Glossary

Base64

Base64 is a binary-to-text encoding scheme that represents arbitrary byte data using only 64 printable ASCII characters (A–Z, a–z, 0–9, +, /), so binary content can travel safely through systems — email, JSON, URLs, HTML — that only reliably handle text. It's defined in RFC 4648.

How it works

Base64 groups input bytes into chunks of 3 (24 bits) and re-splits each chunk into four 6-bit groups, mapping each 6-bit value (0–63) to one character in the Base64 alphabet. Because 6 bits can only represent 64 distinct values, three arbitrary bytes always expand to exactly four encoded characters — a fixed 4:3 size overhead of roughly 33%. When the input length isn't a multiple of 3, the last group is padded with one or two = characters so the output length always stays a multiple of 4.

A URL-safe variant, Base64URL (RFC 4648 §5), swaps +→- and /→_ so the output can appear in a URL or filename without percent-encoding, and conventionally omits the = padding since the decoder can infer it from length.

Example:

Input (bytes):  "hi!"           (3 bytes → no padding)
Base64:         "aGkh"

Input (bytes):  "hi"            (2 bytes → 1 padding char)
Base64:         "aGk="

Common pitfalls

  • Base64 is an encoding, not encryption — anyone can decode it instantly. Never use it to "hide" secrets or passwords.
  • Encoded output is always ~33% larger than the input; encoding large files inline (e.g. as a data URI) bloats payload size.
  • Standard Base64's + and / characters need percent-encoding inside a URL — use Base64URL instead to avoid double-encoding bugs.
  • Mixing standard and URL-safe alphabets when decoding (e.g. feeding a +// string to a URL-safe-only decoder) fails silently or throws, depending on the library.

Related terms

  • UTF-8 — the encoding usually applied to text before it's Base64-encoded, since Base64 itself only operates on raw bytes.
  • JWT — uses Base64URL (without padding) to encode its header and payload segments.
  • Unicode — the character set that text must be converted to bytes from before Base64 can encode it.

See also

  • Tool: Base64 Encode / Decode — encode text to Base64 or decode Base64 back to text, with UTF-8 and URL-safe support.