Base64 is a way of encoding binary data as text. It converts any sequence of bytes into a string of 64 printable characters — A–Z, a–z, 0–9, plus + and /. This lets you safely send images, files, and any binary data through systems that only handle text, like JSON, XML, email, or URLs.

This guide explains what Base64 is, how the encoding works, why it's used, and — most importantly — why it's not encryption and should never be used to protect sensitive data.

Definition
Base64 = Binary-to-Text Encoding
A reversible encoding scheme that turns any binary data into a safe, printable ASCII string — using 64 characters that work everywhere text does.

What Problem Does Base64 Solve?

Computers store data as bytes. Most bytes are fine, but some — like 0x00 (null), 0x0A (newline), or 0xFF — mean something special in many systems. If you try to send raw binary through JSON, email, or URLs, the data can get corrupted or rejected.

Base64 solves this by converting every byte into a printable character that has no special meaning anywhere. Now the data can travel safely through any text-only channel.

Analogy: Think of Base64 like bubble wrap for data. It doesn't change what's inside the package — it just makes it safe to ship through any system that handles text.

The 64 Characters of Base64

Base64 uses exactly 64 characters (hence the name). Every 6 bits of data maps to one character:

A
B
C
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
a
b
c
d
e
f
g
h
i
j
k
l
m
n
o
p
q
r
s
t
u
v
w
x
y
z
0
1
2
3
4
5
6
7
8
9
+
/
=
=

That's the standard set: A–Z, a–z, 0–9, +, /. The = sign is used as padding at the end.

How Base64 Encoding Works

Base64 works in groups of 3 bytes. Here's what happens to the string "Man":

1. "Man" as bytes (ASCII): M = 77 = 01001101 a = 97 = 01100001 n = 110 = 01101110 2. Combine into 24 bits: 010011010110000101101110 3. Split into 4 groups of 6 bits: 010011 | 010110 | 000101 | 101110 4. Each 6-bit group → decimal → Base64 char: 010011 = 19 = T 010110 = 22 = W 000101 = 5 = F 101110 = 46 = u 5. Result: "TWFu"

So "Man" becomes "TWFu". That's the entire algorithm — every 3 bytes become 4 characters.

What happens with padding? If your data isn't a multiple of 3 bytes, one or two = signs are added at the end to fill the last group. For example, "Ma" becomes "TWE=" and "M" becomes "TQ==".

Why Base64 Makes Data Bigger

Every 3 bytes of input become 4 characters of output — that's a 33% size increase. Larger inputs have slightly less overhead due to padding, but the ratio is always around 4:3.

Original
3 bytes
→
Base64
4 bytes

Practical impact: A 750 KB image becomes roughly 1 MB when Base64 encoded. This is why you should not Base64-encode large files unnecessarily — it wastes bandwidth and storage.

Where Base64 Is Used

📧 Email Attachments (MIME)
Email was designed for text only. Every file attachment is Base64 encoded before transmission — that's why email attachments are roughly 33% larger than the original file.
🎨 Inline Images in CSS/HTML
Small images can be embedded directly in code as data:image/png;base64,.... This avoids extra HTTP requests, speeding up page load for icons and small graphics.
🔑 HTTP Basic Authentication
APIs use Base64 to send username:password in the Authorization header. Note: this is only safe over HTTPS — the credentials are readable by anyone if intercepted.
🪙 JSON Web Tokens (JWT)
JWT tokens are three Base64URL-encoded parts separated by dots. The header and payload are JSON that's been encoded to fit in URLs and headers safely.
📦 Embedding Binary in JSON/XML
JSON and XML are text-only. If an API needs to return binary data, it Base64 encodes it into a string field.
🔗 Data URIs in HTML/CSS
Small files can be inlined as data: URLs without a server request — useful for favicons, small SVGs, and background images in CSS.
📊 Database Blobs
Some databases and ORMs store binary data as Base64 strings in text columns for portability.
🖼️ SVG and Small Assets in CSS
Web developers inline SVG icons in CSS using url("data:image/svg+xml;base64,...") to eliminate HTTP requests.

Base64 vs Encryption — The Critical Difference

This is the most important thing to understand about Base64:

Base64 is NOT encryption. It is NOT security. It is NOT protection. Anyone can decode Base64 instantly with no key, no password, no tool — just a decoder. If your password, API key, or secret is Base64 encoded, it is not safe. At all.

Feature Base64 Encryption (AES, RSA)
PurposeEncode binary as textProtect data from unauthorised access
Requires key?NoYes
Can be reversed by anyone?YesNo — only with the key
Provides secrecy?NoYes
Provides integrity?NoYes (with HMAC/AEAD)
Typical useEncoding files, tokensPasswords, HTTPS, sensitive data

Real-world example of the mistake

An API key like sk_live_abc123xyz Base64 encoded becomes c2tfbGl2ZV9hYmMxMjN4eXo=. A beginner might think "now it's hidden." But pasting that string into any Base64 decoder (including ours) instantly reveals the original key.

