Base64 Encoder / Decoder

Encode text to Base64 and decode it back instantly, UTF-8 safe and two-way.

encode ▼ · ▲ decode
Written and maintained by the KitYards team About KitYards Last reviewed:

KitYards Base64 Encoder / Decoder converts plain text to Base64 and decodes Base64 back to readable text in an instant. It is fully UTF-8 safe, so accented letters, emoji and non-Latin scripts convert correctly both ways. Ideal for data URIs, API tokens and debugging, the tool processes everything locally in your browser so your data is never uploaded, stored or exposed.

How to use the Base64 Encoder / Decoder

  1. 1 Paste your text or Base64 string into the input box.
  2. 2 Choose whether to encode or decode the content.
  3. 3 View the converted result instantly in the output area.
  4. 4 Copy the result to use in your code, URL or API request.

How the encoding works

Base64 rewrites arbitrary bytes using only 64 characters that survive any text channel: A–Z, a–z, 0–9, plus and slash. It works in blocks of three bytes. Three bytes are 24 bits; those 24 bits are re-cut into four groups of six, and each six-bit group indexes the 64-character alphabet. When the input does not divide evenly by three, the last block is padded and the result carries one or two "=" signs to record how much padding was added. This is why Base64 output is always about 33% larger than its input — four output characters for every three input bytes.

The encoder here does something many browser-based encoders get wrong. The built-in btoa function only accepts characters in the 0–255 range, so calling it directly on text containing "é", "ñ" or an emoji throws an exception. This tool first runs your text through TextEncoder, which produces real UTF-8 bytes, and only then calls btoa on those bytes. Decoding reverses it: atob recovers the bytes, and TextDecoder turns them back into text. The practical result is that any language and any emoji round-trips correctly.

Base64 is an encoding, not encryption. Anyone who sees the output can decode it in one step — that is the entire point, since it exists to move binary data through channels that expect text. Treat a Base64 string exactly as sensitively as the data inside it.

Where Base64 shows up

Data URIs in CSS and HTML

A small icon encoded as a data URI saves an HTTP request. It is worth it below roughly 2–4 KB; beyond that the 33% size penalty and the loss of separate caching outweigh the saved round-trip.

Decoding a JWT

The first two segments of a JSON Web Token are Base64url-encoded JSON. Paste a segment here to read the claims — useful when debugging an auth flow and you need to see what the token actually asserts.

Email attachments and MIME

SMTP was designed for 7-bit text, so every attachment you have ever sent travelled as Base64. When you are debugging a raw email source, this is the tool that turns the wall of characters back into something readable.

Config files and secrets

Kubernetes secrets, .env values and certificate blocks are routinely stored Base64-encoded. Decoding them locally matters here: pasting a production secret into a server-side tool would hand it to a third party.

What is Base64 encoding and when to use it

Base64 is an encoding scheme that represents binary or text data using a set of 64 ASCII characters, making it safe to transmit through channels that only reliably handle text. Developers use it to embed images and fonts directly in HTML or CSS as data URIs, to encode credentials in HTTP Basic Auth headers, to inspect JSON Web Tokens, and to move small binary payloads through JSON APIs and email. This tool encodes and decodes in both directions with proper UTF-8 handling, so multibyte characters survive the round trip intact. Because Base64 is encoding and not encryption, it does not secure your data, it only reformats it. All conversion happens client-side in your browser, meaning sensitive tokens and payloads never touch a remote server.

Things worth knowing

Base64 has a few sharp edges that catch people out:

  • This tool uses standard Base64 with "+" and "/". Base64url — used by JWTs and in URLs — substitutes "-" and "_" instead. Swap those characters back before decoding a token segment, or the decode will fail.
  • JWT segments often have their padding stripped. If a decode fails, try appending one or two "=" characters until the length is a multiple of four.
  • Encoded output is roughly 33% larger than the input. For anything over a few kilobytes in a web page, a normal file reference beats a data URI.
  • It provides no security whatsoever. Base64 is trivially reversible and should never be described as "encoded for safety".
  • Whitespace and line breaks inside a Base64 string are tolerated on decode, but a stray character from a bad copy-paste is not — that produces an invalid input error rather than partial output.

Troubleshooting

"Invalid Base64 input"
Three usual causes: the string is Base64url and contains "-" or "_"; padding was stripped so the length is not a multiple of four; or the copy picked up a stray character or a truncated tail. Fix the alphabet, add "=" until the length divides by four, and re-copy the full string.
My accented text came back as gibberish
That happens when the string was produced by an encoder that called btoa on raw text instead of on UTF-8 bytes. The original data was already mangled at encode time; there is nothing on the decode side that can recover it. Re-encode the source with a UTF-8-aware encoder.
I decoded an image and got unreadable characters
Expected — you decoded binary data into a text box. To use an encoded image, put it in an <img src="data:image/png;base64,…"> attribute rather than trying to read the decoded bytes as text.

Frequently Asked Questions

Is Base64 encoding the same as encryption?

No. Base64 only reformats data into text and is fully reversible by anyone. It provides no security or secrecy. Never rely on Base64 to protect passwords or sensitive information; use real encryption for that purpose.

Is my data uploaded when I encode or decode?

No. All encoding and decoding happens locally in your browser using native JavaScript. Your text and Base64 strings are never sent to a server, so tokens and private payloads stay entirely on your device.

Does it handle emoji and accented characters?

Yes. The tool is UTF-8 safe, so emoji, accented letters and non-Latin scripts encode and decode correctly in both directions without corruption or replacement characters, preserving your original text exactly.

Is Base64 a form of encryption?

No, and treating it as one is a genuine security mistake that shows up in real breaches. There is no key and no secret: the transformation is public and reversible by anyone in a single step. If data needs protecting, it needs encryption — Base64 only changes the alphabet it is written in.

Why does my encoded string end in "=" or "=="?

Because the input length was not a multiple of three. Base64 processes three bytes at a time; one leftover byte produces "==" and two leftover bytes produce "=". The padding tells the decoder how many bytes to discard at the end.

Can I encode a file rather than text?

This tool takes text. For a file, the practical route depends on your platform: base64 on macOS and Linux, or certutil -encode on Windows. If the file is an image destined for a data URI, most build tools will inline it for you automatically.

Is it safe to decode a production secret here?

Yes, and that is precisely the reason to use a client-side tool for it. The decode happens in your own browser tab with no network request; the value is never transmitted anywhere. Pasting the same secret into a server-side converter would send it to somebody else’s machine.

Other recommended tools