Developer tool · runs in your browser
Base64 encode and decode online, with SHA-256 hashes
Type or paste text in the box below. The Base64 result and the SHA-1, SHA-256, SHA-384 and SHA-512 hashes update as you type. Paste Base64 into the decode box to get the text back.
Free, no account, no job limit. Nothing is uploaded.
Encode to Base64
Decode insteadThe file is read on this device and never sent anywhere. The whole file is hashed; very long Base64 output is shortened on screen only.
Decode from Base64
Encode insteadHashes of the encoded source
Check a download against its checksum
Switch the source above to File from this device, pick the download, then paste the value from the download page. The result says Match or No match and which hash it matched.
or drop a file here to open it in the full-page workspace
How it works
- 1
Type, paste or pick a file
Text is turned into UTF-8 bytes first, so characters such as ü or emoji encode correctly. A file is read as bytes on your device.
- 2
Read the result as you type
Base64 or Base64URL output and four SHA hashes update on every change. The decoder accepts either alphabet, with or without padding, and names the character that breaks a string.
- 3
Copy, download or compare
Copy the Base64 or any single hash, download the output as a file, or paste a published checksum to see whether your file matches.
Base64, Base64URL and hashes in short
What Base64 does
Base64 writes any bytes with 64 printable characters. Three bytes become four characters, so the output is about one third longer than the input. It is encoding, not encryption: anyone can decode it without a key. Use it to put binary data into text formats such as JSON, email or data URIs.
When to use Base64URL
Base64URL uses - and _ in place of + and /, and usually drops the = padding. The result can go into a URL or a file name without escaping. The decoder on this page reads both forms.
Which hash to use
For checking a download, SHA-256 is the usual choice. A SHA-256 hash is 32 bytes: 64 characters in hex or 44 in Base64. If a published checksum does not match, check whether it is written in hex or Base64 before assuming the file is damaged. This page does not offer MD5, because the browser's Web Crypto API does not include it and MD5 collisions have been practical since 2004. It also does not create password hashes; passwords need a slow, salted algorithm made for that purpose.
Questions
What is the difference between Base64 encoding and hashing?
Base64 is reversible: you can decode the output back to the original bytes. A hash is one-way: you cannot get the input back from it. Use Base64 to carry binary data as text. Use a hash to check that data has not changed.
Which hash algorithms does this tool create?
SHA-1, SHA-256, SHA-384 and SHA-512, shown as lowercase hex, Base64 or Base64URL. MD5 and bcrypt are not offered. For file checks, SHA-256 is the usual choice.
Is Base64 a form of encryption?
No. Base64 is encoding, not encryption. Anyone can decode a Base64 string without a key. It makes binary data safe for text-based transport (URLs, JSON, email) but keeps nothing secret.
Can I verify a file checksum with this tool?
Yes. Switch the source to a file, pick the download, and paste the expected checksum from the download page. The tool compares it with all four SHA hashes in hex and Base64 and shows Match or No match.
Does any data leave my browser?
No. Encoding, decoding, hashing and checksum checks run in your browser with the Web Crypto API and JavaScript. No data is sent to a server, and there is no daily job limit for this tool.