Skip to the tool

Base64 encode

Text in, Base64 out, correctly for accents and emoji. URL-safe and data URI options included, secrecy pointedly not.

Guide

How to use it

  1. Type or paste the text. The Base64 appears as you type, UTF-8 encoded first so nothing mangles.
  2. Tick URL-safe for output going into URLs, filenames or JWT-style tokens.
  3. Tick data URI to wrap the output as data:text/plain;charset=utf-8;base64,…
  4. Copy the result. For images and other files, use the image page.

Examples

Worked examples

A Basic auth header

Encode apiuser:s3cret and prefix the result with Basic for a quick curl test. Then remember anyone who sees the header can decode it.

A config blob in one line

A YAML fragment full of quotes and newlines will not survive an environment variable. Encoded, it is one safe line; the app decodes it on startup.

Accents that survive

Encode Café  →  25° here and decode it back: identical. The same text through a naive encoder comes back broken.

Method

How it works

Your text is converted to UTF-8 bytes with TextEncoder, then packed three bytes at a time into four characters of the Base64 alphabet, which is why output is a third bigger than input. The URL-safe option swaps + and / for - and _ and drops padding, the variant used in JWTs and URL parameters.

Worth repeating because it causes real incidents: Base64 is not encryption. It hides nothing from anyone. Everything here runs locally, and nothing you type is transmitted.

FAQ

Frequently asked questions

When do I actually need Base64 encoding?

When binary or arbitrary text has to survive a text-only channel: embedding files in JSON or CSS, Basic auth headers, SMTP attachments, XML payloads and environment variables that choke on special characters.

Does Base64 protect the content?

Not at all. It is decodable by anyone in milliseconds, with no key. If you need secrecy, encrypt; if you need integrity, sign or hash. Base64 only changes the alphabet.

Why is the output a third bigger?

Base64 spends four characters for every three bytes, a built-in 33% overhead. That is the price of using only safe characters, and why inlining large files is a bad habit.

What does UTF-8 safe mean?

Naive JavaScript btoa breaks on accents, emoji and non-Latin scripts. This encoder converts text to UTF-8 bytes first, so café, straße and 日本語 round-trip correctly.

When do I want the URL-safe alphabet?

When the output lives in a URL or filename: + and / are replaced by - and _ and padding is dropped. JWTs use exactly this variant, as the JWT decoder shows.

Is my text uploaded to encode it?

No. Encoding happens in your browser and nothing is transmitted, which matters given how often the input is a credential.

More tools

Related tools

Base64 decodeCheck your encoded output round-trips cleanly. Image to Base64Files and images as data URIs, with size warnings. Password generatorFor the secrets you were about to hide in Base64.
Skip to the tool

Base64 encode

Text in, Base64 out, correctly for accents and emoji. URL-safe and data URI options included, secrecy pointedly not.

Type text and the Base64 appears instantly, UTF-8 safe.

Everything runs in your browser. Base64 is encoding, not encryption: anyone can decode it, so never treat it as secrecy.

Guide

How to use it

  1. Type or paste the text. The Base64 appears as you type, UTF-8 encoded first so nothing mangles.
  2. Tick URL-safe for output going into URLs, filenames or JWT-style tokens.
  3. Tick data URI to wrap the output as data:text/plain;charset=utf-8;base64,…
  4. Copy the result. For images and other files, use the image page.

Examples

Worked examples

A Basic auth header

Encode apiuser:s3cret and prefix the result with Basic for a quick curl test. Then remember anyone who sees the header can decode it.

A config blob in one line

A YAML fragment full of quotes and newlines will not survive an environment variable. Encoded, it is one safe line; the app decodes it on startup.

Accents that survive

Encode Café  →  25° here and decode it back: identical. The same text through a naive encoder comes back broken.

Method

How it works

Your text is converted to UTF-8 bytes with TextEncoder, then packed three bytes at a time into four characters of the Base64 alphabet, which is why output is a third bigger than input. The URL-safe option swaps + and / for - and _ and drops padding, the variant used in JWTs and URL parameters.

Worth repeating because it causes real incidents: Base64 is not encryption. It hides nothing from anyone. Everything here runs locally, and nothing you type is transmitted.

FAQ

Frequently asked questions

When do I actually need Base64 encoding?

When binary or arbitrary text has to survive a text-only channel: embedding files in JSON or CSS, Basic auth headers, SMTP attachments, XML payloads and environment variables that choke on special characters.

Does Base64 protect the content?

Not at all. It is decodable by anyone in milliseconds, with no key. If you need secrecy, encrypt; if you need integrity, sign or hash. Base64 only changes the alphabet.

Why is the output a third bigger?

Base64 spends four characters for every three bytes, a built-in 33% overhead. That is the price of using only safe characters, and why inlining large files is a bad habit.

What does UTF-8 safe mean?

Naive JavaScript btoa breaks on accents, emoji and non-Latin scripts. This encoder converts text to UTF-8 bytes first, so café, straße and 日本語 round-trip correctly.

When do I want the URL-safe alphabet?

When the output lives in a URL or filename: + and / are replaced by - and _ and padding is dropped. JWTs use exactly this variant, as the JWT decoder shows.

Is my text uploaded to encode it?

No. Encoding happens in your browser and nothing is transmitted, which matters given how often the input is a credential.

More tools

Related tools