Devbelt

Base64 Encode / Decode

Encode or decode text and files instantly

TEXT
up to 2 MB
BASE64
Output appears here as you type.
Type text (or pick a file) to encode.

Everything runs in your browser. Your text and files are never uploaded or stored on a server.

About

When you need to move binary data through something that only understands text, like a JSON field, a URL, or an email, Base64 is how you do it. This tool encodes and decodes both text and files, gets Unicode and emoji right instead of garbling them, and gives you the URL-safe alphabet when you need it. Text and files are both handled in your browser, so nothing you paste or pick ever gets uploaded.

What Base64 is for

A lot of systems were built to move text around, not raw bytes. Email, URLs, JSON, XML, HTTP headers: send raw binary through any of them and something along the way will mangle a byte or read it as a control character. Base64 gets around that by rewriting your data using only 64 characters that are safe everywhere, which is the letters, the digits, plus, and slash.

One thing to keep straight: Base64 does not compress your data and it does not protect it. All it does is make binary safe to carry as text.

How the encoding works

The trick is that it works in groups of three bytes. Three bytes is 24 bits, and Base64 chops those 24 bits into four groups of 6. Each 6-bit group is a number from 0 to 63, and that number picks one character out of the Base64 alphabet. So three bytes go in and four characters come out, every time. That four-thirds ratio is why a Base64 string always ends up about a third bigger than what you started with.

Here is the word "Cat" going through it:

Cat  →  bytes    67       97       116
     →  bits     01000011 01100001 01110100
     →  6-bit    010000 110110 000101 110100
     →  values   16     54     5      52
     →  chars    Q      2      F      0

           Cat  →  Q2F0

Standard vs URL-safe

The normal alphabet ends with plus and slash and pads with equals signs. The catch is that all three of those mean something special inside a URL. So there's a URL-safe variant that swaps plus for minus, slash for underscore, and drops the padding. That version drops straight into a query string, a filename, or a JWT without any extra escaping. This tool does both. If something decodes into garbage, the usual reason is that it was encoded with the alphabet you aren't currently using.

Base64 is not security

Because the output looks scrambled, people sometimes treat Base64 like it hides something. It doesn't. Anyone can decode it in one step, and that's the whole idea. Don't lean on it to protect passwords, tokens, or anything else meant to stay secret. It's there to move data safely, not to keep it private. If the data is sensitive, it needs real encryption on top.

Frequently asked questions

What is Base64 encoding used for?
Base64 represents binary data as plain ASCII text, so it can travel safely through systems that only handle text. Common examples are embedding images in CSS or HTML as data URIs, encoding data in URLs and JWTs, and attaching files in email and JSON APIs.
How do I decode a Base64 string?
Switch to Decode, then paste your Base64 into the input box. Devbelt decodes it instantly and accepts both the standard and URL-safe alphabets, with or without padding.
Does this handle Unicode and emoji correctly?
Yes. Devbelt encodes and decodes via UTF-8, so accented characters, non-Latin scripts and emoji round-trip correctly, unlike naive tools that mangle anything outside plain ASCII.
What is URL-safe Base64?
Standard Base64 uses + and / and = padding, which have special meaning in URLs. URL-safe Base64 replaces + with -, / with _, and drops the padding, so the result can be dropped straight into a URL or a JWT.
Is my text or file uploaded anywhere?
No. All encoding and decoding, including files you choose, happens entirely in your browser. Nothing is uploaded or stored on a server.

Related tools