Base64 encode
Text in, Base64 out, correctly for accents and emoji. URL-safe and data URI options included, secrecy pointedly not.
Guide
How to use it
- Type or paste the text. The Base64 appears as you type, UTF-8 encoded first so nothing mangles.
- Tick URL-safe for output going into URLs, filenames or JWT-style tokens.
- Tick data URI to wrap the output as data:text/plain;charset=utf-8;base64,…
- Copy the result. For images and other files, use the image page.
Examples
Worked examples
Encode apiuser:s3cret and prefix the result with Basic for a quick curl test. Then remember anyone who sees the header can decode it.
A YAML fragment full of quotes and newlines will not survive an environment variable. Encoded, it is one safe line; the app decodes it on startup.
Encode Café → 25° here and decode it back: identical. The same text through a naive encoder comes back broken.
Method
How it works
Your text is converted to UTF-8 bytes with TextEncoder, then packed three bytes at a time into four characters of the Base64 alphabet, which is why output is a third bigger than input. The URL-safe option swaps + and / for - and _ and drops padding, the variant used in JWTs and URL parameters.
Worth repeating because it causes real incidents: Base64 is not encryption. It hides nothing from anyone. Everything here runs locally, and nothing you type is transmitted.
FAQ
Frequently asked questions
When do I actually need Base64 encoding?
When binary or arbitrary text has to survive a text-only channel: embedding files in JSON or CSS, Basic auth headers, SMTP attachments, XML payloads and environment variables that choke on special characters.
Does Base64 protect the content?
Not at all. It is decodable by anyone in milliseconds, with no key. If you need secrecy, encrypt; if you need integrity, sign or hash. Base64 only changes the alphabet.
Why is the output a third bigger?
Base64 spends four characters for every three bytes, a built-in 33% overhead. That is the price of using only safe characters, and why inlining large files is a bad habit.
What does UTF-8 safe mean?
Naive JavaScript btoa breaks on accents, emoji and non-Latin scripts. This encoder converts text to UTF-8 bytes first, so café, straße and 日本語 round-trip correctly.
When do I want the URL-safe alphabet?
When the output lives in a URL or filename: + and / are replaced by - and _ and padding is dropped. JWTs use exactly this variant, as the JWT decoder shows.
Is my text uploaded to encode it?
No. Encoding happens in your browser and nothing is transmitted, which matters given how often the input is a credential.
More tools