What this tool does
The text is converted to UTF-8 bytes, then those bytes are encoded in Base64. The two steps matter in that order: Base64 encodes bytes, not characters, and the byte count is what determines the output.
That is why café gives Y2Fmw6k= — five bytes, not four, because the accented letter takes two.
The URL-safe variant
Standard Base64 uses + and /, both of which have their own meaning in a URL. The URL-safe alphabet replaces them with - and _, and drops the = padding, which is equally awkward in a query string.
So a encodes to YQ== normally and to YQ in URL-safe form. Decoders that understand the URL-safe alphabet accept the unpadded version — that is what RFC 4648 intends.
What it is not
Base64 is not encryption. There is no key, nothing is secret, and decoding takes one step with any tool including this one. It is a way to carry bytes through a channel that only accepts text — a data URI, an email attachment, a JSON field.
Putting a password or a token in Base64 protects nothing. It only makes the value slightly less obvious to a human skimming a log, which is not a security property.
Size
The output is about a third larger than the input, plus padding. A 3 KB file becomes roughly 4 KB of Base64 — worth knowing before embedding an image in a stylesheet or a data URI.
Private by design
Everything runs locally in your browser with JavaScript. Your data is never uploaded, which makes the tool safe for sensitive content, and it keeps working offline.