Encode and decode Base64, URLs and HTML entities. Handles emoji.
People decode Base64 to read something that was packed into it: the middle part of a web token, a value in a log line, a string from an API response or a header copied from a request. This page opens on the Base64 tab in decode mode. Paste the text and the result appears as you type. Both alphabets are accepted, so a value with - and _ works as well as one with + and /, spaces and line breaks are ignored, and missing = padding does not matter. The bytes are read as UTF-8, so accents and emoji come back correctly. If the Base64 is valid but the bytes are not text, as with an image, a compressed file or an encrypted blob, the page says that it is not text and offers the bytes as a download, not a screen of broken characters. If the input is not Base64 at all, the message points to the first character that does not belong. Decoded markup such as a script tag is shown as plain text and is never run.
Base64 turns bytes into letters, digits, + and /. Text is not bytes until you pick an encoding, and this tool always uses UTF-8, the encoding most websites and APIs use. That is why héllo ✓ becomes aMOpbGxvIOKckw==: the letter é takes two bytes and the check mark takes three. The browser's own btoa function only accepts characters up to U+00FF. It throws an error on ✓ or an emoji, and it quietly gives aOlsbG8= for héllo, which is Latin-1 bytes and not what an API expecting UTF-8 wants. This tool converts the text to UTF-8 bytes first, so accents, Chinese characters and emoji all round-trip. The URL-safe option swaps + and / for - and _ and drops the = padding, the form used in web tokens and file names. When decoding, both alphabets are accepted, spaces and line breaks are ignored, and missing padding is fine. If the bytes are not valid UTF-8, for example the decoded bytes of an image, the tool says so and offers the bytes as a download instead of showing garbage. Base64 is an encoding, not encryption: anyone can reverse it.
A URL uses a few characters for structure: / separates path parts, ? starts the query, & separates parameters, = joins a name to a value and # starts the fragment. Whole value mode uses encodeURIComponent, which escapes all of those, so use it for one piece, such as a search term that will sit after q=. Whole address mode uses encodeURI, which leaves those characters alone and escapes only what cannot appear in an address at all, such as spaces and accents, so use it on a full link. For a b&c=d/é the first gives a%20b%26c%3Dd%2F%C3%A9 and the second gives a%20b&c=d/%C3%A9. Decoding follows the same mode: decodeURIComponent undoes every %XX, while decodeURI leaves %26 and %3D escaped. The tool does not turn + into a space or back, because + only means a space in form data, not in the rest of a URL. A % that is not followed by two hex digits is reported in plain words, not as an error code.
HTML entities write a character as text that a page shows as that character: < for <, & for &, ' for an apostrophe. Encoding replaces & < > " and ' so that text can sit inside a page or an attribute without being read as markup. The optional setting also writes every character above ASCII, such as é or an emoji, as a numeric entity like é. Decoding handles named entities from a built-in list of about 250 common names, plus decimal (A) and hexadecimal (A) numbers. A name that is not in the list, such as &foo;, is left as written, so uncommon names stay as they are. A number that is zero, a surrogate or above U+10FFFF becomes the replacement character. Decoding runs once, so &lt; becomes < and not <. The text is never loaded as a web page: the tool replaces entities in a plain string and shows the result in a read-only box, so a pasted script tag or an image with an onerror handler stays as literal text. It is shown, not run.
On the Base64 tab you can also choose a file of up to 5 MB and get its data URI, the data:image/png;base64,... form used inside HTML and CSS. The file is read in this tab by your browser and never uploaded; a data URI is about a third longer than the file. The box shows the first 200 characters, and the Copy and Download buttons hold the whole value. Text can be up to 1,000,000 characters, and a long result shows its first 100,000 characters with the full value on Copy. Turning Base64 back into a picture or file is not offered; if decoded bytes are not text, you can download the raw bytes. The page counts visits with Google Analytics, using only the name of the tool, the fact that a result appeared or a button was pressed, and a rough size group such as 1 to 10 MB when you choose a file, never your text or your file. The text is not put in the address bar and is not saved. The tab, direction and options are remembered on this device.
A token has three parts split by dots. The first two are URL-safe Base64 of JSON, so you can paste one part at a time and read it. The third part is a signature and usually decodes to bytes, not text, so the page offers it as a download.
It counts the characters you typed, starting at 1 and counting spaces, up to the first one that is not allowed in Base64. In !!!abc the position is 1. An = in the middle of the text, or three = at the end, is also pointed out.
Not as an image. If the bytes are not UTF-8 text, the page lets you download the raw bytes as a .bin file. Rename it, for example to .png, if you know what it is. Nothing is previewed.
No. Base64 only rewrites bytes with 64 letters and symbols, and anyone can decode it, as you can on this page. SGVsbG8= is Hello. Do not use it to hide a password or a token; use real encryption for that.
btoa works on Latin-1 characters only. For héllo it gives aOlsbG8=, and for ✓ or an emoji it throws an error. This tool encodes the text as UTF-8 first and gives aMOpbGxvIOKckw==, which is what most servers and libraries expect.
It is Base64 with - in place of + and _ in place of /, and the = padding at the end removed. The standard characters + and / have a meaning inside URLs and file names. For ???>>> the standard form is Pz8/Pj4+ and the URL-safe form is Pz8_Pj4-.
Use encodeURIComponent for one value that goes into a link, such as a search term, because it also escapes / ? & = and #. Use encodeURI for a whole address you want to keep working, because it leaves those characters alone and escapes spaces and accents only.
The Base64 is valid, but the bytes are not UTF-8 text. A PNG, a PDF or a zip file looks like this, for example /w== is the single byte 0xFF. The tool offers the bytes as a download instead of showing broken characters.
No. The conversion runs in this tab with your browser's own functions, and a file you choose is read in the tab as well. Nothing you type or choose is sent anywhere, and the text is not stored. Only the tool name and the fact that a result appeared or a Copy was pressed are counted.