 be
Every three bytes become four characters, so the Base64 output is 4 × ⌈n ÷ 3⌉ characters long, where n is the number of bytes and the brackets mean rounding up. That makes it roughly 33% longer. In emails, Base64 is also wrapped into lines of 76 characters, each ending with CR LF, so an attachment grows by about 37%. Going the other way, a Base64 string of length d holds 3 × d ÷ 4 bytes, minus the number of = signs at the end.
| Original file | Base64 | Base64 in an email (MIME) |
|---|---|---|
| 1.00 KB | 1.34 KB | 1.37 KB |
| 10.00 KB | 13.34 KB | 13.69 KB |
| 100 KB | 133 KB | 137 KB |
| 1.00 MB | 1.33 MB | 1.37 MB |
| 10.00 MB | 13.33 MB | 13.68 MB |
Base64 variants
All variants share the same first 62 characters. They differ in the last two characters, in padding and in whether the output is wrapped into lines.
| Variant | Characters 62 and 63 | Padding = | Lines | Where it is used |
|---|---|---|---|---|
| Standard Base64 (RFC 4648) | + / | yes | no line breaks | APIs, JSON, data URIs |
| base64url (RFC 4648) | - _ | usually not | no line breaks | JWT, OAuth, URLs, file names |
| MIME (RFC 2045) | + / | yes | every 76 characters | email attachments |
| PEM (RFC 7468) | + / | yes | every 64 characters | certificates and cryptographic keys |
Base64 and base64url
Standard Base64 contains the characters +, / and =, which have their own meaning in URLs. The base64url variant uses - and _ instead and drops the trailing = signs. It is used by JWT tokens, OAuth and signed URLs, for example.
An image as a data URI
A data URI puts a file straight into HTML or CSS, for example <img src="data:image/png;base64,…">. It works well for small icons, because the browser does not have to download them separately. For larger images it is not worth it: they are a third bigger and the browser cannot cache them separately. Do not use data URIs in emails, as Gmail does not display such images and spam filters often treat them as suspicious.
Where Base64 is used in practice
Images right in HTML and CSS
You can embed a small icon or logo in a page as a data URI, with no separate file and no extra request to the server.
<img src="data:image/png;base64,iVBORw0KGgo…" alt="Logo">
.icon {
background: url("data:image/svg+xml;base64,PHN2Zy…");
}
Email attachments
Email can only carry text, so every attachment is encoded in Base64. The attachment header tells the email client how to decode it.
Content-Type: application/pdf; name="invoice.pdf"
Content-Transfer-Encoding: base64
JVBERi0xLjcKJeLjz9MK…
HTTP Basic authentication
The browser joins the username and password with a colon and sends them in Base64. This is not encryption. Only an HTTPS connection protects the credentials.
Authorization: Basic dXNlcjpwYXNzd29yZA==
JWT tokens
A token has three parts separated by dots: the header, the payload and the signature. The first two are JSON encoded in base64url, so anyone can read them. The signature guarantees nobody has changed them, but it does not hide them.
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjMiLCJuYW1lIjoiSmFuYSJ9.signature
Certificates and keys
SSL certificates and private keys are stored as Base64 between BEGIN and END lines. This format is called PEM.
-----BEGIN CERTIFICATE-----
MIIDdzCCAl+gAwIBAgIE…
-----END CERTIFICATE-----
Files in APIs and JSON
JSON cannot hold binary data, so APIs send files as a Base64 string in an ordinary text field.
{
"name": "contract.pdf",
"content": "JVBERi0xLjcKJeLjz9MK…"
}
Kubernetes Secrets
Kubernetes stores values in Secret objects as Base64 so they can contain binary data too. But this is not protection: anyone with access to the object can simply decode the value. Real protection only comes from encryption at rest and access controls.
apiVersion: v1
kind: Secret
data:
password: dGFqbmVoZXNsbw==
How to identify a file from the start of its Base64
Most formats start with typical bytes, so their Base64 always starts the same way too. The first few characters often tell you the file type before you even decode it. Rows marked with an asterisk only show the most common start, not a fixed rule.
| Base64 starts with | File type | MIME type |
|---|---|---|
iVBORw0KGg… | PNG | image/png |
/9j/… | JPEG | image/jpeg |
R0lGO… | GIF | image/gif |
UklGR… | RIFF (WebP, WAV, AVI) | image/webp, audio/wav |
PHN2Z… | SVG* | image/svg+xml |
JVBERi… | application/pdf | |
UEsDB… | ZIP, DOCX, XLSX | application/zip |
H4sI… | GZIP | application/gzip |
PD94bW… | XML* | application/xml |
ey… | JSON, JWT* | application/json |
Base64 compared with other encodings
Base64 is not the only way to write bytes as text. Other encodings are either longer but easier to read and type, or shorter but use less common characters.
