Base64 Encoder

Encode text to Base64, in the standard or URL-safe alphabet, entirely in your browser.

Runs entirely in your browser. Nothing is uploaded, logged or stored.

Base64 turns arbitrary bytes into characters that survive a text channel: an HTTP header, a JSON string, an email body, a data URI. It is an encoding, not encryption, and anyone can reverse it instantly.

How it works

The text is read as UTF-8 bytes, then every three bytes become four characters from a 64 character alphabet. When the length is not a multiple of three the result is padded with one or two "=" signs. This is why Base64 output is always about a third larger than the input.

The URL-safe alphabet of RFC 4648 replaces "+" and "/" with "-" and "_" and drops the padding, so the value can sit in a query string or a filename without being escaped again. JSON Web Tokens use this variant.

Examples

Case Input Result
Basic authentication credentials aladdin:opensesame YWxhZGRpbjpvcGVuc2VzYW1l
Text with an accent, encoded from its UTF-8 bytes café Y2Fmw6k=

Frequently asked questions

Does Base64 protect my data?

Not at all. It is a reversible encoding with no key and no secret. Anything you encode can be read back by anyone who sees it, including this page in one click.

Why is the output longer than the input?

Four output characters carry three input bytes, so the result grows by roughly 33%, plus up to two padding characters. That overhead is the price of moving binary data through a text-only channel.

Which alphabet should I pick?

Standard for anything that travels in a body or a header. URL-safe when the value goes into a URL, a filename or a JWT, so that "+", "/" and "=" do not have to be percent-encoded on top.

Good to know

  • Everything happens in your browser. What you paste is not uploaded, not logged and not stored.

Sources

All Code tools