Base64 Encode
Encode any text to Base64, with an optional URL-safe alphabet for query strings and tokens. Handles UTF-8 correctly. Nothing is uploaded to a server.
Worked examples
- A short plain-text string
The everyday case: encoding a short string to embed in a URL, header or config value.
- Text with multi-byte UTF-8 characters
Accented letters and emoji take more than one byte in UTF-8, so the encoded output is longer than the character count suggests — a frequent source of bugs.
- URL-safe encoding for use in a query string
Standard Base64 uses + and / and = padding, all of which need escaping in a URL; the URL-safe alphabet swaps them for - and _ and drops padding.
What this tool does
Base64 encoding turns arbitrary text (or binary data) into a string made up only of letters, digits, and a few symbols — an alphabet safe to put inside places that only reliably handle plain ASCII text, like email bodies, URLs, JSON strings, and HTTP headers. This tool encodes UTF-8 text to Base64 entirely in your browser, with an option for the URL-safe variant.
When you need it
- Embedding binary-ish or special-character data inside a JSON field, a URL, or a config file without worrying about escaping.
- Building the
Authorization: Basicheader for HTTP Basic Auth, which requiresusername:passwordto be Base64-encoded. - Preparing a value to paste into a system (some webhook payloads, some legacy APIs) that expects Base64 rather than raw text.
- Understanding what a Base64 string you're about to send actually contains, by encoding a known value and comparing.
Rules the encoder applies
- Text is encoded as UTF-8 bytes first, then those bytes are mapped to Base64 characters three bytes at a time. This matters because a character count and a byte count aren't the same thing once accented letters, emoji or other non-ASCII characters are involved — those take two to four bytes each in UTF-8.
- Standard Base64 uses
+,/and=padding. This is the default and the form most systems (email, most APIs) expect. - URL-safe Base64 replaces
+with-and/with_, and omits the=padding. This is the form used inside JWTs and in URL query parameters, where+,/and=would otherwise need percent-encoding to be safe. - The output length is always a multiple of 4 characters in standard mode (using padding to reach that), and 0–2 characters shorter in URL-safe mode, where the padding is dropped.
Why the output is longer than the input
Base64 represents every 3 bytes of input as 4 characters of output, so encoded text is roughly 33% larger than the original. This is an expected, unavoidable property of the encoding — it's not evidence of anything going wrong, and it's the trade-off for making binary-safe data usable as plain ASCII text.
Things to check after encoding
- If you need the result inside a URL, use the URL-safe option rather than percent-encoding a standard Base64 string afterward — it produces a cleaner, shorter result.
- Base64 is not encryption or compression. Anyone who sees the encoded string can decode it back to the original text in one step; never use Base64 alone to protect a secret or password.
- If you're building an HTTP Basic Auth header, remember the input format is
username:password(with a literal colon) before encoding, not just the password.
Limits
Input is capped at 2 MB of text. This tool encodes text input, not raw binary files — for encoding an image or other binary file to Base64, you need a file-reading tool rather than a text box.
Frequently asked questions
- Is my text uploaded anywhere?
- No. Encoding runs entirely in your browser; nothing is sent to a server.
- What is Base64 encoding used for?
- Representing binary or arbitrary text as plain ASCII, so it can safely travel through systems that only handle text — email, URLs, JSON, config files.
- What's the difference between standard and URL-safe Base64?
- URL-safe Base64 replaces + and / with - and _ and omits the = padding, so the result can be used directly inside a URL without extra escaping.
- Does Base64 encrypt my data?
- No. Base64 is an encoding, not encryption — anyone can decode it back to the original text instantly. Don't use it to hide secrets.