Base64 converter

Type some text to get its Base64, or paste Base64 to see what’s inside. You don’t have to say which way you’re going, and if what comes out is an image or a file, we show it as one.

Direction
or drop one on this box. 10 MB at most.
When encoding, write

The result appears as you type. Text and files are converted inside this page and are not sent to us. Base64 is a way to write bytes as letters, not encryption: anyone can decode it.

Sending bytes through channels built for text

Email was designed for plain English letters. So were the first web addresses, and so are JSON and XML today. A photo, a PDF or a cryptographic key is made of arbitrary bytes, and to a channel like that, many of those bytes mean something special or nothing at all. Push them through as they are and they arrive damaged.

Base64 is the workaround. It rewrites any sequence of bytes using 64 harmless characters: A to Z, a to z, 0 to 9, + and /. Every email attachment travels this way. So do the images embedded in a style sheet and the tokens that keep you signed in.

Three bytes become four characters

A byte holds 8 bits, and one of 64 characters can stand for 6 bits. So the encoder takes 3 bytes (24 bits) at a time and cuts them into four groups of 6 bits. Each group picks one character from the alphabet.

text     M        a        n
bytes    01001101 01100001 01101110
6 bits   010011 010110 000101 101110
Base64   T      W      F      u

That has two side effects. The output is a third longer than the input, about 33 %, a little more with line breaks. And when the input doesn’t divide by 3, the last group gets completed with one or two = signs, called padding. Ma gives TWE= and M gives TQ==. The padding carries no data, which is why some systems leave it out.

Standard, URL-safe, MIME

VariantCharacters 63 and 64PaddingWhere you meet it
Standard+ /YesData URIs, HTTP Basic authentication, PEM keys
URL-safe (Base64URL)- _Usually noneJSON Web Tokens, links, file names
MIME+ /YesEmail attachments, with a line break every 76 characters

When decoding, this tool takes all of them at once: either alphabet, padding or no padding, spaces and line breaks anywhere. Then it tells you which variant it saw. Characters outside the alphabet are listed with their position and skipped. A length that leaves one character over gets flagged. A single character holds 6 bits and can’t make a byte, so something was cut off.

Text is bytes first

Base64 encodes bytes, not letters, so text has to be turned into bytes before anything else happens. This tool uses UTF-8, the encoding of nearly all of the web. In UTF-8 an unaccented Latin letter is 1 byte, é is 2, most Chinese or Japanese characters are 3 and an emoji is 4. That’s why é alone becomes w6k=.

The classic bug is skipping that step. In JavaScript, btoa("é") returns 6Q==, the Latin-1 byte, and btoa("👍") throws an error. On the way back, atob() hands you é where é used to be. The fix is TextEncoder before encoding and TextDecoder after decoding.

When the decoded bytes aren’t valid UTF-8, the tool doesn’t print garbage at you. It looks at the first bytes, which identify most file formats (PNG, JPEG, GIF, WebP, PDF, ZIP and gzip are recognized), previews a picture, offers the result as a file and shows the beginning in hexadecimal.

It hides nothing

Base64 has no key and no secret. Decoding is the same recipe read backwards, and every programming language ships with it. A password “protected” with Base64 is a password in clear text with extra steps. Take the HTTP header Authorization: Basic dXNlcjpwYXNz, which anyone can turn back into user:pass.

A data: URI such as data:image/png;base64,iVBORw0… puts a whole file inside an address. For a tiny icon, that saves one request. For anything larger you pay the extra 33 % and the file can no longer be cached separately.

Questions people ask

Is Base64 encryption?

No. It’s an encoding, a public and reversible way to write bytes with 64 printable characters. There’s no key, so anyone can decode it. Use it to transport data, never to protect it.

Why does Base64 end with one or two equals signs?

The encoder works on groups of 3 bytes. When the last group only has 1 or 2 bytes, the output gets completed with == or = so its length stays a multiple of 4. The signs carry no data, and URL-safe Base64 often leaves them out.

What is the difference between Base64 and Base64URL?

Two characters. Standard Base64 uses + and /, which both mean something in web addresses. Base64URL swaps them for - and _ and usually drops the = padding. The data inside is the same.

Why do accents or emoji come out wrong after decoding?

The decoder read the bytes with the wrong text encoding, usually Latin-1 when the text was UTF-8. That’s when you see é for é. Decode the bytes as UTF-8 (in JavaScript, with TextDecoder) and the text comes back intact.

How much bigger is a file in Base64?

About 33 %, since every 3 bytes become 4 characters. A 300 KB image turns into roughly 400 KB of text, plus about 2.6 % when lines are wrapped at 76 characters for email.

How do I turn an image into a data URI?

Drop the image on the tool. You get the Base64 and a complete data:image/…;base64,… address to paste into an src attribute or a CSS url(). Keep this for small images of a few kilobytes.