How to use
- Choose Encode to turn text into Base32, or Decode to turn Base32 back into text.
- Pick the variant. RFC 4648 is the default and the one used by TOTP secrets and most libraries.
- Type or paste your input, or open a file. The result updates as you type.
- Copy the result or download it as a file.
What is Base32?
Base32 represents binary data with 32 printable characters. Each character carries 5 bits, so every 5 input bytes become 8 output characters. The output is about 60% larger than the input, which is more overhead than Base64, but the alphabet avoids lowercase letters and easily confused symbols.
The standard alphabet defined in RFC 4648 uses the letters A-Z and the digits 2-7. The digits 0, 1, 8 and 9 are left out so they cannot be mistaken for the letters O, I and B. When the input length is not a multiple of 5 bytes, the output is padded with = to a multiple of 8 characters.
Where Base32 is used
- Two-factor authentication. TOTP and HOTP secrets in authenticator apps (the
secret=value in anotpauth://link) are Base32 strings. - Case-insensitive systems. Because the alphabet has a single letter case, Base32 survives file systems, DNS labels and email addresses that ignore case.
- Human-typed codes. License keys, onion addresses and short identifiers use Base32 so they are easier to read aloud and type.
If size matters more than readability, Base64 is more compact. If you need short identifiers without confusing characters, compare Crockford Base32 and Base58.
Base32 variants
| Variant | Alphabet | Typical use |
|---|---|---|
| RFC 4648 | A-Z 2-7 | TOTP secrets, general purpose |
| Base32hex | 0-9 A-V | Sort order matches the raw bytes, DNSSEC NSEC3 |
| Crockford | 0-9 A-Z without I, L, O, U | Readable IDs, ULID |
| z-base-32 | lowercase, permuted | Human-oriented keys, OpenPGP WKD, ZRTP |
Base32 in code
# Python
import base64
base64.b32encode(b'hello') # encode
base64.b32decode('NBSWY3DP') # decode
// Node.js has no built-in Base32; use a package such as "hi-base32"
// Go (import "encoding/base32")
base32.StdEncoding.EncodeToString(data)
Specification
| Alphabet | A-Z 2-7 |
|---|---|
| Output size | 8 characters per 5 bytes (160%) |
| Padding | = to a multiple of 8 characters |
| Standard | RFC 4648 section 6 |
| Case sensitive | No |
Examples
| Input (UTF-8) | Output |
|---|---|
Hello, World! | JBSWY3DPFQQFO33SNRSCC=== |
Base64.is | IJQXGZJWGQXGS4Y= |
你好 | 4S62BZNFXU====== |
Frequently asked questions
Is Base32 case sensitive?
The RFC 4648 alphabet is defined in uppercase, but this decoder accepts lowercase input too. Use the Lowercase option if you need lowercase output.
Why does my Base32 string end with = signs?
The equals signs are padding that fills the last block to 8 characters. Many systems, including most TOTP apps, accept Base32 without padding. Turn padding off to remove it.
How much larger is Base32 than the original data?
Every 5 bytes become 8 characters, so Base32 output is about 1.6 times the size of the input. Base64 is about 1.33 times.
Can I decode a TOTP secret with this tool?
Yes. Paste the secret into the Decode tab and choose Hex output to see the raw key bytes. Spaces in the secret are ignored.