Skip to content

Base64 Encoding: What It Is, How It Works, and When to Use It

What Is Base64 Encoding?

Base64 is a binary-to-text encoding scheme that converts binary data into a string of 64 printable ASCII characters. It was designed to solve a specific problem: transmitting binary data through systems that only support text — email being the original and most important use case.

Encode and decode any text or data with WritePadPro's Base64 Encoder & Decoder — paste plain text to get the Base64 representation, or paste Base64 to decode it back to readable text.

When you attach a photo to an email, that image is binary data — sequences of bytes representing pixel colors. But email protocols (SMTP) were designed to carry 7-bit ASCII text, not arbitrary binary. Base64 converts the image's binary bytes into a safe text representation that travels through the email system, then the recipient's email client decodes it back to the original image.

The name "Base64" comes from the encoding's alphabet of 64 characters. Just as decimal uses 10 digits (0-9) and hexadecimal uses 16 (0-F), Base64 uses 64 characters: A-Z (26), a-z (26), 0-9 (10), + and / (2). These 64 characters are safe in virtually every text-based protocol and system.

How the Algorithm Works

The Base64 encoding process converts every 3 bytes of input into 4 characters of output, using a 6-bit grouping scheme.

Step 1: Convert to Binary

Take the input bytes and express them as a continuous binary stream. The text "Hi" in ASCII is two bytes: H = 72 = 01001000, i = 105 = 01101001. Combined: 01001000 01101001.

Step 2: Split Into 6-Bit Groups

Instead of the usual 8-bit byte grouping, split the binary stream into 6-bit groups: 010010 000110 1001. Since the last group has only 4 bits, pad with zeros to make 6: 010010 000110 100100.

Step 3: Map to Base64 Characters

Each 6-bit group represents a value from 0 to 63. Map each value to the Base64 alphabet:

6-Bit ValueDecimalBase64 Character
01001018S
0001106G
10010036k

Step 4: Add Padding

Base64 output must be a multiple of 4 characters. Since "Hi" produces only 3 Base64 characters (SGk), add one = padding character: SGk=

The Complete Base64 Alphabet

Values 0-15Values 16-31Values 32-47Values 48-63
0=A, 1=B, 2=C, 3=D16=Q, 17=R, 18=S, 19=T32=g, 33=h, 34=i, 35=j48=w, 49=x, 50=y, 51=z
4=E, 5=F, 6=G, 7=H20=U, 21=V, 22=W, 23=X36=k, 37=l, 38=m, 39=n52=0, 53=1, 54=2, 55=3
8=I, 9=J, 10=K, 11=L24=Y, 25=Z, 26=a, 27=b40=o, 41=p, 42=q, 43=r56=4, 57=5, 58=6, 59=7
12=M, 13=N, 14=O, 15=P28=c, 29=d, 30=e, 31=f44=s, 45=t, 46=u, 47=v60=8, 61=9, 62=+, 63=/

Padding Rules

  • 3 bytes input → 4 Base64 characters, no padding
  • 2 bytes input → 3 Base64 characters + one =
  • 1 byte input → 2 Base64 characters + two ==

Padding ensures the encoded output length is always a multiple of 4, which simplifies decoding. For a comparison of how binary data is represented numerically, see our Binary & Hex Guide.

The 33% Size Overhead

Base64 encoding increases data size by approximately 33%. Every 3 bytes of input become 4 bytes of output — a 4:3 expansion ratio. A 1 MB image becomes approximately 1.33 MB when Base64 encoded.

Why the Overhead?

Each byte has 8 bits (256 possible values). Each Base64 character represents only 6 bits (64 possible values). You need more characters to encode the same information: 8 bits per byte ÷ 6 bits per character = 1.33 characters per byte.

When the Overhead Matters

  • Inline images in CSS/HTML: A 10 KB icon becomes ~13.3 KB when Base64 encoded and embedded. For small images (under 5 KB), the overhead is offset by saving an HTTP request. For large images, the overhead makes Base64 embedding counterproductive.
  • API payloads: Base64-encoded file uploads are 33% larger than binary uploads. Most modern APIs accept multipart/form-data (binary) to avoid this overhead.
  • Email attachments: A 5 MB PDF attachment becomes ~6.7 MB after Base64 encoding. This is why email attachment limits are typically lower than the raw file size limit.