If you need to protect secrets, use AES-256 encryption, HTTPS, or a secrets manager like AWS Secrets Manager, HashiCorp Vault, or 1Password.

URL-Safe Base64

Standard Base64 uses + and /, which have special meanings in URLs and filenames. To fix this, a variant called Base64URL is used in tokens and URLs:

Standard URL-safe
+-
/_
= paddingDropped

JWTs, URLs, and many modern APIs use Base64URL. Our free Base64 encoder supports both modes.

How to Encode and Decode Base64

In JavaScript

// Encode const encoded = btoa("Hello, world!"); console.log(encoded); // "SGVsbG8sIHdvcmxkIQ==" // Decode const decoded = atob("SGVsbG8sIHdvcmxkIQ=="); console.log(decoded); // "Hello, world!" // For Unicode strings (emoji, non-English) const b64 = btoa(unescape(encodeURIComponent("Hello 🚀"))); const str = decodeURIComponent(escape(atob(b64)));

In Python

import base64 # Encode encoded = base64.b64encode(b"Hello, world!") print(encoded) # b'SGVsbG8sIHdvcmxkIQ==' # Decode decoded = base64.b64decode(b"SGVsbG8sIHdvcmxkIQ==") print(decoded) # b'Hello, world!' # URL-safe variant url_safe = base64.urlsafe_b64encode(b"data")

In Bash

# Encode $ echo -n "Hello, world!" | base64 SGVsbG8sIHdvcmxkIQ== # Decode $ echo "SGVsbG8sIHdvcmxkIQ==" | base64 -d Hello, world!

Common Base64 Mistakes

Mistake 1: Using Base64 for "security"

Base64 is not encryption. Never encode passwords, API keys, or sensitive data and consider it safe. Use real encryption.

Mistake 2: Base64-encoding images for performance

Inlining small images is fine. Inlining large ones bloats your HTML by 33% and blocks rendering. Keep images above ~10 KB as separate files.

Mistake 3: Confusing standard and URL-safe variants

If you see + or / in a URL parameter, it may break — use URL-safe Base64 instead. Conversely, if you're decoding a JWT, use URL-safe decoding.

Mistake 4: Forgetting padding

Some decoders reject Base64 without proper = padding. If decoding fails, check the string length — it must be a multiple of 4 (after adding padding).

Mistake 5: Character encoding issues

JavaScript's btoa() only works with Latin-1 strings. For Unicode text (emoji, Chinese, Arabic), use TextEncoder and TextDecoder, or our online tool which handles UTF-8 correctly.

Base64 in the Real World

Context Usage
Gmail attachmentsEvery file → Base64 (MIME)
JWT tokensHeader + payload → Base64URL
Basic Auth headersuser:pass → Base64
SVG icons in CSSdata:image/svg+xml;base64,...
Kubernetes secretsBase64 (encoding, not encryption!)
Git packfilesBinary blobs → Base64
XML-RPCBinary payloads → Base64
Data URIsSmall files → inline Base64

Skip the Code — Use a Converter

Our free Base64 encoder/decoder handles everything in your browser — text, files, Unicode, and both standard and URL-safe modes. No upload, no signup, no data leaves your device.

🔐 Free Base64 Encoder/Decoder

Encode or decode text and files, with URL-safe and UTF-8 support.

Open Base64 Tool →

Related Developer Tools

Working with Base64 usually means you're also handling JWTs, JSON, and API responses. These tools pair well:

🛠️ All Developer Tools

Free, in-browser utilities for developers.

Browse All Tools →

Frequently Asked Questions

What is Base64?

Base64 is a way of encoding binary data as text using 64 printable ASCII characters (A-Z, a-z, 0-9, +, /). It lets you safely transmit binary data through text-only systems like JSON, XML, email, or URLs.

Is Base64 encryption?

No. Base64 is encoding, not encryption. Anyone can decode Base64 instantly without a key. Never use Base64 to protect passwords, secrets, or sensitive data — use real encryption like AES instead.

Why does Base64 make data larger?

Base64 encodes 3 bytes of data into 4 characters, so it adds about 33% overhead. A 1 KB file becomes roughly 1.33 KB when Base64 encoded.

What is URL-safe Base64?

URL-safe Base64 replaces + with - and / with _, and drops padding equals signs. It's safe to use in URLs, filenames, and JSON Web Tokens.

Where is Base64 used?

Email attachments, inline images in CSS/HTML, HTTP Basic Authentication, JWT tokens, embedding binary data in JSON/XML, and any context where binary must pass through text-only channels.

Can Base64 be decoded?

Yes — always. Base64 encoding is reversible by design, and decoding requires no key or password. Anyone with the encoded string and a Base64 decoder can recover the original data.

Why do JWTs look like Base64?

JWTs consist of three Base64URL-encoded parts joined by dots. The header and payload are JSON data encoded so they're URL-safe. The signature is a binary HMAC also Base64URL-encoded.

Should I Base64-encode images for my website?

Only for small images (under ~10 KB) like icons and small SVGs. Larger images should stay as separate files — inlining them bloats HTML by 33% and blocks page rendering.