Base64 Encoding Explained
Base64 turns binary data into safe text. It is not encryption and it is not compression — here is what it does and when to use it.
What Base64 does
Base64 encodes binary data as ASCII text using 64 safe characters (A–Z, a–z, 0–9, +, /, with = padding). It exists so binary data can travel through systems that only handle text.
Encode or decode instantly with the Base64 tool.
Why it exists
Many protocols and formats are text-only: email, HTML, JSON, HTTP headers. Base64 lets you embed images, certificates, keys and attachments without corrupting bytes that would break a text channel.
How it works, briefly
Every 3 bytes (24 bits) become 4 Base64 characters (6 bits each). If the input is not a multiple of 3, padding (=) fills the gap. That is why output is about 33% larger.
"Man" → "TWFu"
Base64 is not encryption
This is the most important point: Base64 is reversible with no key. It offers no confidentiality. Treating Base64 as security is a common and dangerous mistake. For confidentiality use encryption; for integrity use hashing.
Where you meet Base64
- Data URIs — inlining images in CSS/HTML.
- Email attachments — MIME encoding.
- JWTs — the header and payload are Base64URL-encoded (signed, not encrypted).
- Basic auth —
Authorization: Basic base64(user:pass). - Binary in JSON — keys, certificates, small files.
Base64 vs Base64URL
URLs cannot safely contain + and /, so Base64URL replaces them with - and _ and often drops padding. JWTs use Base64URL.
Practical cautions
- Never store passwords or secrets as Base64.
- Do not use it to "compress" — it expands data.
- Validate decoded output; malformed input yields garbage.
- Mind the size when inlining large files.
Encode and decode free
Use the Base64 encoder/decoder for text and files, and the SHA-256 generator when you need integrity instead of encoding.