YAML to Base64 Converter
Encodes YAML text to Base64 through its UTF-8 bytes and decodes Base64 back to text, so accented letters and emoji survive the round trip. Output can wrap at 64 or 76 characters or use the URL-safe alphabet without padding, and the YAML is carried as text, not parsed or validated.
This tool sends nothing over the network. Everything you enter is processed on your device and never reaches our servers.
Documentation
A YAML to Base64 converter rewrites configuration text as Base64, an alphabet of 64 printable characters (A to Z, a to z, 0 to 9, + and /), so text full of line breaks, colons, quotes, and indentation can travel through systems that accept only a single line of plain ASCII. YAML is a frequent payload because Kubernetes Secret manifests store every value under data as Base64, and many CI systems pass multi-line configuration through one environment variable.
Encoding first turns the text into UTF-8 bytes: an ASCII character is one byte, é is two (C3 A9), and an emoji is four. Every group of three bytes becomes four characters, each standing for 6 bits. A final group of one or two bytes is padded with = signs, which makes the encoded length 4 x ceil(bytes / 3). The URL-safe variant from RFC 4648 section 5 swaps + for - and / for _ and drops the padding, the form used in URLs, file names, and JSON Web Tokens. Line wrapping inserts a break every 64 characters, the PEM convention, or every 76, the MIME line limit, and the encoded Character Count reports the length without those breaks.
Decoding strips all whitespace first, so wrapped Base64 decodes as one string. It accepts both alphabets and restores missing padding. The bytes must form valid UTF-8 text; Base64 that holds an image, an archive, or other binary data is reported as such instead of being shown as replacement characters. The decoded Character Count counts characters rather than bytes or UTF-16 units, so one emoji counts once.
Base64 is an encoding, not encryption. Anyone holding the string can decode it, which is why a Kubernetes Secret needs access control or encryption at rest to keep its values private. The YAML is carried as text and never parsed, so an indentation error or a tab encodes exactly as written and only surfaces when the receiving system parses the decoded file.
The two-line YAML a: 1 and b: 2 is 9 bytes, 61 3A 20 31 0A 62 3A 20 32 in hexadecimal, with 0A as the line break. The first three bytes, 61 3A 20, are the 24 bits 011000 010011 101000 100000, which index the characters Y, T, o, and g. The remaining two groups give MQpi and OiAy, so the whole file encodes to YTogMQpiOiAy: 12 characters for 9 bytes, with no padding because 9 divides evenly by 3. The single character é is the two bytes C3 A9 and encodes to w6k=, with one = of padding.
Base64-encoded YAML appears throughout infrastructure automation, cloud platforms, and application configuration. The scenarios below are where converting between the two formats is part of the work.
- Kubernetes Secrets: Encode YAML key-value content for the data field of a Secret manifest, where values must be Base64 rather than plain text, or for a config file mounted from a Secret.
- Secret Review: Decode the data values of an existing Secret, which kubectl get secret -o yaml prints in Base64, to see what a deployed configuration actually contains before changing it.
- CI/CD Pipelines: Store multi-line YAML configuration as a single Base64-encoded environment variable in GitHub Actions, GitLab CI, or Jenkins, then decode it at runtime to reconstruct the configuration file.
- API Payloads: Embed YAML configuration inside JSON request bodies as Base64, avoiding escaping conflicts between YAML syntax characters and JSON string delimiters.
- Helm Charts: Check the output of the b64enc template function, or prepare values for charts that expect configuration as an opaque encoded string rather than structured YAML.
- Cloud Provisioning: Pass YAML cloud-init configuration where a resource expects Base64, such as the custom_data argument of an Azure Linux virtual machine in Terraform or the user data of an AWS launch template.
- Docker Compose Overrides: Encode environment-specific YAML overrides for transmission between deployment stages, then decode them on the target host to merge with the base Compose file.
- Configuration Backup: Archive YAML configuration files as compact Base64 strings in databases, spreadsheets, or issue trackers where multi-line text formatting would be lost. Decoding restores the original indentation and structure for direct reuse without manual reformatting.
Inputs, outputs, and what the YAML to Base64 Converter computes
What the YAML to Base64 Converter asks for and what it returns, as a plain list. Defaults, units, and ranges are the ones the form loads with.
Inputs
- YAML Input
- Encoded Result (copyable)
- Base64 Input
- Decoded Result (copyable)
- Line Wrapping · default: No wrapping
- URL-safe Base64 (replace + / with - _ and strip padding) · default: off
Controls
Convert · Reset
Example
The two-line YAML a: 1 and b: 2 is 9 bytes, 61 3A 20 31 0A 62 3A 20 32 in hexadecimal , with 0A as the line break.