Encode any text to Base64 and decode it back — Unicode-safe in both directions (emoji and accents survive), with the URL-safe variant JWTs use, live as you type.
How to use it
- Pick the direction: Text → Base64 or Base64 → Text.
- Paste — the result appears live. Encoding offers a URL-safe checkbox.
- Copy the output.
Where Base64 shows up
Authorization headers (Basic credentials), JWT segments, data-URI images in CSS, email
attachments, config values that must survive text-only pipelines, webhook payloads, and the
occasional log line hiding something interesting. Half the time the job is decoding something
you found; the other half is encoding something so a text-only channel can carry it. Both
directions here handle real text correctly — UTF-8 first, then Base64 — which is exactly the
step naive tools skip and the reason accented text comes out mangled elsewhere.
The two alphabets, demystified
Standard Base64 ends up with +, /, and = — three characters with jobs of their own inside
URLs. The URL-safe variant substitutes - and _ and drops the padding, which is why a JWT
never needs escaping. Encode with the checkbox when the output is headed into a URL or token;
when decoding, paste either form — the tool normalizes automatically, padding or not. (JSON
inside the decoded result? The JSON formatter is next door, and
percent-encoded strings go to the URL decoder.)
Private by design
The strings people paste into Base64 tools are credentials embarrassingly often. Nothing here leaves your browser — encode and decode run on your device, unlogged and unstored.