What is Base64 encoding?
Base64 is a way of writing any data using only 64 characters that are safe almost everywhere: the letters A to Z and a to z, the digits 0 to 9, and the symbols + and /. Many systems can only handle plain text, such as email bodies, JSON values, HTML attributes and HTTP headers, and Base64 lets other data travel through them without being damaged.
To Base64 encode text, the tool first converts it to bytes and then rewrites those bytes with the 64-character alphabet. The scheme is defined in RFC 4648. It is a reversible rewrite, not a secret code: for any valid Unicode text, Base64 Decode gives back exactly what you started with.
How Base64 encoding works
Base64 reads the data three bytes at a time. Three bytes are 24 bits, which are split into four groups of six bits. Each group is a number from 0 to 63 that selects one character from the alphabet, so every 3 bytes become 4 characters.
When the last group has only one or two bytes, one or two = signs are added as padding, so the length of the output is always a multiple of four. A short example:
Text: Hello
Base64: SGVsbG8=Because 4 characters stand for 3 bytes, the output is about a third larger than the bytes it encodes, rounded up to a multiple of four.
Where Base64 is used
- Data URIs, which put a small image or font straight inside HTML or CSS.
- HTTP Basic authentication, where
username:passwordis Base64 encoded in the Authorization header. - Email attachments, which are sent as Base64 inside the message.
- Binary values inside JSON or XML, which can only carry text.
- JSON Web Tokens, which use the URL-safe variant of Base64.
- Short binary values in config files and environment variables.
Base64 is not encryption
Base64 hides nothing. Anyone can decode it in a second, with no key and no password. It only changes how data is written so that it can travel safely.
Converting UTF-8 text to Base64
Base64 works on bytes, so text has to be turned into bytes first. This tool uses UTF-8, the encoding that the web and almost every API expect, which is why accented letters, Urdu, Chinese and emoji all encode correctly.
The classic trap in browser JavaScript is btoa. It only accepts characters up to U+00FF, so it throws an error on emoji and most non-Latin text. Convert the text to UTF-8 bytes first. The function below also works on large inputs, because it builds the string in chunks. Spreading one huge array into String.fromCharCode can fail with a RangeError.
function toBase64(text) {
const bytes = new TextEncoder().encode(text);
let binary = "";
for (let i = 0; i < bytes.length; i += 8192) {
binary += String.fromCharCode(...bytes.subarray(i, i + 8192));
}
return btoa(binary);
}
console.log(toBase64("Hello, ToolPlank! ๐")); // SGVsbG8sIFRvb2xQbGFuayEg8J+Riw==// Node.js
const text = "Hello, ToolPlank! ๐";
const base64 = Buffer.from(text, "utf8").toString("base64");
console.log(base64); // SGVsbG8sIFRvb2xQbGFuayEg8J+Riw==import base64
text = "Hello, ToolPlank! ๐"
encoded = base64.b64encode(text.encode("utf-8")).decode("ascii")
print(encoded) # SGVsbG8sIFRvb2xQbGFuayEg8J+Riw==One more edge case: a string can contain half of an emoji (a lone surrogate), for example after it was cut in the middle of a character. That is not valid Unicode, and a browser's TextEncoder quietly swaps it for a replacement character, which changes your data. This tool stops and tells you instead.
Standard and URL-safe Base64
The standard alphabet contains + and /, and both have special meanings in URLs and file names. The URL-safe variant, often called Base64URL (RFC 4648, section 5), replaces them with - and _, and it often leaves out the = padding. JSON Web Tokens use this form.
Text Standard URL-safe
??? Pz8/ Pz8_
>>> Pj4+ Pj4-Tick URL-safe to get this form, and tick Remove = padding to drop the trailing equals signs. Base64 Decode accepts both forms, with or without padding.
Common mistakes
- Treating Base64 as security. It hides nothing.
- Calling btoa directly on text that contains emoji or non-Latin letters. Convert it to UTF-8 bytes first.
- Mixing up the two alphabets. A standard string with + and / can break inside a URL, and not every decoder accepts - and _.
- Expecting line breaks. Email wraps Base64 at 76 characters per line, while this tool produces one line. Base64 Decode ignores line breaks if you paste wrapped text.
- Encoding twice by accident. The result is a longer, different string that needs two rounds of decoding.
Is it safe to paste private text here?
The encoding runs in your browser, and the text you paste is not sent to our servers. The Privacy Policy has the details.