Base64 Encoder for developers — convert text, JSON, or files to Base64 and back. Decode JWTs, detect data URIs and Basic Auth headers automatically, and share any result via URL. Perfect for API payloads, data URIs, email MIME encoding, and Basic Auth headers. Handles Unicode correctly. Free, private, no signup.
Authorization: Basic dXNlcm5hbWU6cGFzc3dvcmQ=The string after "Basic" is the Base64 encoding of
username:password. Always use HTTPS with Basic Auth so the credential is transmitted over an encrypted connection.
background-image: url("data:image/png;base64,iVBORw0KGgoAAA...");Small images and icons can be embedded directly into a stylesheet as a data URI to reduce the number of HTTP requests.
eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxMjM0In0.abcA JWT is three Base64URL segments joined by dots: header, payload (claims), and signature. Decode the first two segments with the JWT tab above to inspect the token's contents.
Content-Transfer-Encoding: base64 header tells the client how to decode the attachment.
Tip: press ⌘/Ctrl + Enter inside any input to run the encoder or decoder.
Base64 Encoder & Decoder: Text, Files, and JWT
Base64 Encoder is a developer tool that converts text, JSON, or binary files into a text-safe Base64 representation — and back again. It also decodes JSON Web Tokens (JWT), auto-detects data URIs and Basic Auth headers, and shows you exactly what kind of content you are working with. Base64 encoding is used everywhere in modern software: API payloads, data URIs in CSS, MIME email attachments, HTTP Basic Authentication headers, JWT tokens, and configuration files for cloud services.
Our free Base64 Encoder runs entirely in your browser. Nothing is uploaded, nothing is stored. The tool handles Unicode correctly using the TextEncoder and TextDecoder APIs, supports URL-safe output, applies MIME line wrapping when needed, and can convert entire files to Base64 or ready-to-paste data URIs.
What Is Base64 Encoding?
Base64 is a scheme for representing binary data as a string of printable ASCII characters. It uses a 64-character alphabet — A–Z, a–z, 0–9, +, and / — plus a padding character =. Every three bytes of input become four characters of output, which means the encoded string is approximately 33% larger than the original.
The standard is defined in RFC 4648. A URL-safe variant replaces + with - and / with _, so the output can be safely placed in URLs, filenames, and query strings.
Auto-Detection — What Kind of Input Is This?
Most Base64 tools assume you already know what you are working with. This one tells you. When you paste an input, the tool inspects the format and identifies:
JWT tokens — three Base64URL segments separated by dots. The tool recognises them and offers a one-click jump to the JWT Decoder tab.
Data URIs — strings starting with data: that carry an embedded asset. The Base64 payload is extracted automatically for decoding.
Basic Auth headers — full Authorization: Basic ... headers or the raw base64 of a credential. The tool strips the header prefix and decodes just the payload.
JSON payloads — when the decoded output is valid JSON, the tool flags it and shows the structure.
Binary vs UTF-8 text — the tool checks for non-printable bytes and warns you if the decoded data is binary rather than text.
JWT Decoder Built In
JSON Web Tokens are the modern standard for stateless authentication. A JWT is three Base64URL segments — header, payload, and signature — joined by dots. The header describes the signing algorithm, and the payload carries claims like sub (subject), exp (expiration), iat (issued at), and aud (audience).
The JWT Decoder tab parses any JWT and shows the header and payload as formatted JSON, extracts common claims in human-readable form (with relative time like "Valid for 45m 12s"), and displays the raw signature bytes. The signature is not verified — that requires the secret or public key, which is never sent to the browser. Use the tool to inspect tokens during debugging, never as a substitute for server-side verification.
Unicode Handling — Why It Matters
Base64 encodes bytes, not characters. Many online tools use the naive btoa() function, which throws an error when the input contains any character outside ASCII — including accented letters, emoji, or text in non-Latin scripts. This tool uses the browser's TextEncoder API to convert any string to UTF-8 bytes first, then applies Base64 to those bytes. The result is correct for every language and every Unicode character.
Base64 Is Encoding, Not Encryption
It is important to be clear about what Base64 does and does not do. Base64 is a transport encoding — it makes binary data safe to carry over text-based systems. It does not protect the data. Anyone with the Base64 string can decode it back to the original bytes in a single step, with no key required.
If you need to protect data in transit or at rest, use proper encryption (AES, TLS). Base64 and encryption solve different problems, and they are often used together: encrypt first, then Base64-encode the ciphertext so it can be transmitted safely.
Shareable Links and Recent History
Every encode and decode you run is saved to a recent-items list — up to 10 entries, clickable to reload into the appropriate tab. You can also generate a shareable URL that encodes the current input in the hash, so you can bookmark a specific debugging session or send it to a teammate.
Private, Fast, and Free
All conversion happens locally in your browser using the standard Base64 algorithm. Your text, your JSON, your JWT tokens, and your files never leave your device. There is no sign-up, no data collection, and no file limit for text. Whether you are debugging an API integration, building a data URI for a stylesheet, or inspecting a JWT during an auth issue, the Base64 Encoder gives you a correct result in one click.
Frequently Asked Questions
What is Base64 encoding used for?
Is Base64 encryption?
What is the difference between Base64 and Base64URL?
+ with - and / with _, and often omits the = padding. It exists because + and / have special meaning in URLs and filenames. JWTs use Base64URL. This tool supports both, and the decoder auto-detects URL-safe input.