| Encoding | Characters | Size increase | Typical use |
|---|---|---|---|
| Hex (Base16) | 0-9, A-F | 100% | hashes, colors, byte dumps |
| Base32 | A-Z, 2-7 | 60% | two-factor authentication keys (TOTP) |
| Base58 | 58 characters, without 0, O, I and l | about 37% | cryptocurrency addresses, short IDs |
| Base64 | A-Z, a-z, 0-9, + / | 33% | attachments, data URIs, APIs, JWT |
| Base85 (Ascii85) | 85 characters | 25% | PDF, PostScript, binary diffs in Git |
Base64 is not encryption
Anyone can decode Base64, no key required. It does not protect passwords, personal data or secret keys. It only writes them in a different form. Scammers love to abuse it, though: phishing emails and malicious scripts use it to hide links and code from simple filters. If you come across an unusually long Base64 string, feel free to decode it here and see what is inside. Nothing gets executed when you decode it.
A short history of Base64
-
1987
The encoding first appeared in the Privacy-Enhanced Mail (PEM) specification, RFC 989, under the name printable encoding.
-
1992
The MIME standard (RFC 1341) adopted it for email attachments, introduced 76-character lines and gave it the name Base64.
-
2003
RFC 3548 described Base64 on its own, outside of email, and added a variant for URLs and file names.
-
2006
RFC 4648 replaced the previous document and is still in force today.
For developers
Base64 in programming languages and on the command line
Here is how to encode and decode the text "Hello" in common languages. Always convert text with accented or other non-ASCII characters to UTF-8 bytes first, or you will get an error or a different result.
JavaScript
const base64 = btoa(String.fromCharCode(...new TextEncoder().encode('Hello')));
const text = new TextDecoder().decode(Uint8Array.from(atob(base64), (c) => c.charCodeAt(0)));
On its own, btoa('€') throws an InvalidCharacterError, because btoa only accepts characters up to U+00FF (Latin-1). The latest browsers also support Uint8Array.prototype.toBase64().
Node.js
Buffer.from('Hello', 'utf8').toString('base64');
Buffer.from('SGVsbG8=', 'base64').toString('utf8');
Buffer.from('Hello').toString('base64url');
Node.js supports the base64url encoding out of the box, so you do not need a library.
PHP
base64_encode('Hello');
base64_decode('SGVsbG8=', true);
With the second parameter set to true, the function returns false on invalid input. Without it, PHP silently skips characters that are not allowed.
Python
import base64
base64.b64encode('Hello'.encode()).decode()
base64.b64decode('SGVsbG8=').decode()
base64.urlsafe_b64encode(b'Hello')
An Incorrect padding error means the string is missing the = signs at the end.
Java
Base64.getEncoder().encodeToString("Hello".getBytes(StandardCharsets.UTF_8));
new String(Base64.getDecoder().decode("SGVsbG8="), StandardCharsets.UTF_8);
For base64url, use Base64.getUrlEncoder(). For email, use Base64.getMimeEncoder().
C#
Convert.ToBase64String(Encoding.UTF8.GetBytes("Hello"));
Encoding.UTF8.GetString(Convert.FromBase64String("SGVsbG8="));
The same methods work in both .NET and PowerShell.
Linux and macOS
printf 'Hello' | base64
echo 'SGVsbG8=' | base64 -d
base64 < file.pdf > file.txt
The echo command adds a newline at the end, so use printf or echo -n for encoding. Older versions of macOS use -D instead of -d.
Windows PowerShell
[Convert]::ToBase64String([Text.Encoding]::UTF8.GetBytes('Hello'))
[Text.Encoding]::UTF8.GetString([Convert]::FromBase64String('SGVsbG8='))
[Convert]::ToBase64String([IO.File]::ReadAllBytes('file.pdf'))
In the classic Command Prompt, certutil -encode file.pdf file.txt also works, but it wraps the output in BEGIN and END lines.
Images and SVG in code
Image to Base64 in JavaScript
const file = document.querySelector('input[type=file]').files[0];
const reader = new FileReader();
reader.onload = () => console.log(reader.result);
reader.readAsDataURL(file);
The readAsDataURL method returns a complete data URI including the file type, for example data:image/png;base64,iVBORw0KGg….
