Free Base64 Encoder and Decoder
This free Base64 encoder and decoder converts text to Base64 and Base64 back to text in one step, with the standard and URL-safe alphabets, optional padding and 76-character line wrapping. Paste a token, an email body or a data URI and it decodes it, reporting binary content instead of printing garbage. It suits developers debugging JWTs, APIs, email headers and embedded images.

Base64 Encoder and Decoder
Generators and Converters
About this tool
Base64 turns any bytes into a string of 64 printable characters (A to Z, a to z, 0 to 9, plus and slash) so binary data can travel through systems built for text: email attachments, JSON payloads, HTTP basic authentication headers, data URIs in CSS and HTML, and the three parts of a JSON Web Token. Every three bytes become four characters, so the result is about a third larger than the input, and = padding is added at the end to make the length a multiple of four.
The URL-safe variant swaps plus and slash for minus and underscore so the string can sit in a URL or a file name without escaping; JWTs and many APIs use it without padding. The decoder here accepts either alphabet, ignores spaces and line breaks, and adds missing padding, so a token copied from a browser or a log decodes without fuss. Text is treated as UTF-8 in both directions, and nothing you paste is stored.
Base64 is an encoding, not encryption: anyone can decode it, so never use it to hide a password or a key. When the decoded bytes are not readable text, for example the image inside a data URI or a binary signature, the tool shows the byte count and a hex preview rather than the raw bytes. For files, convert them with a command line tool; this page is for text up to 500 KB.
Frequently asked questions
Is Base64 a form of encryption?
No. Base64 is a reversible encoding that anyone can decode in a second, with no key involved. It exists to carry binary data through text-only channels, not to protect it. If you see a Base64 string in a config file or a URL, treat it as plain text. To keep something secret, use real encryption and keep the key out of the code.
Why does the decoded text look like garbage?
Either the input was not text to begin with, such as the image bytes inside a data URI or a binary signature, or it was text in an encoding other than UTF-8. The tool detects bytes that are not valid UTF-8 and shows a hex preview instead. If you expected text, check whether the string was compressed or encrypted before it was Base64 encoded, which is common in tokens and cookies.
What is the difference between standard and URL-safe Base64?
The alphabets differ in two characters: standard Base64 uses + and /, which have special meaning in URLs and file names, while URL-safe Base64 uses - and _ instead. JWTs, OAuth tokens and many API keys use the URL-safe form, usually without the trailing = padding. The decoder here accepts both, so you do not have to work out which one you have.
How do I decode a JWT?
A JSON Web Token is three URL-safe Base64 parts separated by dots: header, payload and signature. Paste the middle part into the decoder to read the claims, such as the user ID and expiry, and the first part to see the algorithm. The third part is a binary signature and will show as hex. Decoding a token proves nothing about its validity; only checking the signature with the key does.
