मुफ्त उपकरण

Base64 एन्कोड / डिकोड

पाठ को Base64 में एन्कोड करें या Base64 को फिर से पाठ में डिकोड करें, पूरी तरह से UTF-8 सुरक्षित, एक वैकल्पिक URL-सुरक्षित संस्करण के साथ।

What this Base64 encoder and decoder does

This is a two-way Base64 converter that runs entirely in your browser. Paste ordinary text on one side and read its Base64 representation on the other, or drop in a Base64 blob and recover the original bytes instantly. It handles the standard alphabet as well as the URL-safe variant, manages padding for you, and operates on full UTF-8 text rather than plain ASCII only, so emoji, accented letters and non-Latin scripts round-trip cleanly. You reach for a tool like this whenever some other system speaks in Base64 and you need to read or produce that format by hand: inspecting a data: URI, hand-crafting an HTTP Authorization header, pulling a value out of a YAML or JSON config, decoding a token fragment, or sanity-checking what a webhook payload actually contains before you wire it into code.

How Base64 actually works

The single most important thing to understand is that Base64 is an encoding, not encryption and not compression. Its only job is to represent arbitrary binary data using a small, safe set of printable characters, so that the data can survive channels that were designed for text: email bodies, URLs, XML, JSON strings and HTTP headers. It provides zero confidentiality. Anyone can reverse it in a fraction of a second, which is exactly what this page does. The mechanism itself is pure arithmetic on bits:

  • The input is treated as a stream of 8-bit bytes. Base64 regroups those bits into 6-bit chunks, because 2 to the 6th power is 64, precisely the size of the alphabet.
  • Every 3 bytes (24 bits) become 4 output characters (4 times 6 equals 24 bits). That fixed 3-to-4 ratio is why Base64 output is always roughly 33% larger than the input it came from.
  • The 64 symbols are A to Z, a to z, 0 to 9, plus two extras. Standard Base64 uses + and /; the URL-safe variant swaps those for - and _ so the string can live inside a URL, a filename or a cookie without needing percent-escaping.
  • When the input length is not a multiple of 3, the final group is padded with one or two = characters so the output stays a whole number of 4-character blocks. For example, "M" encodes to "TQ==", "Ma" to "TWE=", and "Man" to "TWFu" with no padding at all.

Because the transformation is fully deterministic and reversible, decoding is simply the same process run backwards: map each character to its 6 bits, concatenate the bits, and slice them back into 8-bit bytes. There is no key and no randomness anywhere in the algorithm, which is exactly why Base64 must never be mistaken for a way to protect or obscure sensitive data.

Concrete places you will run into it

Base64 is quietly everywhere in web and network plumbing. Recognising it and being able to decode it on the spot saves a surprising amount of debugging time.

  • Data URIs. A small icon or SVG embedded directly in HTML or CSS as data:image/png;base64,iVBOR... avoids a separate network request. Decode one here to confirm what image is really being served.
  • HTTP Basic authentication. The header Authorization: Basic dXNlcjpwYXNz is nothing more than user:pass run through Base64. That is why Basic auth over plain HTTP is considered effectively plaintext, and why it belongs only on encrypted connections.
  • JSON Web Tokens. A JWT is three base64url segments joined by dots: header, payload and signature. The header and payload are readable JSON, not secrets. You can Base64-decode the first two parts to inspect claims, though the signature still guards against tampering.
  • Email attachments (MIME). Binary attachments are Base64-encoded and traditionally wrapped at 76 characters per line so they pass through mail servers that only tolerate text.
  • Binary inside text formats. Certificates, keys, small blobs in Kubernetes secrets and similar values are stored as Base64 so they fit inside JSON or YAML without breaking the syntax.

Tips, common gotchas, and where your data goes

A few practical points prevent most confusion. First, never rely on Base64 to hide credentials, tokens or personal data; treat an encoded string as if it were written in the clear. Second, watch the variant: if a string contains - or _ it is URL-safe Base64, and if a standard decoder rejects it, that mismatch is usually why. Third, mind the padding; some systems strip the trailing = characters, and a decoder may need them restored to reach a valid block length. Finally, remember that encoding grows your data by about a third, so it is a poor choice for anything large where size or bandwidth matters. On the privacy side, this matters a great deal: this converter runs 100% locally in your browser using the built-in encoding functions. Whatever you paste, including auth headers, token payloads or private snippets, is processed on your own device and is never uploaded, stored or logged by us. That local-only guarantee is the whole point, and it is the same principle behind our other developer tools, letting you decode a suspicious token or a Basic auth string without ever handing it to a third-party server.

लोगों ने इस पृष्ठ को खोजकर पाया

वास्तविक खोज वाक्यांश जिनका यह पृष्ठ उत्तर देता है — लिंक किए गए वाक्यांश उस पृष्ठ को खोलते हैं जो उन्हें गहराई से कवर करता है।