A tip for SVG icons
SVG is text, so you do not need to encode it in Base64 to use it in CSS. Just URL-encode it, for example url("data:image/svg+xml,%3Csvg…"). The result is usually shorter, and you can still easily edit the icon in it, for example to change its color. Base64 only makes sense for SVG when a system will not accept any other form.
Decoding a Base64 file on the command line
When you have Base64 saved in a file, for example from an API or a log, you can decode it straight back to the original file:
- Linux
base64 -d image.txt > image.png- macOS
base64 -d -i image.txt -o image.png- Windows (Command Prompt)
certutil -decode image.txt image.png- Windows PowerShell
[IO.File]::WriteAllBytes('image.png', [Convert]::FromBase64String((Get-Content image.txt -Raw)))- OpenSSL
openssl base64 -d -A -in image.txt -out image.png
If the file starts with a data URI header such as data:image/png;base64,, delete it first. The certutil command also handles files with BEGIN and END lines.
Common errors and how to fix them
Accented letters turn into ÄŤ and similar gibberish
The text was encoded in UTF-8 but is being read as Windows-1250, or the other way around. A Czech or Slovak word like čaj, saved in UTF-8 and displayed as Windows-1250, comes out as ÄŤaj. If the text is not UTF-8, this tool tries reading it as Windows-1250 and lets you know.
InvalidCharacterError in JavaScript
The btoa function only accepts characters up to U+00FF (Latin-1), so it fails on characters like €, č or emoji. Convert the text to bytes with TextEncoder first, as in the example above.
Incorrect padding in Python
Base64 taken from a JWT token or a URL has no = signs at the end. Add them back so the length is divisible by four. This tool adds them for you.
Plus signs turned into spaces
If you put Base64 into a URL without encoding it, the server reads + as a space and decoding fails. Encode the value with the URL Encoder or use base64url.
The decoded result is Base64 again
The text was encoded twice, for example Hello → SGVsbG8= → U0dWc2JHOD0=. Decode it once more: click Swap to move the result into the input, then choose Decode again.
The image does not show up
The string is truncated, is missing its beginning or contains the data URI prefix twice. Compare the first characters with the table above: a PNG must start with iVBORw0KGg and a JPEG with /9j/.
When to use Base64 and when not to
Good for
- small icons and images of a few kilobytes embedded right in CSS or HTML
- binary data in JSON, XML or a configuration file
- keys, tokens and signatures that have to be plain text
- sending data through systems that only handle text, such as email
Not good for
- large images and videos on the web, which become a third bigger and cannot be cached separately
- images in emails, because Gmail does not display them
- files in a database with binary (BLOB) columns, where Base64 takes up a third more space
- protecting passwords and sensitive data, which is what encryption and hashing are for
Glossary
- Bit
- The smallest unit of data, with a value of 0 or 1.
- Byte
- A group of eight bits, which is a number from 0 to 255.
- UTF-8
- A way to write text characters as bytes. Plain English letters take one byte, accented letters such as é or č take two.
- Padding
- The = signs added to the output to make its length divisible by four.
- base64url
- A Base64 variant that uses - and _ instead of + and /, suitable for URLs and file names.
- MIME
- The email standard that uses Base64 for attachments.
- Data URI
- A way to write a file directly in text, in the form data:type;base64,content.
- PEM
- A format for certificates and keys: Base64 between BEGIN and END lines.
- RFC 4648
- The document that officially defines Base64, Base32 and Base16 today.
Related Tools
More tools for preparing, editing, and checking text.
FAQ
What is Base64?
Is Base64 encryption?
Why is Base64 longer than the original text?
What is base64url and when should I use it?
- and _ instead of + and / and drops the trailing =. JWT tokens, OAuth and URL signatures use it. When decoding, this tool recognises it automatically.
How do I decode Base64 to an image or a PDF?
Why do I get an error when decoding?
+ / =, plus - _ for base64url. Spaces and line breaks are fine. Any other character or an incompletely copied string causes an error. A JWT token has three parts separated by dots, so decode each part separately.
Is my text or file sent to a server?
How do I convert an image to Base64?
src attribute or into CSS. This works well for images of a few kilobytes. Larger ones are better kept as separate files.
Why does Base64 end with one or two = signs?
How do I decode a JWT token?
Why was the text shown with a Windows-1250 notice?
Why are Kubernetes Secret values in Base64 if it is not encryption?
How do I generate a random key in Base64?
openssl rand -base64 32. Both use a cryptographically secure source of randomness. Do not use ordinary random number generators in programming languages, such as Math.random(), for secret keys.