Base64 Decoder and Encoder

Paste Base64 and read the text right away, or encode text and files. It understands Authorization: Basic headers, Kubernetes Secrets, data URIs and Base64url, and points to the line and column of an invalid character.

Base64 often carries passwords and tokens. Here the conversion runs in your browser: the content isn't sent to any server, isn't put in the URL and isn't saved.

Mode
0 characters
Examples:

Result

Nothing to show yet

Paste Base64 in the field or try one of the examples. The result shows up here as you type.

Putting an image in HTML, CSS or an email? The image converter shows a preview and builds the data URI for you.

Image to Base64

What is Base64

Base64 writes arbitrary bytes using only 64 text-safe characters: A to Z, a to z, 0 to 9, + and /. Every 3 bytes become 4 characters, and the = at the end completes the last group. It carries binary data or accented text through places that only accept ASCII, such as HTTP headers, JSON, YAML and email. There's no key or password: anyone can decode it.

Where Base64 shows up day to day

  • In the Authorization: Basic header, which carries user:password in Base64. Paste it here and the value comes back split into user and password.

  • In Kubernetes Secrets, where every value under data: is Base64. Paste the output of kubectl get secret name -o yaml and see all keys decoded together.

  • In queue messages and webhooks: Google Pub/Sub delivers the body in message.data as Base64, and AWS API Gateway does the same with binary bodies when isBase64Encoded is true.

  • In files carried inside text: email attachments (MIME), PEM certificates, and PDFs or images sent in JSON by APIs.

Base64 and Base64url

Base64url replaces + with - and / with _, because + and / mean something in URLs and file paths, and it usually drops the trailing =. It's the format of JWTs and of many tokens in links. This decoder accepts both without you having to choose.

VariantExtra characters= at the endWhere it's used
Base64 (RFC 4648, section 4)+ /YesBasic header, Kubernetes, MIME, PEM, data URI
Base64url (RFC 4648, section 5)- _Usually notJWT, URL parameters, file names

Why the decoded text looks wrong

If you see things like ç instead of ç, the text was written as UTF-8 and read as Latin-1, or the other way around. Here the text is read as UTF-8 and, if the bytes aren't valid UTF-8, as Windows-1252 with a warning. If the whole output is gibberish, the content isn't text at all: it may be an image, a PDF, a ZIP or gzip. In that case the page names the type and offers a download.

Base64 in the terminal

On Linux, echo -n 'text' | base64 encodes and base64 -d decodes. macOS uses the same command; older versions use -D to decode. In PowerShell, [Convert]::ToBase64String([Text.Encoding]::UTF8.GetBytes('text')) encodes. Without -n, echo adds a line break and the Base64 changes: echo -n user gives dXNlcg==, and echo user gives dXNlcgo=.

Base64 protects nothing

Base64 only changes how the bytes are written. A Kubernetes Secret without etcd encryption and access control is readable by anyone who can read it, and a Basic header over HTTP without TLS hands the password to anyone on the path. To hide a value, use encryption; to prove it hasn't changed, use a hash or an HMAC.

Base64 frequently asked questionsFrequently asked questions

Decoding, common errors, Basic headers, Kubernetes and privacy.