When the Overhead Does NOT Matter

  • Short strings: Encoding a 32-byte API token adds only ~11 bytes — negligible.
  • JWT tokens: JWT payloads are typically under 1 KB. The 33% overhead adds a few hundred bytes — irrelevant.
  • Small icons: A 2 KB SVG icon becomes 2.7 KB. Saving the HTTP request is worth more than the 700 bytes.

Use Cases for Base64 Encoding

1. Email Attachments (MIME)

The original motivation for Base64 was email. SMTP (Simple Mail Transfer Protocol) was designed to carry 7-bit ASCII text. Binary files — images, PDFs, executables — cannot travel through SMTP directly. MIME (Multipurpose Internet Mail Extensions) solves this by Base64-encoding attachments into text that SMTP can transport. Every email client decodes Base64 attachments transparently — you see the image, not the encoded text.

2. Data URIs (Inline Images)

Data URIs embed Base64-encoded images directly in HTML or CSS, eliminating a separate HTTP request:

<img src="data:image/png;base64,iVBORw0KGgoAAAANS..." />

This technique is best for small images (under 5 KB) — icons, logos, decorative elements. Larger images should remain as separate files because the 33% size increase and loss of browser caching outweigh the saved HTTP request. For related HTML encoding techniques, see the URL Encoder and HTML Encoder.

3. JWT (JSON Web Tokens)

JWT tokens — the standard for web authentication — use Base64url encoding (a variant that replaces + with - and / with _) for their header and payload segments. A JWT looks like: eyJhbGciOiJIUzI1NiJ9.eyJ1c2VyIjoiam9obiJ9.abc123... Each segment before the dots is a Base64url-encoded JSON object.

4. API Data Transfer

When APIs need to include binary data (images, documents, certificates) in JSON payloads, Base64 encoding converts the binary into a JSON-safe string. The receiving system decodes it back to binary. While not the most efficient method (multipart uploads are better for large files), it is simple and universally supported.

5. Storing Binary in Text Databases

Some databases and configuration systems only support text fields. Base64 allows storing small binary blobs (cryptographic keys, small images, encoded certificates) in text columns without corruption. For building and testing encoded content, see our Code Playground Guide.

6. Obfuscation (NOT Encryption)

Base64 is sometimes used to obscure data from casual inspection — encoding a password or API key so it is not immediately readable. However, Base64 is not encryption. It is trivially reversible by anyone. Never use Base64 as a security measure. It is an encoding scheme, not a cryptographic algorithm.

Base64 Variants

Several Base64 variants exist for different contexts, each modifying the standard alphabet slightly.

VariantCharacters 62-63PaddingUsed In
Standard (RFC 4648)+ /= paddingEmail (MIME), general use
URL-safe (RFC 4648 §5)- _OptionalURLs, JWT, filenames
MIME (RFC 2045)+ /= padding, line breaks every 76 charsEmail attachments
Filename-safe- _No paddingFilenames, URL parameters

Why URL-Safe Base64 Exists

Standard Base64 uses + and / characters, which have special meanings in URLs (+ means space, / is a path separator). URL-safe Base64 replaces these with - (hyphen) and _ (underscore), which are safe in URLs without percent-encoding. JWT uses URL-safe Base64 for this reason — tokens often appear in URL query parameters.

Base64 in Programming Languages

Every modern programming language provides built-in Base64 encoding and decoding functions.

LanguageEncodeDecode
JavaScript (browser)btoa(string)atob(string)
JavaScript (Node.js)Buffer.from(str).toString('base64')Buffer.from(b64, 'base64').toString()
Pythonbase64.b64encode(bytes)base64.b64decode(string)
PHPbase64_encode($string)base64_decode($string)
JavaBase64.getEncoder().encode(bytes)Base64.getDecoder().decode(string)
C#Convert.ToBase64String(bytes)Convert.FromBase64String(string)
Gobase64.StdEncoding.EncodeToString(bytes)base64.StdEncoding.DecodeString(str)
RubyBase64.encode64(string)Base64.decode64(string)
Command lineecho -n "text" | base64echo "dGV4dA==" | base64 -d

Note: JavaScript's btoa() only works with Latin-1 characters. For Unicode text, first encode to UTF-8: btoa(unescape(encodeURIComponent(text))). For related encoding guides, see our URL Encoding Guide and HTML Entities Guide.

Using WritePadPro's Base64 Encoder & Decoder

WritePadPro's Base64 Encoder & Decoder converts between plain text and Base64 instantly.

