Hex to Base64 Converter

Paste hexadecimal bytes and get the same data as Base64. Separators such as spaces, colons and 0x prefixes are removed automatically, so hashes and fingerprints can be pasted as they are.

Runs entirely in your browser. Nothing is uploaded.

How to use

  1. Paste the hex string into the input. Hex is preselected as the source and Base64 as the target.
  2. Do not worry about formatting: spaces, line breaks, colons, hyphens and 0x or \x prefixes are ignored.
  3. Switch the target to Base64URL if the value goes into a URL, a JWT or a JSON Web Key.
  4. Copy the Base64 result.

Why convert hex to Base64

Most hashing tools print digests in hex, but many protocols expect Base64, which is a third shorter. Typical cases:

  • Subresource Integrity. The integrity attribute on scripts and stylesheets holds a Base64 digest, such as sha384- followed by 64 Base64 characters.
  • Content Security Policy. Hashes that allow inline scripts are written as 'sha256-...' with a Base64 value.
  • Checksums in HTTP APIs. The Content-MD5 header and the Amazon S3 checksum headers carry the Base64 of the binary digest, not the hex string that md5sum prints.
  • Compact identifiers. A UUID is 16 bytes: 32 hex digits, but only 22 characters as unpadded Base64URL.

Accepted hex formats

Hex digits are case-insensitive. Before decoding, the converter removes whitespace, line breaks, colons, semicolons, commas, hyphens and the prefixes 0x, \x, % and &#x. That covers OpenSSL fingerprints like AB:CD:EF, C arrays like 0x12, 0x34, escaped strings like \x12\x34, percent-encoded bytes and UUIDs with hyphens.

After clean-up the input must contain an even number of digits, two per byte. An odd count is reported as an error and usually means a leading zero was lost, for example abc where 0abc was meant.

Encode the bytes, not the hex text

A frequent mistake is pasting a hex digest into an ordinary text-to-Base64 encoder. That encodes the characters 0-9a-f instead of the bytes they stand for, and the result is twice as long as it should be: 88 characters for a SHA-256 digest instead of 44. Anything that expects the binary digest, such as an SRI attribute or a checksum header, will reject it. This converter decodes the hex to bytes first.

# Shell: hex digest to Base64
printf '%s' "$HEX" | xxd -r -p | base64

# SRI value for a file in one step
openssl dgst -sha384 -binary script.js | openssl base64 -A

# Python
base64.b64encode(bytes.fromhex(h)).decode()

// Node.js (stops silently at the first non-hex character)
Buffer.from(h, 'hex').toString('base64')

Frequently asked questions

Why do I get an error for my hex string?

Either the input contains a character that is not a hex digit, such as the letter O instead of a zero, or the number of digits is odd. The error message shows the position of the invalid character; for an odd length, check whether a leading 0 is missing.

How long will the Base64 output be?
Divide the number of hex digits by 2 to get the bytes, then count 4 characters for every 3 bytes, rounded up. A 64-digit SHA-256 digest becomes 44 Base64 characters, including one = sign.
How do I create a Subresource Integrity hash?
Compute the SHA-384 digest of the file, convert the hex digest here, and write integrity="sha384-..." with the Base64 value. With OpenSSL you can do it in one command: openssl dgst -sha384 -binary file.js | openssl base64 -A.
Is the output standard or URL-safe Base64?
Standard Base64 with + and /, as required by SRI, CSP and HTTP checksum headers. Choose Base64URL as the target encoding when you need URL-safe output.