Base32hex Encoder and Decoder

Convert text, hex bytes or files to Base32 with the extended hex alphabet and back. Control padding and letter case, for example to produce NSEC3-style labels.

Runs entirely in your browser. Nothing is uploaded.

How to use

  1. Choose Encode to turn text into Base32hex, or Decode to turn Base32hex back into text.
  2. Keep the Base32hex variant selected. Turn padding off or switch to lowercase if your format needs it.
  3. Type or paste your input, or open a file. The result updates as you type.
  4. Copy the result or download it as a file.

What is Base32hex?

Base32hex is the "Base 32 Encoding with Extended Hex Alphabet" defined in section 7 of RFC 4648. It works exactly like standard Base32: each character carries 5 bits, every 5 bytes become 8 characters, and the output is padded with = to a multiple of 8. Only the alphabet differs. Instead of A-Z 2-7, Base32hex continues counting where hexadecimal stops: the digits 0 to 9 stand for 0 to 9, A is 10 and V is 31.

Because the two alphabets share most of their characters, a Base32hex string can often be fed to a standard Base32 decoder without an error, but the bytes that come out are wrong. Always decode with the same variant that was used to encode.

Sort order is preserved

The alphabet is in ascending ASCII order and each character's value grows with its position. As a result, comparing two Base32hex strings character by character gives the same order as comparing the underlying bytes. RFC 4648 points this out as the property that standard Base32 and Base64 lack, and it makes Base32hex a good fit for keys in sorted storage such as databases and key-value stores.

Keep all strings in one letter case, and turn padding off when the inputs differ in length: the = sign sorts between the digits and the letters and can break the order.

Base32hex in DNSSEC NSEC3

NSEC3 records, defined in RFC 5155, prove that a DNS name does not exist while making it harder to list every name in the zone. Each name is hashed with SHA-1, and the 20-byte hash is written as a 32-character Base32hex label without padding, usually shown in lowercase. Because the encoding keeps the order of the hashes, the hashed names form a sorted chain. To turn a hash into such a label, paste it as hex input, turn padding off and choose Lowercase. This tool performs only the encoding step; it does not compute the salted, iterated NSEC3 hash.

Base32hex in code

# Python 3.10+
import base64
base64.b32hexencode(b'foobar')          # b'CPNMUOJ1E8======'
base64.b32hexdecode('CPNMUOJ1E8======') # b'foobar'

// Go (import "encoding/base32")
base32.HexEncoding.EncodeToString(data)
base32.HexEncoding.WithPadding(base32.NoPadding).EncodeToString(data)

Specification

Alphabet0-9 A-V
Output size8 characters per 5 bytes (160%)
Padding= to a multiple of 8 characters
StandardRFC 4648 section 7
Case sensitiveNo

Examples

Input (UTF-8)Output
Hello, World!91IMOR3F5GG5ERRIDHI22===
Base64.is89GN6P9M6GN6ISO=
你好SIUQ1PD5NK======

Frequently asked questions

What is the difference between Base32 and Base32hex?
Both use 5 bits per character and the same padding rules. Standard Base32 uses A-Z 2-7; Base32hex uses 0-9 A-V, which keeps the sort order of the data. The two are not interchangeable.
Is Base32hex case sensitive?

The alphabet is defined in uppercase, but this decoder accepts lowercase input as well. Turn on Lowercase if you need lowercase output, for example for DNS labels.

Should I use padding?
RFC 4648 pads with = to a multiple of 8 characters, but many formats, including NSEC3, leave it out. The decoder accepts both, so choose whatever the receiving system expects.
Is a Base32hex string the same as hexadecimal?
No. A Base32hex string that happens to contain only 0-9 and A-F looks like hex, but each character carries 5 bits instead of 4. To work with ordinary hex, use the Base16 tool.