How it works
Base64 takes 3 bytes (24 bits) at a time and splits them into four 6-bit values, each mapped to one of 64 characters. If the input is not a multiple of 3 bytes, = padding is added. Text is first converted to UTF-8 bytes, so emoji and non-Latin letters encode correctly.
Standard vs URL-safe Base64
Standard Base64 uses + and /, which have special meaning in URLs. URL-safe Base64 replaces them with - and _ and usually drops the = padding — used in JWTs, signed URLs and file names. The decoder accepts both.
Common uses
- Data URLs for small images:
data:image/png;base64,… - HTTP Basic authentication headers (
Authorization: Basic …). - Email attachments (MIME).
- Reading the payload of a JWT (its middle part is URL-safe Base64 JSON).
Base64 is not encryption
Anyone can decode Base64 instantly. Never use it to protect passwords or secrets. For one-way fingerprints use the Hash Generator; for URL parameters use the URL Encoder.
Frequently asked questions
Is Base64 encryption?
No. It is an encoding anyone can reverse. Do not use it to protect sensitive data.
Why is Base64 output longer than the input?
Base64 uses 4 characters for every 3 bytes, so encoded data is about 33 percent larger.
What is URL-safe Base64?
A variant that uses - and _ instead of + and / and usually omits = padding, so it can be used in URLs and file names.
Does it support emoji and accents?
Yes. Text is converted to UTF-8 before encoding, so all characters work.

