Base64, URL and Hex encoder / decoder
Encode or decode text as Base64 (standard and URL-safe, padded or unpadded), URL (component and form style), Hex and HTML entities. See the position of an invalid character, look at the UTF-8 byte count and a byte dump, and turn a file (up to 10 MB) into Base64. Everything happens in your browser; nothing is sent.
Base64, URL and Hex are not encryption: they are encodings anyone can reverse. Do not think you are "hiding" a password, a key or personal data with them.
The text is turned into UTF-8 bytes and then encoded in the chosen format.
The conversion runs in your browser; the text you type and the file you choose are not sent anywhere or stored.
File to Base64
Choose a file (at most 10 MB). The file is read in your browser and turned into Base64; it is not sent anywhere.
The tool is designed for UTF-8 text; text in another character encoding (e.g. Windows-1254) must first be converted to UTF-8. HTML entity decoding recognises only common named entities (Latin-1, Turkish letters, typographic marks, some symbols) and numeric entities; names outside the table are left as they are. If the decoded text comes from an untrusted source, do not insert it directly into a page.
Would you like to design and secure the data exchange between your systems (authentication, signed payloads, file transfer) together?
Request a call01
How to use
A
Choose the direction (encode or decode) and the format, then paste the text. When decoding, the tool guesses which encoding the input looks like.
B
Copy the output. If there is an error you see the line, column and position of the invalid character; the UTF-8 byte count and a byte dump sit below.
C
To turn a file into Base64 choose it in the "File to Base64" section (at most 10 MB); copy or download the result.
02
Base64 is not encryption
Base64 turns binary data (an image, a key, a compressed file) into text made only of letters, digits and a few marks, so it can pass through channels that carry text only, such as e-mail, JSON, URLs or XML. It provides no secrecy: it is a representation without a key that anyone can reverse in one step. Converting a password, a token or personal data to Base64 does not protect it.
The same holds for URL encoding and Hex. Real confidentiality needs encryption (for example AES-GCM), and integrity and identity need a signature or an HMAC; an encoding does not replace them.
03
Standard and URL-safe Base64, padding
Standard Base64 (RFC 4648) uses + and / in its 64-character alphabet; because those two characters have special meaning in URLs and file names, the URL-safe variant replaces them with - and _. JWTs, web push keys and many API tokens use the URL-safe variant. Every 3 bytes become 4 characters, which is why Base64 makes data about one third larger.
Padding (=) completes the length of the output to a multiple of 4. Padding is technically redundant and is dropped in formats such as JWT; this tool accepts unpadded input, but a string whose length is 4n+1 can represent no data and is reported as an error. For character errors the position is shown as line and column.
04
URL, Hex, HTML entities and UTF-8
URL encoding has two common forms. encodeURIComponent turns a space into %20 and leaves ! ' ( ) * ~ open; the application/x-www-form-urlencoded form of HTML forms turns a space into + and leaves only letters, digits and *-._ open. So a + in a query string means a space or a plus depending on the form; choose the right mode when decoding.
Text is always turned into UTF-8 bytes first: Latin letters take 1 byte, letters such as ç ğ ı ö ş ü take 2, most symbols 3 and an emoji 4. That is why the byte count can be larger than the character count. If decoded text shows broken characters such as ç, the source is usually UTF-8 text that was read as another encoding. HTML entities (& < é é) are for safely putting text into a page; the tool decodes them from a table and does not hand them to a page engine.
FAQ
- Is Base64 a safe way to store or hide something?
- No. Base64 is an encoding, not encryption. It needs no key and anyone reverses it in one step. To hide a password or personal data use encryption, and to store passwords use a salted password hash (Argon2, bcrypt, scrypt or PBKDF2).
- Why does Base64 make data larger?
- Every 3 bytes (24 bits) become 4 characters of 6 bits, which is about 33% growth (a little more with padding and line breaks). A 10 MB file becomes a text of about 13.3 million characters.
- When do I need URL-safe Base64?
- When the output will go into a URL, a file name, a cookie or a token such as a JWT. The + and / of the standard alphabet have special meaning in URLs and = can break a query string. The URL-safe variant uses - and _ and is usually written without padding.
- What is the difference between encodeURIComponent and the form style?
- Spaces and marks. encodeURIComponent writes a space as %20 and leaves ! ' ( ) * ~ as they are. The form style (application/x-www-form-urlencoded) writes a space as + and leaves only letters, digits and *-._ open. Decoding in the wrong mode turns a + into a space or a space into a plus.
- Turkish or German characters come out broken (ç, ü) when I decode. Why?
- The byte sequence is most likely UTF-8 that was read as another encoding or that was encoded twice. This tool reads the bytes as UTF-8; if the bytes are not valid UTF-8 it says so and shows the raw byte dump. Check the encoding of the source system (UTF-8 or Windows-1254/1252).
- Is decoding HTML entities safe? Could a script run?
- In this tool decoding is table-based; the text is never handed to a page engine (innerHTML) and no script runs. The decoded text can still contain something like <script>, and if you insert it directly into another page it will run there. Use the output only as text or escape it correctly for its context.
Let us make the data flow between your systems secure
We design encoding, signing, authentication and error handling for the data flows between CRM, ERP and third-party systems. Let's talk through your current flow in a free discovery call.