What Is Base64 and When Should You Use It?
Updated October 2026
Base64 turns any data into plain letters and digits, so it can travel through systems that were built for text. You meet it in emails, web pages and APIs, usually without noticing.
What Base64 does
Computers store everything as bytes, and a byte can have 256 different values. Many of those values are not printable characters. Older systems, such as email, were designed for text and can damage or drop such bytes.
Base64 solves this by rewriting the data with only 64 safe characters: A to Z, a to z, 0 to 9, plus the signs + and /. Every three bytes of the original become four characters. One or two = signs at the end fill up the last group when the data does not divide evenly by three.
A small example: the text Hi! becomes SGkh. Decoding SGkh gives back exactly Hi!.
Why Base64 is larger than the original
Four characters are needed for every three bytes, so Base64 is about 33 percent larger than the data it represents. A 30 KB image becomes roughly 40 KB of text. That is the price for being able to send it as text.
Base64 is not encryption
This is the most important thing to remember. Base64 has no key and no secret. Anyone can decode it in a second, with a tool like the one on this site. It changes how data looks, not who can read it.
Never use Base64 to protect passwords, tokens or personal data. If something has to stay secret, it needs real encryption.
Where you run into it
- Email attachments. Files are sent through email as Base64 text and turned back into files by your mail program.
- Images inside HTML or CSS. A small icon can be written directly in the page as a data URI, which saves a separate download.
- APIs and JSON. JSON can only hold text, so a file or image inside a JSON message is usually Base64.
- Login headers and tokens. HTTP Basic authentication and the parts of a JWT token are Base64. They are readable by anyone who sees them.
The URL-safe variant
The characters + and / have a special meaning in web addresses. For use in a URL there is a variant called Base64URL that writes - instead of + and _ instead of /, and usually leaves off the = padding. It carries the same data and is what JWT tokens use.
When to use it, and when not
| Situation | Use Base64? |
|---|---|
| Small icon inside a stylesheet or email template | Yes |
| A file inside a JSON or XML message | Yes |
| Large photos on a web page | No, a normal image file loads faster |
| Hiding a password or other secret | No, it offers no protection |
| Making data smaller | No, it makes data larger |