Quick answer: Base64 is a way of writing any data, including images and other binary files, using only 64 safe text characters. It lets data travel through systems that only handle plain text, such as email, URLs and JSON. It is an encoding, not encryption. You can convert text with the Base64 encoder and decoder.
How Base64 Works
Base64 reads data three bytes (24 bits) at a time and splits those 24 bits into four groups of six bits. Each six-bit group is a number from 0 to 63, and each number maps to one character in the alphabet: A to Z, a to z, 0 to 9, plus + and /.
For example, the text Man is the bytes 77, 97 and 110. Written in binary and regrouped into sixes, they become 19, 22, 5 and 46, which are the characters TWFu.
When the input is not a multiple of three bytes, the output is padded with one or two = characters. So Hi becomes SGk=.
Why Base64 Output Is Bigger
Three bytes of input become four characters of output, so Base64 is about 33% larger than the original data. That is the price of using only safe characters.
Where You Will See Base64
- Data URIs: small images embedded directly in HTML or CSS.
- Email attachments: the MIME standard uses Base64 to carry binary files in text messages.
- HTTP Basic authentication: the username and password are Base64-encoded in a header.
- JSON Web Tokens (JWT): each segment is Base64URL-encoded JSON.
- APIs: files or binary blobs sent inside JSON payloads.
Standard vs URL-Safe Base64
The characters + and / have special meanings in URLs. URL-safe Base64 (Base64URL) replaces them with - and _ and usually drops the trailing = padding. JWTs use this variant.
Base64 Is Not Encryption
There is no key and no secret: anyone can decode Base64 in one step. If a value is Base64-encoded, treat it as readable. Never use it to hide passwords, tokens or personal data.
Troubleshooting Decoding Problems
- Check for missing
=padding or stray line breaks copied along with the string. - If the string contains
-or_, it is URL-safe Base64. - If the result looks like gibberish, the original data was probably binary (an image or file), not text.
If the decoded text is JSON, paste it into the JSON formatter to read it comfortably.