Base64 encode text online

Encode and decode Base64, URLs and HTML entities. Handles emoji.

You usually need Base64 encoding when a system expects plain text but you have something else: a username and password for a basic authorization header, a short JSON payload for a query parameter, a small icon to place inside a stylesheet, or a value for a config file. This page opens on the Base64 tab in encode mode, so you can paste and copy straight away. The text is turned into UTF-8 bytes before encoding, which matters for anything beyond English letters. The text héllo ✓, with an accent and a check mark, gives aMOpbGxvIOKckw==, and an emoji works as well, where the browser's btoa function would fail. Tick URL-safe when the result goes into a web address, a file name or a web token, because it swaps + and / for - and _ and drops the = at the end. To embed a picture, choose a file of up to 5 MB and copy the data URI. This page encodes to Base64 only; it is not encryption, and anyone can decode the result.

How it works

  1. Paste your text
  2. Choose encode or decode
  3. Copy the result

Why Base64 needs UTF-8

Base64 turns bytes into letters, digits, + and /. Text is not bytes until you pick an encoding, and this tool always uses UTF-8, the encoding most websites and APIs use. That is why héllo ✓ becomes aMOpbGxvIOKckw==: the letter é takes two bytes and the check mark takes three. The browser's own btoa function only accepts characters up to U+00FF. It throws an error on ✓ or an emoji, and it quietly gives aOlsbG8= for héllo, which is Latin-1 bytes and not what an API expecting UTF-8 wants. This tool converts the text to UTF-8 bytes first, so accents, Chinese characters and emoji all round-trip. The URL-safe option swaps + and / for - and _ and drops the = padding, the form used in web tokens and file names. When decoding, both alphabets are accepted, spaces and line breaks are ignored, and missing padding is fine. If the bytes are not valid UTF-8, for example the decoded bytes of an image, the tool says so and offers the bytes as a download instead of showing garbage. Base64 is an encoding, not encryption: anyone can reverse it.

encodeURIComponent vs encodeURI

A URL uses a few characters for structure: / separates path parts, ? starts the query, & separates parameters, = joins a name to a value and # starts the fragment. Whole value mode uses encodeURIComponent, which escapes all of those, so use it for one piece, such as a search term that will sit after q=. Whole address mode uses encodeURI, which leaves those characters alone and escapes only what cannot appear in an address at all, such as spaces and accents, so use it on a full link. For a b&c=d/é the first gives a%20b%26c%3Dd%2F%C3%A9 and the second gives a%20b&c=d/%C3%A9. Decoding follows the same mode: decodeURIComponent undoes every %XX, while decodeURI leaves %26 and %3D escaped. The tool does not turn + into a space or back, because + only means a space in form data, not in the rest of a URL. A % that is not followed by two hex digits is reported in plain words, not as an error code.

HTML entities and safety

HTML entities write a character as text that a page shows as that character: &lt; for <, &amp; for &, &#39; for an apostrophe. Encoding replaces & < > " and ' so that text can sit inside a page or an attribute without being read as markup. The optional setting also writes every character above ASCII, such as é or an emoji, as a numeric entity like &#233;. Decoding handles named entities from a built-in list of about 250 common names, plus decimal (&#65;) and hexadecimal (&#x41;) numbers. A name that is not in the list, such as &foo;, is left as written, so uncommon names stay as they are. A number that is zero, a surrogate or above U+10FFFF becomes the replacement character. Decoding runs once, so &amp;lt; becomes &lt; and not <. The text is never loaded as a web page: the tool replaces entities in a plain string and shows the result in a read-only box, so a pasted script tag or an image with an onerror handler stays as literal text. It is shown, not run.

Files, limits and your privacy

On the Base64 tab you can also choose a file of up to 5 MB and get its data URI, the data:image/png;base64,... form used inside HTML and CSS. The file is read in this tab by your browser and never uploaded; a data URI is about a third longer than the file. The box shows the first 200 characters, and the Copy and Download buttons hold the whole value. Text can be up to 1,000,000 characters, and a long result shows its first 100,000 characters with the full value on Copy. Turning Base64 back into a picture or file is not offered; if decoded bytes are not text, you can download the raw bytes. The page counts visits with Google Analytics, using only the name of the tool, the fact that a result appeared or a button was pressed, and a rough size group such as 1 to 10 MB when you choose a file, never your text or your file. The text is not put in the address bar and is not saved. The tab, direction and options are remembered on this device.

Frequently asked questions

How do I Base64 encode a username and password for a header?

Type them as user:password, with a colon, and copy the result. For example Aladdin:open sesame gives QWxhZGRpbjpvcGVuIHNlc2FtZQ==. Basic authorization then adds the word Basic and a space in front of it.

Why does the encoded text end with = or ==?

Base64 writes 3 bytes as 4 characters. When the input is not a multiple of 3 bytes, one or two = signs fill the last group, so Hello (5 bytes) ends with a single = and Hi! ends with none. URL-safe mode removes them.

Can I encode an image or a PDF here?

Yes, up to 5 MB, as a data URI that starts with data:image/png;base64, for a PNG. Choose the file under the text box. It is read in this tab and not uploaded. Turning Base64 back into a file is not offered.

Is Base64 encryption?

No. Base64 only rewrites bytes with 64 letters and symbols, and anyone can decode it, as you can on this page. SGVsbG8= is Hello. Do not use it to hide a password or a token; use real encryption for that.

Why does my Base64 differ from the browser's btoa?

btoa works on Latin-1 characters only. For héllo it gives aOlsbG8=, and for ✓ or an emoji it throws an error. This tool encodes the text as UTF-8 first and gives aMOpbGxvIOKckw==, which is what most servers and libraries expect.

What is URL-safe Base64?

It is Base64 with - in place of + and _ in place of /, and the = padding at the end removed. The standard characters + and / have a meaning inside URLs and file names. For ???>>> the standard form is Pz8/Pj4+ and the URL-safe form is Pz8_Pj4-.

When do I use encodeURI and when encodeURIComponent?

Use encodeURIComponent for one value that goes into a link, such as a search term, because it also escapes / ? & = and #. Use encodeURI for a whole address you want to keep working, because it leaves those characters alone and escapes spaces and accents only.

Why does my decoded Base64 say it is not text?

The Base64 is valid, but the bytes are not UTF-8 text. A PNG, a PDF or a zip file looks like this, for example /w== is the single byte 0xFF. The tool offers the bytes as a download instead of showing broken characters.

Is my text uploaded?

No. The conversion runs in this tab with your browser's own functions, and a file you choose is read in the tab as well. Nothing you type or choose is sent anywhere, and the text is not stored. Only the tool name and the fact that a result appeared or a Copy was pressed are counted.