Base64 is one of those formats every developer has used but few can explain without pausing. It looks like random characters. It makes data bigger. And yet it’s the backbone of email attachments, JWT payloads, data URIs, and dozens of other protocols that need to move binary data over text-only channels.
A Base64 decoder is one of the most common developer utilities — and most of the free ones online send your data to a server.
What Base64 actually does
Base64 encodes arbitrary binary data as printable ASCII characters. Every 3 bytes of input becomes 4 characters of output, using a 64-character alphabet (A-Z, a-z, 0-9, +, /). The = character pads the output when the input length isn’t a multiple of 3.
The trade-off: Base64 increases data size by roughly 33%. A 1KB image becomes about 1.3KB of text.
Base64 is encoding, not encryption. Anyone can decode it. If you’re putting sensitive data in Base64, you’re obscuring it, not protecting it.
Standard vs URL-safe Base64
Not all Base64 is identical:
| Variant | Alphabet | Padding | Used in |
|---|---|---|---|
| Standard | A-Za-z+/= |
Yes | Email (MIME), general transport |
| URL-safe | A-Za-z-_ |
No | JWTs, URL parameters, filenames |
| No padding | A-Za-z+/ |
No | Some APIs, compact storage |
The - and _ in URL-safe Base64 replace + and /, which are special characters in URLs. When you’re debugging a JWT or a data URI and decoding fails, check whether the encoder used URL-safe or standard Base64.
Where developers encounter Base64
JWT payloads. The three parts of a JWT (header, payload, signature) are each URL-safe Base64-encoded. Decoding a JWT means reversing the Base64url encoding on each segment. See our JWT decode guide for more.
Data URIs. data:image/png;base64,iVBOR... inlines images directly in HTML or CSS. The image bytes are Base64-encoded so they can appear in a text attribute.
Email attachments. MIME (RFC 2045) uses Base64 to encode binary attachments. If you’ve seen a .eml file with long strings of random characters, that’s Base64-encoded content.
APIs. Some APIs accept or return Base64-encoded binary data (file uploads, image processing, cryptographic signatures). Less common now that most APIs support multipart form data, but it still shows up.
How to decode Base64 in your browser
The fastest way:
echo 'SGVsbG8gV29ybGQ=' | base64 -d
# → Hello World
For URL-safe Base64 (JWTs, URL parameters), you need to swap - → + and _ → / first:
echo 'eyJzdWIiOiIxMjM0NSJ9' | tr '_-' '/+' | base64 -d
If you’d rather not memorize the tr dance, a browser-based decoder handles both variants automatically. The Base64 converter on DevSpeedTools encodes and decodes standard and URL-safe Base64 with full UTF-8 support. Paste a string, get the decoded output — no server, no upload.
Common Base64 mistakes
- Using standard Base64 in URLs. The
+and/characters break URL parsing. Use URL-safe Base64 for URLs and JWTs. - Forgetting UTF-8 encoding. Base64 operates on bytes, not characters. If you’re encoding text with non-ASCII characters, encode as UTF-8 first, then Base64-encode the bytes.
- Treating Base64 as encryption. It’s encoding. Anyone can decode it. Don’t put secrets in Base64 without additional protection.
- Ignoring padding. Some parsers require padding (
=), others don’t. If decoding fails, try adding or removing padding.
Encode and decode now
If you need to encode or decode Base64, use a browser-based tool. The Base64 converter on DevSpeedTools handles standard and URL-safe Base64 with UTF-8 support. No upload, no server — all processing happens in your browser using btoa() and atob().