Base64 is a way of encoding binary data as text. It converts any sequence of bytes into a string of 64 printable characters — A–Z, a–z, 0–9, plus + and /. This lets you safely send images, files, and any binary data through systems that only handle text, like JSON, XML, email, or URLs.
This guide explains what Base64 is, how the encoding works, why it's used, and — most importantly — why it's not encryption and should never be used to protect sensitive data.
What Problem Does Base64 Solve?
Computers store data as bytes. Most bytes are fine, but some — like 0x00 (null), 0x0A (newline), or 0xFF — mean something special in many systems. If you try to send raw binary through JSON, email, or URLs, the data can get corrupted or rejected.
Base64 solves this by converting every byte into a printable character that has no special meaning anywhere. Now the data can travel safely through any text-only channel.
Analogy: Think of Base64 like bubble wrap for data. It doesn't change what's inside the package — it just makes it safe to ship through any system that handles text.
The 64 Characters of Base64
Base64 uses exactly 64 characters (hence the name). Every 6 bits of data maps to one character:
That's the standard set: A–Z, a–z, 0–9, +, /. The = sign is used as padding at the end.
How Base64 Encoding Works
Base64 works in groups of 3 bytes. Here's what happens to the string "Man":
So "Man" becomes "TWFu". That's the entire algorithm — every 3 bytes become 4 characters.
What happens with padding? If your data isn't a multiple of 3 bytes, one or two = signs are added at the end to fill the last group. For example, "Ma" becomes "TWE=" and "M" becomes "TQ==".
Why Base64 Makes Data Bigger
Every 3 bytes of input become 4 characters of output — that's a 33% size increase. Larger inputs have slightly less overhead due to padding, but the ratio is always around 4:3.
Practical impact: A 750 KB image becomes roughly 1 MB when Base64 encoded. This is why you should not Base64-encode large files unnecessarily — it wastes bandwidth and storage.
Where Base64 Is Used
data:image/png;base64,.... This avoids extra HTTP requests, speeding up page load for icons and small graphics.username:password in the Authorization header. Note: this is only safe over HTTPS — the credentials are readable by anyone if intercepted.data: URLs without a server request — useful for favicons, small SVGs, and background images in CSS.url("data:image/svg+xml;base64,...") to eliminate HTTP requests.Base64 vs Encryption — The Critical Difference
This is the most important thing to understand about Base64:
Base64 is NOT encryption. It is NOT security. It is NOT protection. Anyone can decode Base64 instantly with no key, no password, no tool — just a decoder. If your password, API key, or secret is Base64 encoded, it is not safe. At all.
| Feature | Base64 | Encryption (AES, RSA) |
|---|---|---|
| Purpose | Encode binary as text | Protect data from unauthorised access |
| Requires key? | No | Yes |
| Can be reversed by anyone? | Yes | No — only with the key |
| Provides secrecy? | No | Yes |
| Provides integrity? | No | Yes (with HMAC/AEAD) |
| Typical use | Encoding files, tokens | Passwords, HTTPS, sensitive data |
Real-world example of the mistake
An API key like sk_live_abc123xyz Base64 encoded becomes c2tfbGl2ZV9hYmMxMjN4eXo=. A beginner might think "now it's hidden." But pasting that string into any Base64 decoder (including ours) instantly reveals the original key.
If you need to protect secrets, use AES-256 encryption, HTTPS, or a secrets manager like AWS Secrets Manager, HashiCorp Vault, or 1Password.
URL-Safe Base64
Standard Base64 uses + and /, which have special meanings in URLs and filenames. To fix this, a variant called Base64URL is used in tokens and URLs:
| Standard | URL-safe |
|---|---|
+ | - |
/ | _ |
= padding | Dropped |
JWTs, URLs, and many modern APIs use Base64URL. Our free Base64 encoder supports both modes.
How to Encode and Decode Base64
In JavaScript
In Python
In Bash
Common Base64 Mistakes
Mistake 1: Using Base64 for "security"
Base64 is not encryption. Never encode passwords, API keys, or sensitive data and consider it safe. Use real encryption.
Mistake 2: Base64-encoding images for performance
Inlining small images is fine. Inlining large ones bloats your HTML by 33% and blocks rendering. Keep images above ~10 KB as separate files.
Mistake 3: Confusing standard and URL-safe variants
If you see + or / in a URL parameter, it may break — use URL-safe Base64 instead. Conversely, if you're decoding a JWT, use URL-safe decoding.
Mistake 4: Forgetting padding
Some decoders reject Base64 without proper = padding. If decoding fails, check the string length — it must be a multiple of 4 (after adding padding).
Mistake 5: Character encoding issues
JavaScript's btoa() only works with Latin-1 strings. For Unicode text (emoji, Chinese, Arabic), use TextEncoder and TextDecoder, or our online tool which handles UTF-8 correctly.
Base64 in the Real World
| Context | Usage |
|---|---|
| Gmail attachments | Every file → Base64 (MIME) |
| JWT tokens | Header + payload → Base64URL |
| Basic Auth headers | user:pass → Base64 |
| SVG icons in CSS | data:image/svg+xml;base64,... |
| Kubernetes secrets | Base64 (encoding, not encryption!) |
| Git packfiles | Binary blobs → Base64 |
| XML-RPC | Binary payloads → Base64 |
| Data URIs | Small files → inline Base64 |
Skip the Code — Use a Converter
Our free Base64 encoder/decoder handles everything in your browser — text, files, Unicode, and both standard and URL-safe modes. No upload, no signup, no data leaves your device.
🔐 Free Base64 Encoder/Decoder
Encode or decode text and files, with URL-safe and UTF-8 support.
Open Base64 Tool →Related Developer Tools
Working with Base64 usually means you're also handling JWTs, JSON, and API responses. These tools pair well:
- JSON Formatter — beautify and validate API responses
- Unix Timestamp Converter — decode JWT
expandiatclaims - Regex Tester — extract Base64 strings from logs
Frequently Asked Questions
What is Base64?
Base64 is a way of encoding binary data as text using 64 printable ASCII characters (A-Z, a-z, 0-9, +, /). It lets you safely transmit binary data through text-only systems like JSON, XML, email, or URLs.
Is Base64 encryption?
No. Base64 is encoding, not encryption. Anyone can decode Base64 instantly without a key. Never use Base64 to protect passwords, secrets, or sensitive data — use real encryption like AES instead.
Why does Base64 make data larger?
Base64 encodes 3 bytes of data into 4 characters, so it adds about 33% overhead. A 1 KB file becomes roughly 1.33 KB when Base64 encoded.
What is URL-safe Base64?
URL-safe Base64 replaces + with - and / with _, and drops padding equals signs. It's safe to use in URLs, filenames, and JSON Web Tokens.
Where is Base64 used?
Email attachments, inline images in CSS/HTML, HTTP Basic Authentication, JWT tokens, embedding binary data in JSON/XML, and any context where binary must pass through text-only channels.
Can Base64 be decoded?
Yes — always. Base64 encoding is reversible by design, and decoding requires no key or password. Anyone with the encoded string and a Base64 decoder can recover the original data.
Why do JWTs look like Base64?
JWTs consist of three Base64URL-encoded parts joined by dots. The header and payload are JSON data encoded so they're URL-safe. The signature is a binary HMAC also Base64URL-encoded.
Should I Base64-encode images for my website?
Only for small images (under ~10 KB) like icons and small SVGs. Larger images should stay as separate files — inlining them bloats HTML by 33% and blocks page rendering.