Convert text to Base64 and back in real time. Switch between the standard and URL-safe alphabets and handle full Unicode correctly. Handy for data URLs, HTTP headers, API payloads and debugging encoded strings.
A UUID identifies a record — never use it as an authentication token.
Math.random() is predictable. Use the CSPRNG for tokens, IDs and secrets.
Decoding is not verifying. Always validate the signature and claims on the server.
Generate keys here, then store them in environment variables or a vault.
Convert text to Base64 and back in real time. Switch between the standard and URL-safe alphabets and handle full Unicode correctly. Handy for data URLs, HTTP headers, API payloads and debugging encoded strings.
Select Encode to turn text into Base64, or Decode to turn Base64 back into readable text.
URL-safe replaces + and / with - and _ so the result can be embedded in URLs and filenames.
The output updates as you type — copy it with one click.
| Plain text | Base64 |
|---|---|
| Hello | SGVsbG8= |
| password | cGFzc3dvcmQ= |
| Bright Coding | QnJpZ2h0IENvZGluZw== |
| 1 + 1 = 2 | MSArIDEgPSAy |
Spaces, symbols and Unicode are all preserved on decode.
It is completely free, private and requires no signup.
Use the tool nowNo. Base64 is only an encoding — anyone can decode it. Never use it to hide passwords or secrets.
It encodes 3 bytes into 4 characters, so the output is about 33% larger than the input.
A variant that swaps + and / for - and _ so the string is safe inside URLs, query strings and JWT segments.
Yes. Text is UTF-8 encoded before conversion, so accents, Arabic, Chinese and emoji all round-trip correctly.
Explore the whole collection — no signup, 100% free & private.