100% local — your data never leaves your browser

Text to Base64 — Safe in a Header or a Body

Encode text as Base64, with an optional URL-safe variant. The text becomes UTF-8 bytes first, so accents and emoji arrive on the other side intact.

Instant Private Zero cookies

Text input

Base64 output

What this tool does

The text is converted to UTF-8 bytes, then those bytes are encoded in Base64. The two steps matter in that order: Base64 encodes bytes, not characters, and the byte count is what determines the output.

That is why café gives Y2Fmw6k= — five bytes, not four, because the accented letter takes two.

The URL-safe variant

Standard Base64 uses + and /, both of which have their own meaning in a URL. The URL-safe alphabet replaces them with - and _, and drops the = padding, which is equally awkward in a query string.

So a encodes to YQ== normally and to YQ in URL-safe form. Decoders that understand the URL-safe alphabet accept the unpadded version — that is what RFC 4648 intends.

What it is not

Base64 is not encryption. There is no key, nothing is secret, and decoding takes one step with any tool including this one. It is a way to carry bytes through a channel that only accepts text — a data URI, an email attachment, a JSON field.

Putting a password or a token in Base64 protects nothing. It only makes the value slightly less obvious to a human skimming a log, which is not a security property.

Size

The output is about a third larger than the input, plus padding. A 3 KB file becomes roughly 4 KB of Base64 — worth knowing before embedding an image in a stylesheet or a data URI.

Private by design

Everything runs locally in your browser with JavaScript. Your data is never uploaded, which makes the tool safe for sensitive content, and it keeps working offline.

Frequently asked questions

Is Base64 a form of encryption?
No, and treating it as one is a common and costly mistake. Base64 is a transport encoding with no key and no secret: anyone can decode it in one step. It hides nothing — it only makes binary data safe to put in a text field.
Why is my URL-safe output missing its = signs?
Because RFC 4648 makes padding optional in the URL-safe alphabet, and a bare `=` is itself problematic in a query string. Decoders that accept the URL-safe form accept the unpadded one too.
Why did my 4-letter word become 8 characters?
Two effects compound. The text becomes UTF-8 bytes first, so an accented letter costs two bytes rather than one; then Base64 itself turns every 3 bytes into 4 characters. Expect roughly a third more than the byte count.

Related converters