A cheat sheet for your terminal.
A few small, copyable recipes for everyday engineering. These examples use harmless sample data and UTF-8 text.
macOS and Linux
Use printf to avoid the extra newline that echo usually adds. Command-line options vary between platforms.
# Encode text (macOS and Linux)
printf '%s' 'Hello, world!' | base64
# Decode on Linux (GNU coreutils)
printf '%s' 'SGVsbG8sIHdvcmxkIQ==' | base64 --decode
# Decode on macOS
printf '%s' 'SGVsbG8sIHdvcmxkIQ==' | base64 -D
# Encode a file without line wrapping on GNU/Linux
base64 -w 0 sample.bin
# Encode a file without line wrapping on macOS
base64 -i sample.bin -b 0
JavaScript in Node.js
const text = 'Hello, ไธ็ ๐';
const encoded = Buffer.from(text, 'utf8').toString('base64');
const decoded = Buffer.from(encoded, 'base64').toString('utf8');
// URL-safe alphabet; padding is omitted
const token = Buffer.from(text, 'utf8').toString('base64url');Nodeโs decoder is permissive. If validating external input, check its alphabet and padding for your protocol before decoding.
JavaScript in a browser
btoa() expects one-byte characters; do not pass arbitrary Unicode directly to it. Convert text to UTF-8 bytes first. This example is for short strings.
const bytes = new TextEncoder().encode('Hello, ไธ็ ๐');
const encoded = btoa(Array.from(bytes, b => String.fromCharCode(b)).join(''));
const decodedBytes = Uint8Array.from(atob(encoded), c => c.charCodeAt(0));
const text = new TextDecoder('utf-8', { fatal: true }).decode(decodedBytes);
Python 3
import base64
raw = 'Hello, ไธ็ ๐'.encode('utf-8')
encoded = base64.b64encode(raw).decode('ascii')
decoded = base64.b64decode(encoded, validate=True).decode('utf-8')
url_safe = base64.urlsafe_b64encode(raw).decode('ascii')
# Remove '=' only when your protocol requires no padding.
Measure bytes, not characters
An emoji may use four UTF-8 bytes. Character counts, JavaScript string lengths, and byte counts can all differ. For padded Base64, calculate size using 4 ร ceil(byteLength / 3). On this site the input counter reports UTF-8 bytes.
Keep real credentials out of shell history, command arguments, logs, and screenshots. Use a safe local file or an approved secret-handling workflow when needed.
Reference documentation
See Node.js Buffer, Pythonโs base64 module, MDN btoa(), and GNU base64.