RFC 4648 test vector
foobar → MZXW6YTBOI======, and f → MY======.
Encode text to Base32 (RFC 4648) or decode Base32, including authenticator secrets.
Runs in your browser — nothing you enter is sent to a server.
Base32 turns bytes into text made of only the letters A–Z and the digits 2–7. Every 5 bytes (40 bits) become 8 characters of 5 bits each; the end is padded with = to a multiple of 8. Text is converted to UTF-8 bytes first, so any language works.
Decoding ignores upper and lower case, spaces, dashes and missing padding, as authenticator apps do. If the bytes aren't text — for example a two-factor (TOTP) secret — they are shown as hex.
5 bytes → 8 characters (40 bits)
So Base32 is 60% larger than the original, compared with 33% for Base64 — the price of using only 32 unambiguous characters.
foobar → MZXW6YTBOI======, and f → MY======.
The secret GEZDGNBVGY3TQOJQ decodes to the text 1234567890. Most real secrets are random bytes and show as hex.
Base32 is case-insensitive and avoids characters that are easy to confuse (0 and O, 1 and I) or awkward in URLs and file names (+ and /). That makes it good for codes people type, such as 2FA secrets.
Standard Base32 never uses them. A code with 0 usually meant the letter O, 1 the letter I and 8 the letter B.
No. Anyone can decode Base32. Never treat an encoded secret as protected.
Encode text to Base64 or decode Base64 to text, with full Unicode support and URL-safe output.
Developer Tools
Generate time-based one-time passwords from a 2FA secret or otpauth link, like an authenticator app.
Security Tools
Percent-encode text for URLs and query strings, or decode %20-style encoded text back to readable text.
Developer Tools