What is Base64?
Base64 encoding explained with examples and common use cases.
Base64 is a way of converting binary data — images, files, anything that isn't plain text — into a string of safe, printable ASCII characters. It is not encryption and not compression: it is purely a transport encoding, designed so that binary data can survive systems that only handle text.
You have already seen Base64 many times. Every data URL in an HTML img tag, every email attachment you have ever inspected, and most API tokens that travel as strings are Base64-encoded underneath.
What is Base64 encoding?
Base64 is an encoding scheme that translates arbitrary binary data into text using a fixed alphabet of 64 characters: A-Z, a-z, 0-9, plus two extra characters (usually + and /). A trailing = character is used as padding so the output length is always a multiple of four.
The word "encoding" matters here. Encoding is a reversible transformation with a specific purpose — moving data between formats. Anyone can decode Base64 back to the original bytes in milliseconds; there is no key, no secret, and no security. If you see Base64, assume the contents are fully readable.
How does Base64 work?
Base64 works on groups of three bytes. Each byte is 8 bits, so three bytes give 24 bits, which splits cleanly into four groups of 6 bits. Each 6-bit group has 64 possible values (2 to the 6th power), and each value maps to one character in the alphabet. That is where the name comes from: 64 characters, 6 bits each.
For example, the three bytes that make up the word "Man" — hex values 4D, 61, 6E — become the binary 01001101 01100001 01101110. Split into 6-bit groups (010011, 010110, 000101, 101110) and mapped through the table, that yields T, W, F, u — so "Man" encodes to "TWFu". When the input length is not a multiple of three, padding with = keeps the output aligned.
Why does Base64 exist?
Base64 was created in the early days of email and network protocols, when many systems could only reliably transmit 7-bit ASCII text. Binary data — an image, a compiled executable, an encrypted payload — contains byte values above 127 and control characters that email servers, MIME handlers, and legacy protocols would silently corrupt, truncate, or reinterpret.
Encoding binary data as Base64 guarantees that every character is a safe, printable ASCII character that any text-only channel can carry unchanged. The same problem exists today in JSON payloads, URLs, and XML — which is why Base64 is still everywhere, half a century after it was designed.
Common use cases
The most visible use is email attachments: MIME wraps binary attachments in Base64 so they can ride along inside a plain-text email. Data URLs use the same trick to embed images directly in HTML and CSS, like data:image/png;base64,iVBORw0KGgo..., which saves a round trip to the server at the cost of larger files.
In APIs, Base64 appears in HTTP Basic Authorization headers, in JSON Web Tokens (which are Base64URL-encoded), and any time a binary blob — a certificate, a signature, an uploaded file — has to travel inside a JSON or XML document that only accepts text.
Base64 vs other encodings
Hexadecimal is the most common alternative: every byte becomes two characters (0-9, A-F), so it expands data by a clean 2x instead of Base64's roughly 1.33x. Hex is easier for humans to read byte-by-byte, which is why debuggers, hex editors, and cryptographic hashes display values in hex.
URL encoding (percent-encoding) solves a different problem — safely embedding text inside a URL — and percent-encodes only the characters that actually need it. Base64 has a URL-safe variant called Base64URL that swaps + and / for - and _ so the output works unescaped in query strings and filenames, and it is what JWTs use.