Base64 Encoder
Turn text into Base64, in the tab, with nothing uploaded.
Runs entirely in your browser
Loading the tool…
Text in, Base64 out, as you type. This page opens facing that direction; the same tool decodes as well.
Base64 turns arbitrary bytes into sixty-four printable characters so they survive systems that only expect text: email bodies, JSON fields, data URIs and HTTP headers. The cost is size. Encoding makes the data about a third larger, three bytes becoming four characters, which is the reason not to Base64 anything you could send as bytes instead.
It is not encryption and offers no secrecy at all. Anybody can decode it, including this page, with no key and no effort. Base64 in a config file or an HTTP header hides a value from a casual glance and from nothing else. If it needs to be secret, encrypt it first and encode the result.
URL-safe mode swaps + and / for - and
_, which is what you want when the output is going into a URL, a
filename or a JWT, where the standard alphabet's characters mean something else.
How to use it
- Type or paste your text. It encodes as you type.
- Tick URL-safe if the result is going into a URL or a filename.
- Press Copy to take the Base64.
Questions
Is Base64 encryption?
No, and treating it as such is the most common mistake made with it. It is a reversible encoding with no key: anyone can decode it instantly. Use it to move bytes through a text-only channel, never to hide them.
When should I use URL-safe Base64?
Whenever the result goes into a URL, a filename or a JWT. Standard Base64 uses + and /, which already mean something in a URL path or query and will be mangled or misread. The URL-safe alphabet substitutes - and _ instead, and the padding is often dropped as well.
Why is my encoded text longer than the original?
Because Base64 spends four characters on every three bytes, making the result about a third larger, plus padding. That overhead is the price of being safe to put in text, and it is the reason to avoid encoding large files this way when you can send the bytes directly.
Is my text uploaded anywhere?
No. The encoding runs in WebAssembly in this tab, the page makes no request of its own, and nothing is stored. Disconnect first and it still works, which is worth knowing before pasting anything from a real system into any tool of this kind.
Your data stays on your device
Everything above runs inside your browser as WebAssembly compiled from Rust. Nothing you type is uploaded, logged or stored on a server. You can load this page once, go offline, and it still works.
This page makes no requests at all, to anywhere. That is not a promise in the copy: it is a Content-Security-Policy header your browser enforces, and connect-src on it is none. Open the network tab and watch nothing happen.