🔒

Base64 Encoder

Encode text to Base64 with standard or URL-safe output. Instant, free, and processed entirely in your browser.

✓ Free forever✓ No signup✓ 100% private — runs in your browser
Base64 Encoder / Decoder
Encode text or files to Base64, or decode Base64 strings. Supports URL-safe encoding.
Text Input
File → Base64
📁
Click or drop file here
Max 5MB · Any file type
Output
Result appears here…

Base64 represents binary data using 64 printable ASCII characters. It exists because a great deal of internet infrastructure — email headers, URLs, JSON, XML — only reliably handles text, and Base64 is how binary gets safely through those channels.

How to use the Base64 Encoder

  1. Paste the text you want to encode
  2. Click Encode, or Decode to go the other way
  3. Switch to URL-safe output if the result will be used in a URL or token
  4. Copy the result

Base64 is encoding, not encryption

This matters enough to state bluntly: Base64 provides no security whatsoever. It is trivially reversible by anyone, with no key and no effort. Anything encoded can be read.

A recurring real-world mistake is Base64-encoding credentials and treating them as protected. HTTP Basic Auth does exactly this — Authorization: Basic is a Base64 string of username:password, readable by anyone who sees the header. That is why Basic Auth is only acceptable over HTTPS, where TLS provides the actual protection.

If you need secrecy, you need encryption. Base64 solves a transport problem, not a confidentiality one.

Standard versus URL-safe

Standard Base64 uses + and / as its last two characters, plus = for padding. All three are problematic in a URL: + is interpreted as a space in query strings, and / is a path separator.

URL-safe Base64 substitutes - for + and _ for /, and usually drops the padding. This is the variant used in JSON Web Tokens, which is why a JWT contains hyphens and underscores but never slashes.

Frequently asked questions

Is Base64 secure?

No. It is an encoding, not encryption, and is reversible by anyone with no key. Never use it to protect passwords, tokens or personal data.

Why is the encoded output longer than the input?

Base64 represents every 3 bytes as 4 characters, so output is about 33% larger. That overhead buys safe passage through text-only channels.

What are the equals signs at the end?

Padding. Base64 works in 3-byte groups; when the input does not divide evenly, one or two = characters pad the final group. URL-safe variants often omit them.

Does it handle emoji and non-English text?

Yes. Text is converted to UTF-8 bytes before encoding, so any Unicode character round-trips correctly.