Guides › Text, code, and data
Base64 explained: what it is and what it is not
Last updated 10 October 2026 · Written by Souren Das
Base64 turns up everywhere once you start looking: in email attachments, in data: URLs for small images, in API tokens, and in config files that store certificates. It looks like scrambled text, which leads many people to think it is a kind of encryption. It is not. This guide explains what Base64 is for, why it makes data larger, why it hides nothing, and how to encode and decode text in your browser with Dev Tools.
The problem Base64 solves
Computers store everything as bytes, values from 0 to 255. Many older systems, such as email and some text formats, were designed to carry only a safe set of printable characters. Raw bytes from an image or a file can include values those systems treat as control characters, line endings, or the end of a message, and the data gets corrupted.
Base64 is a way to write any bytes using only 64 safe characters: A to Z, a to z, 0 to 9, plus + and /, with = used for padding at the end. Any system that can carry ordinary text can carry Base64, and the receiver decodes it back to the exact original bytes.
How it works, briefly
Base64 takes the input three bytes at a time. Three bytes are 24 bits. It splits those into four groups of 6 bits, and each 6-bit group (a number from 0 to 63) maps to one of the 64 characters. So every 3 bytes of input become 4 characters of output.
That is why Base64 output is about a third larger than the input: 4 characters for every 3 bytes. When the input length is not a multiple of three, the output is padded with one or two = signs so the decoder knows where the data ends.
For example, the word "Man" is three bytes and encodes to "TWFu". The word "Ma" is two bytes and encodes to "TWE=".
Why Base64 is not encryption
Encryption needs a secret key; without it, the data cannot be read. Base64 has no key. Anyone can decode it with any Base64 tool, including the one on this site, in a second. It is an encoding, like writing a word in a different alphabet.
So never treat a Base64 string as protected. Common places where this matters:
- HTTP Basic authentication sends username:password in Base64. It is only safe over HTTPS, which does the actual encrypting.
- JSON Web Tokens (JWTs) are three Base64URL-encoded parts. The middle part, with user details, is readable by anyone who has the token. The signature only proves it was not altered.
- Kubernetes secrets and some config files store values in Base64. That is to keep binary data intact, not to hide it.
If you need to protect data, use real encryption. For a PDF, Password protect PDF uses AES-256 with a password.
Encode and decode in Dev Tools
- Open Dev Tools and choose the Base64 tab.
- To encode, type or paste text into Plain text (UTF-8) and press Encode to Base64. The result appears in the Base64 box.
- To decode, paste a Base64 string into the Base64 box and press Decode from Base64. The text appears in the plain text box. Spaces and line breaks in the Base64 are ignored, so you can paste wrapped output from an email or a terminal.
- If the Base64 is broken, or decodes to bytes that are not valid UTF-8 text, the plain text box says "Invalid Base64, or the bytes are not UTF-8 text".
The encoder works on the UTF-8 bytes of your text, so accented letters, Hindi, Tamil, and emoji encode and decode correctly, and the output matches the base64 command on Linux and macOS for the same text.
Base64 and Base64URL
Standard Base64 uses + and /, which have special meanings in web addresses. Base64URL, used in JWTs and some URLs, swaps them for - and _ and often drops the = padding. Dev Tools uses standard Base64. To decode a Base64URL string, replace - with + and _ with /, and add = signs until the length is a multiple of four.
Common mistakes
- Thinking it secures a password. It does not. See above.
- Decoding a file as text. If the Base64 holds an image or a PDF, decoding to text fails or shows garbage. This tool handles text only.
- Copying with missing characters. A Base64 string cut short by one character will not decode. Copy the full string, including any = at the end.
- Using Base64 to shrink data. It always makes data bigger. To make files smaller, compress them.
- Embedding large images as data: URLs. Base64 images in HTML or CSS are a third larger and cannot be cached separately. Keep this for tiny icons.
Privacy
Encoding and decoding run in your browser tab with the built-in TextEncoder and atob functions. Nothing is sent to FileTools Kit. Because Base64 is trivially reversible, treat any decoded token or credential as sensitive, and do not paste live secrets on a shared screen.
FAQ
How much bigger does Base64 make data?
About 33 percent, plus up to two padding characters. Some systems add a line break every 76 characters, which adds a little more.
Can I encode an image here?
No. The Base64 tab works with text. Encoding files needs a tool that reads raw bytes.
Is Base64 the same as hashing?
No. A hash such as SHA-256 is one-way and cannot be reversed. Base64 is fully reversible. See hash text with SHA-256.
Why does my output differ from another tool?
Usually because the other tool encoded a different character set, added a trailing newline, or used Base64URL.
Related guides: hash text with SHA-256, JSON formatting explained, watermark, password, and redaction are different.
Written by Souren Das, FileTools Kit, Bengaluru. Last updated 10 October 2026. Spotted a mistake or a step that does not match the tool? Email support@filetoolskit.com and I will fix it. See how tools and guides are tested.