Free Online Base64 Encoder and Decoder, UTF-8 Safe, URL-Safe Variant
Encode text to Base64 or decode it back, the right way for Unicode. Accented letters and emoji are handled through UTF-8, which the browser's own btoa cannot do. There is a URL-safe variant for tokens, an option to drop the padding, and a decode that tells you plainly when the input is not valid Base64.
JavaScript has a built-in btoa for Base64, and it throws an error the moment you give it a
character outside Latin-1: an accented letter, a curly quote, an emoji. That is because btoa
works on bytes and assumes each character is one byte, which stopped being true the day text
went Unicode.
This encodes through UTF-8 first, which is the step btoa skips. The text is turned
into its UTF-8 bytes, and those bytes are what get Base64-encoded, so an emoji becomes four
bytes and survives the round trip intact. Decoding reverses both steps. It means the result
here matches what a server or another language produces, rather than what the browser's own
function would if it did not throw.
Base64 is not encryption, and it hides nothing. Anyone can decode it in a second,
which is exactly what the decode side here does. It exists to carry binary or awkward text
safely through channels that expect plain ASCII, such as a data URL, an email attachment or
a JWT. Putting a secret in Base64 and thinking it is protected is a common and costly mistake.
The URL-safe variant swaps two characters, and it is not optional where it is needed.
Standard Base64 uses + and /, both of which mean something special in a URL and in a filename.
The URL-safe variant uses - and _ instead, and often drops the = padding too. A JWT uses this
variant, which is why pasting a raw JWT segment into a standard decoder sometimes fails. This
decoder accepts both without being told which one you have.
Where Your Input Goes
Nowhere. And you can check that yourself.
A token or a data URL with real content stays in your browser and is never sent anywhere.
It is all done by your own browser. Press F12, open the Network tab, and use the tool:
the page fetches its own code and nothing else. Or load the page, turn off your wifi, and
carry on. It still runs, because there was never a server in the middle.
How to Encode and Decode Base64
A few steps, and nothing is uploaded.
1
Choose a directionEncode text to Base64, or decode Base64 back to text. The boxes relabel themselves so it is clear which is which.
2
Paste your inputIt converts as you type. Accented letters and emoji are handled through UTF-8, which the browser's own btoa cannot do.
3
Pick a variant if encodingURL-safe swaps + and / for - and _, and you can drop the = padding. A JWT uses this variant.
4
Copy or downloadThe decode side accepts both the standard and URL-safe alphabets without being told which.
What to Know About Base64
Including the things this tool cannot do.
Encoding and decoding both go through UTF-8, which the browser's built-in btoa does not. btoa throws an error on any character outside Latin-1, so an accented letter or an emoji breaks it. Here the text becomes UTF-8 bytes first and those are encoded, so the result matches what a server or another language produces and survives the round trip unchanged.
Base64 is not encryption. It hides nothing and protects nothing. It is a way to carry binary data or awkward characters through a channel that only expects plain ASCII, such as a data URL or an email. Anyone can decode it instantly, which is what the decode side here does. Never put a secret in Base64 and assume it is safe.
The URL-safe variant is a real difference, not a preference. Standard Base64 uses + and /, which both have special meaning in URLs and filenames. The URL-safe variant uses - and _, and often has no = padding. A JWT is encoded this way, so a raw JWT segment will not decode in a strict standard decoder. The decoder here reads both alphabets.
Base64 makes data about a third larger, so it is a transport format, not storage. Every three bytes become four characters, which is a 33% overhead. That is a fine price for getting an image into a data URL or a token into a header, but it is the wrong choice for storing or transferring large amounts of data, where the raw bytes are smaller.
Key Features & Capabilities
What this tool does, and what it deliberately does not.
UTF-8 safeAccents and emoji survive, where the browser's own btoa throws an error.
URL-safe variantThe - and _ alphabet a JWT uses, with optional padding.
Both directionsEncode and decode, with the decoder reading both alphabets.
Clear errorsInvalid Base64 says which character is wrong instead of failing silently.
As you typeNo button. The conversion follows what you type.
Nothing uploadedA token or a data URL stays in your tab.
About the Base64 Encode / Decode
Base64 is how binary data and awkward characters travel through channels built for plain text. A small image in a data URL, a token in an HTTP header, a file in an email, the segments of a JWT: all of them are Base64. It comes up constantly, and the browser's own function for it has a sharp edge that catches people out.
That edge is Unicode. The built-in btoa works on bytes and assumes one character is one byte, so it throws the moment you hand it an accented letter or an emoji. This tool encodes through UTF-8 first, so any text works and the result matches what a server on the other end would produce. Decoding reverses both steps, and it accepts the URL-safe alphabet a JWT uses as well as the standard one.
It is worth saying plainly that Base64 is not security. It is trivially reversible, which is exactly what the decode side demonstrates. It exists to move data safely, not to hide it. The one real choice to make is the variant: standard for most things, URL-safe when the result has to live in a URL or a filename, which is a difference this tool makes visible rather than guessing.
Frequently Asked Questions
Why btoa breaks, why it is not encryption, and what URL-safe means.
Because they use the browser's built-in btoa, which only handles Latin-1 and throws on anything else. This tool encodes the text as UTF-8 bytes first, so emoji, accents and any other Unicode work and the result is what a server or another language would produce.
No. It hides nothing and anyone can decode it instantly, which is what the decode side here does. It is a transport format for getting binary or awkward data through a text-only channel. Never put a secret in Base64 and think it is protected.
Standard Base64 uses + and /, which both mean something in a URL and a filename. The URL-safe variant replaces them with - and _, and usually drops the = padding. JWTs are encoded this way. This decoder accepts both, so you do not have to know which one you were handed.
That is inherent to the format: every three bytes become four characters, a 33% overhead. It is a fine trade for embedding a small image or a token, but it means Base64 is a transport format, not a way to store or move large amounts of data.
No. Everything is encoded and decoded in your browser, which is why a token or a data URL with real content is safe to paste here. You can confirm it in the Network tab or by working offline.