How to use
- Paste the hex string into the input. Hex is preselected as the source and Base64 as the target.
- Do not worry about formatting: spaces, line breaks, colons, hyphens and 0x or \x prefixes are ignored.
- Switch the target to Base64URL if the value goes into a URL, a JWT or a JSON Web Key.
- Copy the Base64 result.
Why convert hex to Base64
Most hashing tools print digests in hex, but many protocols expect Base64, which is a third shorter. Typical cases:
- Subresource Integrity. The
integrityattribute on scripts and stylesheets holds a Base64 digest, such assha384-followed by 64 Base64 characters. - Content Security Policy. Hashes that allow inline scripts are written as
'sha256-...'with a Base64 value. - Checksums in HTTP APIs. The
Content-MD5header and the Amazon S3 checksum headers carry the Base64 of the binary digest, not the hex string thatmd5sumprints. - Compact identifiers. A UUID is 16 bytes: 32 hex digits, but only 22 characters as unpadded Base64URL.
Accepted hex formats
Hex digits are case-insensitive. Before decoding, the converter removes whitespace, line breaks, colons, semicolons, commas, hyphens and the prefixes 0x, \x, % and &#x. That covers OpenSSL fingerprints like AB:CD:EF, C arrays like 0x12, 0x34, escaped strings like \x12\x34, percent-encoded bytes and UUIDs with hyphens.
After clean-up the input must contain an even number of digits, two per byte. An odd count is reported as an error and usually means a leading zero was lost, for example abc where 0abc was meant.
Encode the bytes, not the hex text
A frequent mistake is pasting a hex digest into an ordinary text-to-Base64 encoder. That encodes the characters 0-9a-f instead of the bytes they stand for, and the result is twice as long as it should be: 88 characters for a SHA-256 digest instead of 44. Anything that expects the binary digest, such as an SRI attribute or a checksum header, will reject it. This converter decodes the hex to bytes first.
# Shell: hex digest to Base64
printf '%s' "$HEX" | xxd -r -p | base64
# SRI value for a file in one step
openssl dgst -sha384 -binary script.js | openssl base64 -A
# Python
base64.b64encode(bytes.fromhex(h)).decode()
// Node.js (stops silently at the first non-hex character)
Buffer.from(h, 'hex').toString('base64')
Frequently asked questions
Why do I get an error for my hex string?
Either the input contains a character that is not a hex digit, such as the letter O instead of a zero, or the number of digits is odd. The error message shows the position of the invalid character; for an odd length, check whether a leading 0 is missing.
How long will the Base64 output be?
= sign.How do I create a Subresource Integrity hash?
integrity="sha384-..." with the Base64 value. With OpenSSL you can do it in one command: openssl dgst -sha384 -binary file.js | openssl base64 -A.Is the output standard or URL-safe Base64?
+ and /, as required by SRI, CSP and HTTP checksum headers. Choose Base64URL as the target encoding when you need URL-safe output.