Base64 Encoder & Decoder

Convert strings, special characters, and binaries into RFC 4648 compliant Base64 representations securely.

๐Ÿ›ก๏ธ 100% Client-Side Processing: Secrets and strings are encoded locally without network requests.
0 chars | 0 lines(Ctrl+Enter) Input Text / Base64 Data
0 chars | 0 lines(Ctrl+Enter) Output Result

Base64 Architecture: RFC 4648 Bit Splitting & URL-Safe Encoding

Base64 bridges the gap between raw binary bytes and legacy 7-bit ASCII transmission channels. It converts groups of 24 input bits (3 bytes) into four 6-bit chunks, with each chunk indexing a character in a 64-symbol table.

Format Specifications & Syntax Reference

Specification ParameterStandard Value / Parsing Behavior
Payload Overhead+33.3% size inflation (4 output chars per 3 input bytes)
IETF SpecificationRFC 4648 ยง4 (Standard) & ยง5 (URL / Filename Safe)
Standard AlphabetA-Z, a-z, 0-9, +, / (Padding: =)
URL-Safe AlphabetA-Z, a-z, 0-9, -, _ (No padding in JWTs)

โš ๏ธ Common Engineering Edge Cases & Gotchas

  • Why does btoa() fail with InvalidCharacterError on Unicode or Chinese characters: Browser window.btoa() expects binary strings where character codes are strictly between 0 and 255 (Latin1). Multibyte UTF-8 characters exceed this range, throwing DOMException. Convert string to UTF-8 bytes using TextEncoder before passing to btoa().
  • Why does Base64 data corrupt when passed inside URL query parameters: Standard Base64 contains '+' which HTTP query string parsers decode as a literal space ('%20'). Always use RFC 4648 ยง5 URL-Safe Base64 (swapping '+' for '-' and '/' for '_') to prevent delimiter corruption.

Production Implementation Examples

Node.js / Modern Browser (UTF-8 Safe)

// Native TextEncoder prevents Latin1 InvalidCharacterError
function toBase64(text) {
  const bytes = new TextEncoder().encode(text);
  const bin = Array.from(bytes, b => String.fromCharCode(b)).join('');
  return btoa(bin);
}

function fromBase64(b64) {
  const bin = atob(b64);
  const bytes = Uint8Array.from(bin, c => c.charCodeAt(0));
  return new TextDecoder().decode(bytes);
}

// URL-Safe Base64 (RFC 4648 ยง5 - used in JWT headers and OAuth 2.0 PKCE)
function toBase64Url(text) {
  return toBase64(text).replace(/\+/g, '-').replace(/\//g, '_').replace(/=+$/, '');
}

Python 3

import base64

raw_bytes = "Hello UTF-8 ๐Ÿš€".encode("utf-8")
std_b64 = base64.b64encode(raw_bytes).decode("ascii")

# URL-Safe Base64 (swaps '+' for '-', '/' for '_', strips padding)
url_b64 = base64.urlsafe_b64encode(raw_bytes).rstrip(b"=").decode("ascii")

# Safe decoding with automatic padding restoration
padding_needed = (4 - len(url_b64) % 4) % 4
decoded = base64.urlsafe_b64decode(url_b64 + "=" * padding_needed).decode("utf-8")

High-Throughput Processing & Memory Safety Bounds

Client-side parsing and data transformation operates against browser V8 memory limits. When manipulating large documents or high-volume datasets approaching the 2MB boundary, synchronous operations can block the main execution thread. Production web applications should delegate heavy serialization and formatting jobs to background Web Workers or leverage streaming parsers (such as the WHATWG TransformStream interface) to maintain interface responsiveness during heavy data ingestion. Ensure robust UTF-8 multi-byte sequence validation to prevent surrogate pair slicing and payload corruption. Incorporate automated benchmark assertions into build pipelines to intercept algorithmic complexity regressions before production release.

Official Standards & Format Specifications