Base64 encoder / decoder
Encode text to base64 or decode it back, in the standard or URL-safe alphabet, with proper UTF-8 handling and an error that says which character is wrong.
Text
Whatever you paste stays in this tab. The work is done by JavaScript in your browser. None of it is uploaded, logged or saved, and the tool keeps working with the network off.
Alphabet
Base64
The encoded result appears here as you type.
Base64 is not encryption
It is worth saying first, because it is the mistake with real consequences. Base64 has no key and keeps no secret. Anything encoded with it can be read back instantly by anyone: on this page, in a browser console, with one shell command. A credential stored base64 “for safety” is stored in plain text with a step in front of it.
What it is for is survival. It turns arbitrary bytes into sixty-four characters that pass unharmed through systems built only for text: email bodies, JSON strings, data URLs, PEM certificates, URL parameters. The problem it solves is mangling, not privacy.
It runs here, in your browser
Both directions are plain JavaScript on this page. Nothing is uploaded, nothing is logged and nothing is stored: load the page, pull the network cable, and the tool still works. Given how often the thing you want to decode is a token or a payload from something real, that seemed worth being able to prove rather than merely assert.
The two alphabets
Standard base64 uses + and / for its last two characters. Both mean something inside a URL, so a value carrying them has to be escaped all over again to travel in one. URL-safe base64 substitutes - and _ and normally drops the = padding, which is the form JWTs and most URL parameters use.
Decoding accepts either without being told which, along with missing padding and the line breaks that wrapped base64 arrives with from openssl or an email header. Only encoding needs the choice, because only then does the tool have to pick.
Text, bytes and the encoding trap
Base64 encodes bytes. Text has to become bytes first, and which bytes depends on the character encoding, which is why an online encoder sometimes disagrees with your code. This tool uses UTF-8 throughout, matching JavaScript, JSON and the web.
It also means the browser’s own btoa is not used here: it works in Latin-1 and throws on any character above U+00FF, so btoa("é") is an error. Going through UTF-8 makes accented text, Chinese and emoji ordinary rather than a special case.
In the other direction, bytes that are not valid UTF-8 are reported rather than printed as replacement characters. Base64 of an image is a perfectly reasonable thing to paste in, and being told it is a file is more useful than a screenful of question marks.
Questions
Is base64 a form of encryption?
What is base64 actually for?
Is anything I paste here uploaded?
What is the difference between standard and URL-safe base64?
Why does my base64 end in = signs?
Why can it not decode my image?
Does base64 make my data bigger?
Why does an online encoder sometimes give a different answer to my code?
More tools
JSON formatter & validator
Indent it, shrink it, or find out what is wrong with it
URL encoder / decoder
Percent-encoding, with the component and whole-URL rules apart
Robots.txt tester
See which rule a crawler actually applies