What Is Base64 Encoding and How Do You Encode or Decode It?
Base64 is an encoding scheme that represents binary data as ASCII text, so it can travel safely through systems that only handle text — email, JSON, URLs, HTML, config files. It is not encryption and provides no security. You encode when you need to embed or transmit binary content as text, and decode when you receive Base64 text and need the original bytes back. For quick one-off work, a browser tool like CyberChef handles both directions without installing anything.
What Base64 actually does
Base64 takes every 3 bytes (24 bits) of input and splits them into 4 groups of 6 bits. Each 6-bit value maps to one of 64 characters: A–Z, a–z, 0–9, +, and /. That is why the output is roughly 33% larger than the input — 3 bytes become 4 characters.
The alphabet is deliberately limited to characters that survive text protocols unchanged. The = character is used only as padding at the end, to fill out the final group when the input length is not a multiple of 3.
Because the mapping is fixed and reversible, anyone can decode Base64. Treat it as a transport format, not a protection mechanism.
A worked example
Take the three ASCII bytes Man:
| Step | Value |
|---|---|
| Bytes | M a n |
| ASCII (decimal) | 77, 97, 110 |
| Binary (24 bits) | 010011 010110 000101 101110 |
| 6-bit values | 19, 22, 5, 46 |
| Base64 chars | T, W, F, u |
| Result | TWFu |
Decoding TWFu reverses the process exactly. If the input is Ma (2 bytes), the encoder pads the output to TWE=; a single byte M becomes TQ==. The = signs carry no data — they only signal how many bytes were in the final group.
Where Base64 shows up
- Data URLs in HTML/CSS —
data:image/png;base64,iVBORw0KGgo...embeds an image directly in a page or stylesheet, avoiding a separate HTTP request. - Email attachments (MIME) — binary files are Base64-encoded so they can pass through SMTP, which was designed for 7-bit text.
- JSON and XML APIs — these formats cannot hold raw bytes, so binary fields (keys, certificates, small files) are Base64-encoded.
- HTTP Basic auth —
username:passwordis Base64-encoded in theAuthorizationheader. This is encoding, not hashing; the credentials are trivially readable. - JWT and similar tokens — the header and payload segments are Base64URL-encoded JSON.
Encoding and decoding with CyberChef
CyberChef is a browser-based tool for encoding, decoding, compression, and data analysis. It runs entirely in the page, so pasted data is not sent to a server.
- Open
cyberchef.org. - In the Operations list on the left, find To Base64 (for encoding) or From Base64 (for decoding).
- Drag the operation into the Recipe column.
- Paste your input into the Input pane.
- Read the result in the Output pane.
For decoding, the operation auto-detects the alphabet by default. If your data uses the URL-safe variant, set the alphabet explicitly to A-Za-z0-9-_ so - and _ are handled correctly.
Common pitfalls
Padding errors. A decoder expects the input length to be a multiple of 4. If = padding was stripped somewhere along the way, many decoders will reject the string. Re-add = until the length is a multiple of 4, or use a decoder that tolerates missing padding.
Line breaks and whitespace. MIME-encoded email wraps Base64 at 76 characters. Some decoders treat those newlines as invalid characters. Strip whitespace before decoding, or use a decoder that ignores it.
Standard vs. URL-safe alphabet. Standard Base64 uses + and /, which have meaning in URLs and filenames. The URL-safe variant substitutes - and _. Decoding a URL-safe string with a standard decoder (or vice versa) produces garbage or an error. Check which variant your source uses.
Confusing encoding with encryption. Base64 is fully reversible by anyone. Never use it to "hide" passwords, API keys, or personal data. If confidentiality is the goal, use actual encryption.
Double encoding. Applying Base64 twice is occasionally intentional (for nested transports) but is more often a bug. If decoded output still looks like Base64, check whether it was encoded more than once.
Character set assumptions. Base64 encodes bytes, not characters. A string must be converted to bytes using a defined character encoding (usually UTF-8) before encoding. Decoding gives you bytes back — interpreting them as text requires the same character encoding.
Choosing how to do it
| Situation | Practical choice |
|---|---|
| One-off encode/decode, no install | Browser tool such as CyberChef |
| Repeated work in a script | Language standard library (base64 in Python, Buffer.from(x, 'base64') in Node, base64 command on Linux/macOS) |
| Data inside a URL or filename | URL-safe alphabet |
| Data inside email | Standard alphabet with line wrapping |
| Data that must stay secret | Not Base64 — use encryption |
The rule of thumb: pick the tool that matches how often you do the task, and always confirm which alphabet and padding convention your data uses before decoding.