Base32 Encoder and Decoder

Convert text, hex bytes or files to Base32 and back. Choose the RFC 4648 alphabet, Base32hex, Crockford or z-base-32, and control padding and letter case.

Runs entirely in your browser. Nothing is uploaded.

How to use

  1. Choose Encode to turn text into Base32, or Decode to turn Base32 back into text.
  2. Pick the variant. RFC 4648 is the default and the one used by TOTP secrets and most libraries.
  3. Type or paste your input, or open a file. The result updates as you type.
  4. Copy the result or download it as a file.

What is Base32?

Base32 represents binary data with 32 printable characters. Each character carries 5 bits, so every 5 input bytes become 8 output characters. The output is about 60% larger than the input, which is more overhead than Base64, but the alphabet avoids lowercase letters and easily confused symbols.

The standard alphabet defined in RFC 4648 uses the letters A-Z and the digits 2-7. The digits 0, 1, 8 and 9 are left out so they cannot be mistaken for the letters O, I and B. When the input length is not a multiple of 5 bytes, the output is padded with = to a multiple of 8 characters.

Where Base32 is used

  • Two-factor authentication. TOTP and HOTP secrets in authenticator apps (the secret= value in an otpauth:// link) are Base32 strings.
  • Case-insensitive systems. Because the alphabet has a single letter case, Base32 survives file systems, DNS labels and email addresses that ignore case.
  • Human-typed codes. License keys, onion addresses and short identifiers use Base32 so they are easier to read aloud and type.

If size matters more than readability, Base64 is more compact. If you need short identifiers without confusing characters, compare Crockford Base32 and Base58.

Base32 variants

VariantAlphabetTypical use
RFC 4648A-Z 2-7TOTP secrets, general purpose
Base32hex0-9 A-VSort order matches the raw bytes, DNSSEC NSEC3
Crockford0-9 A-Z without I, L, O, UReadable IDs, ULID
z-base-32lowercase, permutedHuman-oriented keys, OpenPGP WKD, ZRTP

Base32 in code

# Python
import base64
base64.b32encode(b'hello')        # encode
base64.b32decode('NBSWY3DP')      # decode

// Node.js has no built-in Base32; use a package such as "hi-base32"
// Go (import "encoding/base32")
base32.StdEncoding.EncodeToString(data)

Specification

AlphabetA-Z 2-7
Output size8 characters per 5 bytes (160%)
Padding= to a multiple of 8 characters
StandardRFC 4648 section 6
Case sensitiveNo

Examples

Input (UTF-8)Output
Hello, World!JBSWY3DPFQQFO33SNRSCC===
Base64.isIJQXGZJWGQXGS4Y=
你好4S62BZNFXU======

Frequently asked questions

Is Base32 case sensitive?

The RFC 4648 alphabet is defined in uppercase, but this decoder accepts lowercase input too. Use the Lowercase option if you need lowercase output.

Why does my Base32 string end with = signs?

The equals signs are padding that fills the last block to 8 characters. Many systems, including most TOTP apps, accept Base32 without padding. Turn padding off to remove it.

How much larger is Base32 than the original data?

Every 5 bytes become 8 characters, so Base32 output is about 1.6 times the size of the input. Base64 is about 1.33 times.

Can I decode a TOTP secret with this tool?

Yes. Paste the secret into the Decode tab and choose Hex output to see the raw key bytes. Spaces in the secret are ignored.