Intro

Open almost any API response and you will eventually meet Base64: strings of letters, digits, and an occasional = at the end, standing in for something binary. Email attachments, embedded images, JWT tokens, and database blobs all lean on it.

This guide explains what Base64 is, why the world needs it, and the trade-offs that matter when you use it. You can try it live with the Base64 encoder/decoder, which handles text and files entirely in your browser.

The problem: binary data in text-only channels

Email was invented as a text-only medium, and much of the web still is: JSON, URLs, HTML, and most protocols carry only a limited set of plain characters. Binary data — an image, a file, encrypted bytes — contains arbitrary byte values that text channels can mangle or reject outright.

Base64 solves this by re-encoding binary data using only 64 safe ASCII characters, so it can travel through any text-based system without corruption. The name comes from the 64-character alphabet it uses.

How Base64 encoding works

Base64 reads the input as a stream of bytes and processes it three bytes at a time. Each 3-byte group (24 bits) is split into four 6-bit chunks, and each chunk is mapped to one character in the 64-character alphabet: A–Z, a–z, 0–9, plus + and /.

That is the core trick: 3 binary bytes become 4 text characters, which is why Base64 output is about a third larger than the original data. The alphabet is deliberately chosen from characters that are safe in virtually every text system.

  • 3 bytes in → 24 bits → four 6-bit values → 4 alphabet characters.
  • The alphabet: A–Z, a–z, 0–9, +, / (64 characters total).
  • If the input is not a multiple of 3 bytes, = padding marks the short final group.

Tip: The = signs at the end are not part of the data — they simply signal how many bytes the final group was short by. Decoders use them to know how much padding to strip.

Where you actually meet Base64

Base64 shows up in surprising places once you know to look:

  • Email attachments — MIME encodes file attachments as Base64 so they survive text-only transport.
  • Data URIs — images embedded directly in HTML or CSS as data:image/png;base64,... strings.
  • JWTs — the middle segment of a JSON Web Token is a Base64URL-encoded payload.
  • APIs and databases — binary blobs stored inside JSON or text columns are almost always Base64.

The trade-offs

Base64 is not free. It inflates data by roughly 33%, which matters for large payloads and storage. It is also encoding, not encryption — anyone can decode Base64 instantly, so never use it to protect sensitive data.

For URLs, the standard alphabet has a problem: + and / are not URL-safe. The Base64URL variant replaces them with - and _ and drops the = padding, which is what JWTs and most web APIs use. The Base64 tool on this site handles both variants.

Tip: Base64 is for transport, not secrecy. If you need confidentiality, encrypt the data first and then Base64-encode the ciphertext for transport.

Practical takeaway

Base64 is a transport representation, not a security boundary. Choose the variant expected by the receiving system, account for its size overhead, and decode only data you are authorised to inspect. Use the browser tool for a quick local conversion, then put validation, limits, and key handling in the application that owns the data.

FAQ

What is Base64?

A way to represent binary data using only 64 safe ASCII characters (A–Z, a–z, 0–9, +, /), so it can travel through text-only systems like email, JSON, and URLs without corruption.

Why does Base64 end with = signs?

Padding. Base64 encodes data in 3-byte groups; when the input is not a multiple of 3 bytes, = marks the short final group so decoders can reconstruct the exact original bytes.

Is Base64 encryption?

No. It is encoding — the transformation is reversible by anyone with a decoder. Never rely on Base64 for confidentiality; encrypt first if the data is sensitive.

Why is Base64 output bigger than the input?

Three bytes of input become four characters of output, so Base64 is about 33% larger. That is the price of squeezing arbitrary bytes into a 64-character text alphabet.

What is Base64URL?

A URL-safe variant that swaps + and / for - and _ and drops = padding, so the string can appear in URLs and query parameters without escaping. JWTs use it.

Sources