Skip to content
TNToolsNexus

Base64 encode / decode

Encode text to Base64 and decode it back — Unicode-safe, URL-safe variant included, instant, and nothing leaves your browser.

Direction

Your data never leaves your browser — encoding happens on your device.

Encode any text to Base64 and decode it back — Unicode-safe in both directions (emoji and accents survive), with the URL-safe variant JWTs use, live as you type.

How to use it

  1. Pick the direction: Text → Base64 or Base64 → Text.
  2. Paste — the result appears live. Encoding offers a URL-safe checkbox.
  3. Copy the output.

Where Base64 shows up

Authorization headers (Basic credentials), JWT segments, data-URI images in CSS, email attachments, config values that must survive text-only pipelines, webhook payloads, and the occasional log line hiding something interesting. Half the time the job is decoding something you found; the other half is encoding something so a text-only channel can carry it. Both directions here handle real text correctly — UTF-8 first, then Base64 — which is exactly the step naive tools skip and the reason accented text comes out mangled elsewhere.

The two alphabets, demystified

Standard Base64 ends up with +, /, and = — three characters with jobs of their own inside URLs. The URL-safe variant substitutes - and _ and drops the padding, which is why a JWT never needs escaping. Encode with the checkbox when the output is headed into a URL or token; when decoding, paste either form — the tool normalizes automatically, padding or not. (JSON inside the decoded result? The JSON formatter is next door, and percent-encoded strings go to the URL decoder.)

Private by design

The strings people paste into Base64 tools are credentials embarrassingly often. Nothing here leaves your browser — encode and decode run on your device, unlogged and unstored.

Last updated:

Frequently asked questions

Why does my émoji/accented text break in other Base64 tools?
Because the browser's raw btoa() only handles Latin-1, and naive tools call it directly — anything beyond that either throws or corrupts. This tool encodes text as UTF-8 bytes first, so "héllo 🙂" round-trips perfectly.
What is the URL-safe variant?
Standard Base64 uses + and /, which collide with URL syntax, and = padding, which gets mangled in query strings. The URL-safe alphabet (RFC 4648 §5) swaps them for - and _ and drops padding — it's what JWTs and web tokens use. The decoder here accepts both alphabets automatically.
Is Base64 encryption?
No — this deserves a plain answer: Base64 is an encoding, reversible by anyone in milliseconds (this page proves it). It exists to move binary data through text-only channels, not to hide anything. Never treat Base64 as protection for secrets.
Why did my decode say "not valid text"?
The Base64 was valid, but the bytes inside aren't UTF-8 text — likely an image, file, or other binary payload. The message tells you that instead of printing garbage.
Is my data uploaded anywhere?
No. Encoding and decoding run entirely in your browser.

Related tools

URL Encode / Decode

Percent-encode values or whole URLs and decode them back — component vs full-URL modes explained, live, free, private.

JSON Formatter

Format, validate, and minify JSON as you paste — 2/4-space or tab indentation, clear syntax errors, copy or download. Private.

Reverse Text

Reverse text by characters, word order, or line order — instantly, with one-click copy. Emoji-safe, free, private.