Step 1: Open the Tool

Navigate to the Base64 Encoder & Decoder. You will see an input area and encode/decode options.

Step 2: Encode Text to Base64

Paste or type your plain text. Click encode. The tool converts each character to its byte value, groups the bytes into 6-bit segments, maps to the Base64 alphabet, and adds padding. "Hello, World!" becomes SGVsbG8sIFdvcmxkIQ==

Step 3: Decode Base64 to Text

Paste a Base64 string. Click decode. The tool reverses the process: maps each character to its 6-bit value, reassembles into 8-bit bytes, and converts to text. SGVsbG8sIFdvcmxkIQ== becomes "Hello, World!"

Step 4: Verify and Use

Use the encoded output in data URIs, API payloads, JWT debugging, email troubleshooting, or any context requiring text-safe binary representation.

Privacy

All encoding and decoding runs locally in your browser using JavaScript's built-in Base64 functions. Your data is never transmitted to any server. This is especially important when decoding JWT tokens or API credentials — sensitive data should never be pasted into server-based encoding tools.

Summary

Base64 is a binary-to-text encoding that converts arbitrary data into 64 safe ASCII characters (A-Z, a-z, 0-9, +, /). It exists because many systems — email protocols, JSON, URLs, text databases — cannot handle raw binary data. The algorithm groups input bytes into 6-bit segments and maps each to a character, producing output 33% larger than the input.

Primary use cases: email attachments (MIME), data URIs for inline images, JWT tokens, API data transfer, and text-field binary storage. Base64 is an encoding scheme, not encryption — it is trivially reversible and should never be used for security.

Encode and decode with WritePadPro's Base64 Encoder & Decoder — instant conversion in your browser with complete privacy.

Frequently Asked Questions

Is Base64 encoding the same as encryption?

No. Base64 is an encoding scheme, not encryption. Encoding converts data from one format to another for compatibility — it is freely reversible by anyone using any Base64 decoder. Encryption converts data into an unreadable form that requires a secret key to decrypt. Base64-encoded data looks random but can be decoded in milliseconds by anyone. Never use Base64 to 'secure' passwords, API keys, or sensitive information. For actual security, use proper encryption algorithms (AES, RSA) or hashing functions (bcrypt, SHA-256).

Why does Base64 increase file size by 33%?

Base64 represents 8-bit bytes (256 possible values each) using characters that carry only 6 bits of information (64 possible values each). You need more characters to encode the same data: 8 bits per byte divided by 6 bits per Base64 character equals 1.33 characters per byte — a 33% increase. Three bytes of input (24 bits) produce exactly four Base64 characters (24 bits). This 4:3 ratio is the mathematical minimum for encoding 8-bit data in a 6-bit alphabet. The overhead is unavoidable by design.

What is the difference between Base64 and URL-safe Base64?

Standard Base64 uses + and / as its 62nd and 63rd characters. These characters have special meanings in URLs: + represents a space in query strings, and / is the path separator. URL-safe Base64 (defined in RFC 4648 Section 5) replaces + with - (hyphen) and / with _ (underscore), which are safe in URLs without percent-encoding. JWT tokens use URL-safe Base64 because tokens frequently appear in URL query parameters. WritePadPro's encoder uses standard Base64 — for URL contexts, replace + with - and / with _ in the output.

When should I use Base64 data URIs for images?

Use Base64 data URIs for small images (under 5 KB) that appear on every page — favicons, small icons, UI elements, simple logos. The 33% size increase is offset by eliminating an HTTP request. For images larger than 5 KB, use regular image files instead. Large Base64 images bloat HTML/CSS file size, cannot be cached independently by the browser, and increase initial page load time. The break-even point depends on server latency — with HTTP/2 multiplexing, the threshold for Base64 advantage drops even further.

How do I decode a JWT token?

A JWT token has three parts separated by dots: header.payload.signature. The header and payload are Base64url-encoded JSON objects. To decode: (1) Split the token at the dots. (2) Take the first or second segment. (3) Replace - with + and _ with /. (4) Add = padding if needed to make length a multiple of 4. (5) Decode using any Base64 decoder. WritePadPro's Base64 Encoder & Decoder handles standard Base64 — for JWT decoding, perform the character replacement first, then paste into the decoder. Never paste JWT tokens into server-based decoders — the token may contain sensitive claims.

Related Tools

Related Articles