2 tools

Base64 Encoding and Decoding Tools

Base64 rewrites arbitrary bytes using 64 characters that survive any text channel, at a cost of roughly 33% size growth. It is how binary data travels inside JSON strings, email bodies, data URIs and HTML attributes.

The single most important thing about it is that it is not encryption. Anyone can decode base64 instantly with no key. Base64 in a token, a config file or a header conceals nothing at all, and treating it as protection is a recurring security mistake.

Two details cause most failures. There are two alphabets (standard base64 uses + and /, while base64url uses - and _ because the former have meaning in a URL), and decoding with the wrong one fails or produces garbage. And because base64 encodes bytes rather than characters, non-ASCII text must be converted to UTF-8 first, or the result is mojibake.

Working with Base64

Practical guides for the tools above, including the checks to make before relying on the result.

  • Base64 encoding explained

    How Base64 works, why it exists, what the padding means, the difference between standard and URL-safe variants, and why it is encoding rather than encryption.