Base64 is a way to represent arbitrary binary data as a string of 64 safe ASCII characters (A–Z, a–z, 0–9, +, /). Browsers, email clients, and APIs work exclusively with text — Base64 lets you "pack" an image, file, or binary token so it travels through any text-based channel without corruption.
How to use this tool
The process takes only a few seconds:
- Paste your plain text or a Base64 string into the input field.
- Click "Encode" to get the Base64 representation.
- Click "Decode" to restore the original text from a Base64 string.
- Copy the result.
The tool runs entirely in your browser — no data is sent to any server, which matters when handling tokens or sensitive information.
Where Base64 is used
Base64 encoding appears in everyday development far more often than you might expect:
- Data URIs in HTML and CSS — embedding small images, fonts, or SVG directly in code:
background: url("data:image/png;base64,…"). - Email attachments (MIME) — the MIME standard encodes attached files in Base64 to carry binary data over the text-based SMTP protocol.
- JWT and authentication tokens — the header and payload of a JSON Web Token are Base64URL-encoded (a URL-safe variant of Base64).
- REST and GraphQL APIs — sending images or PDFs inside a JSON body without multipart forms.
- HTTP Basic Authentication — the
Authorization: Basic …header contains the Base64-encoded stringlogin:password.
Frequently asked questions
Is Base64 a form of encryption?
No. Base64 is encoding, not encryption. Anyone can decode a Base64 string instantly without a key or password. Never rely on Base64 to protect data — use it only to safely transport data through text-based channels.
Why is the encoded string about 33% longer than the original?
Base64 maps every 3 bytes of input to 4 ASCII characters (3 × 8 bits → 4 × 6 bits), which inevitably increases size by one third. This is why Base64 is not suitable for large files — it is best reserved for small data blocks.
Is it safe to store passwords or secrets in Base64?
No. A Base64 string can be decoded instantly by any online tool or a single terminal command. For passwords, use a proper one-way hash function (bcrypt, Argon2); for secrets, use encryption (AES).
What is the difference between Base64 and Base64URL?
Base64URL replaces + and / with - and _, and omits the = padding characters. This makes the string safe to include in URLs and file names without percent-encoding. JWT uses Base64URL for exactly this reason.
Check out other tools for working with data and text.