InTheTab We never get your data

Base64 decode and encode without uploading

Encodes text as UTF-8 Base64. Decode accepts standard or URL-safe input, with or without padding. Everything runs in this tab.

How to decode or encode Base64

  1. Paste your text. Base64 to decode, or plain text to encode.
  2. Click Decode or Encode. The result appears on the right.
  3. Copy the result. If the input can’t be decoded, the error appears under the buttons.

Good to know

  • Unicode is handled. Text is encoded as UTF-8 bytes first, so accents, non-Latin scripts and emoji round-trip correctly (unlike calling btoa() on them directly, which throws).
  • Encode uses the standard alphabet. The output uses A–Z a–z 0–9 + / with = padding, on one line. There’s no URL-safe output option: for that, swap + for - and / for _, and drop the =.
  • Decode is forgiving. It accepts the URL-safe alphabet (- and _), missing = padding, and line breaks or spaces, so wrapped MIME-style Base64 and JWT segments decode as they are.
  • The decoded bytes must be UTF-8 text. This is a text tool. If the Base64 holds an image, a PDF or other binary data, you get an error (in Chrome, The encoded data was not valid.) rather than garbled output.
  • Other characters are errors. Anything outside the two alphabets, such as $ or ., fails with your browser’s message (in Chrome, The string to be decoded is not correctly encoded.). So does a length that can’t be valid Base64.
  • Base64 is not encryption. Anyone can decode it. It’s a way to carry bytes through text-only channels, not a way to hide them.

Your data stays on your device

Base64 strings are often credentials in disguise: Basic auth headers, API keys, Kubernetes secrets, JWT segments. Decoding one on a random website hands over whatever is inside. Here, encoding and decoding happen inside this browser tab with your browser’s built-in functions.

The page’s security policy tells your browser to block uploads, so your data can’t leave your device even by accident. You can check: open your browser’s developer tools, watch the Network tab, and decode something. How InTheTab works

You’ll also see a few small requests to Google Analytics. That’s our visit counter, and it never receives your files. Privacy policy

Questions

How do I decode URL-safe Base64?

Paste it and click Decode. - and _ are read as + and /, and missing padding is added for you.

Why does decoding say “The encoded data was not valid”?

The Base64 decodes to bytes that aren’t UTF-8 text, such as an image or a compressed file. This tool only shows decoded text, so it stops rather than showing broken characters.

Is it safe to decode secrets here?

Yes. Nothing is uploaded. We never get your files or text: the site has no accounts, and its only analytics, Google Analytics, counts visits without ever seeing what you add here.

Can I encode a file?

No. This tool encodes and decodes text you paste. It doesn’t take files.