What Is Base64 Encoding? How It Works, With Examples
Short answer
Base64 is a way to represent any binary data using only 64 safe text characters: A–Z, a–z, 0–9, + and /, with = for padding. It takes every 3 bytes (24 bits) and writes them as 4 characters of 6 bits each, so “Man” becomes “TWFu”. It makes data about 33% larger and it is not encryption: anyone can decode it.
If you have looked at an email’s raw source, a data URL in CSS, an API token or a JSON payload with an embedded image, you have probably seen long strings like SGVsbG8=. That is Base64. It exists because many systems were designed to carry text, not raw bytes, and binary data such as images can be mangled when it passes through them. Base64 solves that by turning bytes into plain, safe characters.
The Base64 alphabet
Standard Base64, defined in RFC 4648, uses 64 characters, one for each 6-bit value from 0 to 63:
| Values | Characters |
|---|---|
| 0–25 | A–Z |
| 26–51 | a–z |
| 52–61 | 0–9 |
| 62 | + |
| 63 | / |
The = sign is used only for padding at the end.
How encoding works, step by step
Let’s encode the word “Man”.
- Convert characters to bytes. In ASCII, M = 77, a = 97, n = 110.
- Write the bytes in binary. 01001101 01100001 01101110 (24 bits).
- Split into 6-bit groups. 010011 010110 000101 101110.
- Convert each group to a number. 19, 22, 5, 46.
- Look up each number in the alphabet. 19 = T, 22 = W, 5 = F, 46 = u.
Result: TWFu. If binary numbers are new to you, our guide to converting binary to decimal explains step 4.
Padding: what the = signs mean
Base64 works on groups of 3 bytes. When the input length is not a multiple of 3, the encoder pads the last group with zero bits and adds = characters so the output length is a multiple of 4:
| Input | Bytes | Base64 |
|---|---|---|
| Man | 3 | TWFu |
| Hi | 2 | SGk= |
| Hello | 5 | SGVsbG8= |
| hello world | 11 | aGVsbG8gd29ybGQ= |
One leftover byte gives two = signs, two leftover bytes give one. Some systems omit padding because the decoder can work out the length anyway.
Why Base64 makes data bigger
Every 3 bytes become 4 characters, so encoded data is about 33% larger than the original (plus a little for padding and any line breaks). A 300 KB image becomes about 400 KB of Base64 text. That is the price of making binary data text-safe.
Unicode text and Base64
Base64 encodes bytes, not characters. Text must first be turned into bytes using a character encoding, almost always UTF-8. The word “café” is 5 bytes in UTF-8 because é takes two bytes, and it encodes to Y2Fmw6k=. In browsers, the built-in btoa() function only accepts characters in the Latin-1 range, so calling it on text with emoji or many non-Latin scripts throws an error unless you convert the text to UTF-8 bytes first. Our Base64 encoder and decoder handles UTF-8 automatically.
URL-safe Base64 (base64url)
The + and / characters have special meanings in URLs and file names. RFC 4648 defines a variant called base64url that replaces them with - and _, and padding is often dropped. For example, the bytes that standard Base64 writes as +/8= become -_8 in base64url. JSON Web Tokens use base64url for their header and payload, which is why you can read a token’s contents with a JWT decoder without any key.
Where Base64 is used
- Email attachments: MIME encodes attachments as Base64 so they survive mail servers.
- Data URLs: small images or fonts embedded directly in HTML or CSS, such as
data:image/png;base64,.... - APIs and JSON: sending binary data, such as a file or signature, inside JSON, which only supports text. See JSON basics for beginners.
- Authentication headers: HTTP Basic authentication sends “username:password” Base64-encoded, which is why it must only be used over HTTPS.
- Tokens and keys: JWTs and many key formats such as PEM certificates.
Base64 is not encryption
This is the most important point. Base64 has no key and no secret. Anyone can decode it instantly, so it provides no security at all. Never “hide” passwords or personal data with Base64. If you need to check that data has not changed, use a hash from the hash generator; if you need secrecy, use proper encryption.
Base64 versus URL encoding
URL encoding (percent-encoding) is different: it replaces only unsafe characters with codes such as %20 for a space, leaving letters and numbers as they are. Use it for query string values; use Base64 for binary data. The URL encoder and decoder handles percent-encoding.
Base64 in code and on the command line
- JavaScript:
btoa()encodes andatob()decodes (Latin-1 only, see above). - Python:
base64.b64encode(data)andbase64.b64decode(text), withurlsafe_b64encodefor base64url. - Terminal:
echo -n 'Hello' | base64prints SGVsbG8=, andbase64 -ddecodes (older macOS versions use-D).
Decoding errors and how to fix them
- Invalid character: the string contains spaces, line breaks or characters outside the alphabet. Remove whitespace, and convert - and _ back to + and / if it is base64url.
- Incorrect length: add = padding until the length is a multiple of 4.
- Garbled output: the data is binary (such as an image), or the original text used a different character encoding than UTF-8.
Frequently asked questions
What is Base64 used for?
It turns binary data into plain text so it can travel safely through systems built for text, such as email, JSON, HTML data URLs and HTTP headers.
Is Base64 encryption?
No. Base64 has no key and can be decoded by anyone. It is an encoding for compatibility, not a security measure.
Why does Base64 end with = or ==?
The equals signs are padding added when the input length is not a multiple of 3 bytes, so the output length is a multiple of 4.
How much bigger is Base64?
About 33% bigger, because every 3 bytes of input become 4 characters of output.
What is the difference between Base64 and base64url?
base64url replaces + with - and / with _ so the result is safe in URLs and file names, and often omits padding.