How it works
- 01
Paste text or load a file
Any text, or a file of any type read as raw bytes. It stays in this tab.
- 02
Pick the alphabet
Standard for most things, URL-safe when the output goes in a link. Padding is optional.
- 03
Copy the output
Copy it, or download it as a text file. The size figures update as you type.
What Base64 is for
Base64 maps any bytes onto 64 printable characters, so binary data can travel through anything that only carries text. Email bodies, JSON fields, XML attributes and data URIs all use it. Every three bytes become four characters, so the output is always about a third bigger than what went in.
It is an encoding, not encryption. Anyone can decode Base64 instantly, so it protects nothing at all. A token or a password is just as exposed encoded as it was plain. Use it to make bytes safe to carry, and use TLS or real encryption to make them private.
- Alphabets
- Standard (RFC 4648) and URL-safe, which swaps + and /.
- Padding
- Trailing = signs pad the length to a multiple of four.
- Input
- Text as UTF-8 or Latin-1, or any file up to 10 MB as raw bytes.
- Size
- Output is a third larger, plus padding.
Standard or URL-safe
The standard alphabet uses + and /. Both mean something inside a URL, so servers and clients re-read them or escape them, and the string arrives changed. The URL-safe form swaps them for - and _, so you can put the output in a query string or a path without escaping it.
JSON Web Tokens use the URL-safe form with the padding stripped. That is why a JWT segment never ends in an equals sign, and why the Include padding switch matters when you are matching one.