Security

What Is Base64 Encoding? (And When to Use It)

📅 June 6, 2026⏱ 5 min read 🛠️ Try the Base64 Encoder →

Base64 is everywhere — in JWTs, image embeds, email attachments and API authentication. This guide explains exactly what it is, how it works and when to use it — with code examples in JavaScript, Python and C#.

What Is Base64 Encoding?

Base64 is a binary-to-text encoding scheme that converts binary data into a string of 64 printable ASCII characters. It's called "Base64" because it uses a 64-character alphabet:

ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/

Plus the = character for padding.

Simple example:

Text:   Hello
Base64: SGVsbG8=

Why Does Base64 Exist?

Many systems were designed to handle text only — not raw binary data. For example:

Base64 solves this by converting any binary data (images, files, keys) into a safe text format that can travel through text-only systems without corruption.

How Base64 Encoding Works

Base64 works by taking 3 bytes (24 bits) of binary data and splitting them into 4 groups of 6 bits, then mapping each 6-bit group to a character in the Base64 alphabet.

Text:     H        e        l
ASCII:    72       101      108
Binary:   01001000 01100101 01101100
          ↓ Split into 4 × 6-bit groups
          010010 000110 010101 101100
          ↓ Map to Base64 alphabet
          S      G      V      s
Result:   SGVs

Since 3 bytes become 4 characters, Base64 increases data size by approximately 33%.

Base64 Padding (=)

If the input isn't divisible by 3 bytes, padding characters (=) are added:

1 byte  remaining → 2 Base64 chars + ==
2 bytes remaining → 3 Base64 chars + =
3 bytes remaining → 4 Base64 chars (no padding)
"A"   → QQ==   (1 byte, 2 padding chars)
"AB"  → QUI=   (2 bytes, 1 padding char)
"ABC" → QUJD   (3 bytes, no padding)

Common Uses of Base64

Use caseExample
JWT tokensHeader and payload are Base64URL encoded
Email attachmentsMIME encoding for binary attachments
Inline images in HTML/CSSdata:image/png;base64,iVBOR...
API authenticationHTTP Basic Auth: Base64(username:password)
Storing binary in JSONEmbed images or files in JSON payloads
Cryptographic keysPEM files use Base64 to encode keys
Data URLsEmbed fonts and images directly in CSS

Base64 in JavaScript

// Encode
const encoded = btoa('Hello, World!');
console.log(encoded); // SGVsbG8sIFdvcmxkIQ==

// Decode
const decoded = atob('SGVsbG8sIFdvcmxkIQ==');
console.log(decoded); // Hello, World!

// Encode Unicode (handles special characters)
function encodeUnicode(str) {
  return btoa(encodeURIComponent(str).replace(/%([0-9A-F]{2})/g,
    (match, p1) => String.fromCharCode('0x' + p1)
  ));
}

// Decode Unicode
function decodeUnicode(str) {
  return decodeURIComponent(atob(str).split('').map(
    c => '%' + ('00' + c.charCodeAt(0).toString(16)).slice(-2)
  ).join(''));
}

// Node.js
const encoded = Buffer.from('Hello').toString('base64');
const decoded = Buffer.from(encoded, 'base64').toString('utf8');

Base64 in Python

import base64

# Encode
text = "Hello, World!"
encoded = base64.b64encode(text.encode('utf-8'))
print(encoded)           # b'SGVsbG8sIFdvcmxkIQ=='
print(encoded.decode())  # SGVsbG8sIFdvcmxkIQ==

# Decode
decoded = base64.b64decode('SGVsbG8sIFdvcmxkIQ==')
print(decoded.decode('utf-8'))  # Hello, World!

# Encode a file
with open('image.png', 'rb') as f:
    encoded = base64.b64encode(f.read()).decode('utf-8')

# URL-safe Base64 (for JWT, URLs)
encoded = base64.urlsafe_b64encode(b'Hello').decode()
decoded = base64.urlsafe_b64decode(encoded + '==')

Base64 in C# / .NET

using System;
using System.Text;

// Encode
string text = "Hello, World!";
byte[] bytes = Encoding.UTF8.GetBytes(text);
string encoded = Convert.ToBase64String(bytes);
Console.WriteLine(encoded); // SGVsbG8sIFdvcmxkIQ==

// Decode
byte[] decodedBytes = Convert.FromBase64String(encoded);
string decoded = Encoding.UTF8.GetString(decodedBytes);
Console.WriteLine(decoded); // Hello, World!

// Encode a file
byte[] fileBytes = File.ReadAllBytes("image.png");
string base64File = Convert.ToBase64String(fileBytes);

// URL-safe Base64 (for JWT)
string urlSafe = encoded.Replace('+', '-').Replace('/', '_').TrimEnd('=');

Base64 vs Base64URL

Standard Base64 uses + and / which have special meanings in URLs. Base64URL replaces them:

FormatCharactersUsed in
Base64+ and /Email, files, general encoding
Base64URL- and _JWT tokens, URLs, filenames
# Convert Base64 to Base64URL
base64url = base64.replace('+', '-').replace('/', '_').rstrip('=')

Is Base64 Encryption?

⚠️ No — Base64 is NOT encryption! This is a very common misconception.

# This is NOT secure — anyone can decode it
password_encoded = base64.b64encode(b'mysecretpassword')

# This IS secure
import hashlib, hmac
password_hash = hmac.new(key, password.encode(), hashlib.sha256).hexdigest()

Frequently Asked Questions

What is the difference between Base64 and Base64URL?
Base64URL replaces + with - and / with _, and removes padding (=). It's safe to use in URLs and filenames. JWT tokens use Base64URL encoding.

Does Base64 increase file size?
Yes — by approximately 33%. Every 3 bytes of input becomes 4 Base64 characters. A 1MB file becomes ~1.33MB when Base64 encoded.

Why does Base64 end with == sometimes?
The = signs are padding characters added when the input length isn't a multiple of 3 bytes. One = means 2 bytes remain; == means 1 byte remains.

Is Base64 the same as encryption?
No — Base64 is encoding, not encryption. Anyone can decode it instantly without a key. Never use Base64 to "hide" sensitive data.

How do I encode an image to Base64 for HTML?

# Python
import base64
with open('image.png', 'rb') as f:
    b64 = base64.b64encode(f.read()).decode()
    print(f'data:image/png;base64,{b64}')

Then use it in HTML: <img src="data:image/png;base64,SGVs...">

Encode or decode Base64 instantly — free

Paste any text and encode to Base64 or decode back instantly. Runs 100% in your browser — your data never leaves your computer.

Base64 Encoder/Decoder →