Base64 encodes arbitrary binary data as a string of 64 printable ASCII characters. Three bytes of input become four Base64 characters — always printable, always safe in text systems like email. The word “Man” encodes to TWFu. The scheme is defined in RFC 4648, which governs Base16, Base32, and Base64.
The 64-Character Alphabet
| Index | Character | Index | Character | Index | Character | Index | Character |
|---|---|---|---|---|---|---|---|
| 0 | A | 16 | Q | 32 | g | 48 | w |
| 1 | B | 17 | R | 33 | h | 49 | x |
| 2 | C | 18 | S | 34 | i | 50 | y |
| 3 | D | 19 | T | 35 | j | 51 | z |
| 4 | E | 20 | U | 36 | k | 52 | 0 |
| 5 | F | 21 | V | 37 | l | 53 | 1 |
| 6 | G | 22 | W | 38 | m | 54 | 2 |
| 7 | H | 23 | X | 39 | n | 55 | 3 |
| 8 | I | 24 | Y | 40 | o | 56 | 4 |
| 9 | J | 25 | Z | 41 | p | 57 | 5 |
| 10 | K | 26 | a | 42 | q | 58 | 6 |
| 11 | L | 27 | b | 43 | r | 59 | 7 |
| 12 | M | 28 | c | 44 | s | 60 | 8 |
| 13 | N | 29 | d | 45 | t | 61 | 9 |
| 14 | O | 30 | e | 46 | u | 62 | + |
| 15 | P | 31 | f | 47 | v | 63 | / |
Each Base64 character represents exactly 6 bits.
Step-by-Step: Encoding “Man”
The word “Man” in ASCII is three bytes: M = 77, a = 97, n = 110.
-
Write out the binary for each byte:
- M =
01001101 - a =
01100001 - n =
01101110
- M =
-
Concatenate:
010011010110000101101110(24 bits total). -
Split into four 6-bit groups:
010011010110000101101110. -
Convert each group to decimal: 19, 22, 5, 46.
-
Look up each index in the alphabet: T, W, F, u.
Result: TWFu
Use the Base64 encoder/decoder to verify any string instantly.
Padding with the = Character
Base64 works in 3-byte input blocks. When the input length is not a multiple of 3, padding fills the gap:
| Input | Bytes | Output | Padding |
|---|---|---|---|
| Man | 3 | TWFu | None |
| Ma | 2 | TWE= | One = |
| M | 1 | TQ== | Two == |
The padding makes it clear where the data ends and ensures every Base64 string has a length that is a multiple of 4.
Where Base64 Is Used
Email attachments (MIME). Email was designed for ASCII text. SMTP cannot reliably transmit raw binary data. MIME uses Base64 to encode attachments — images, PDFs, spreadsheets — as ASCII for transport.
Data URIs. A browser can embed a small image directly in HTML or CSS as a Base64 string: data:image/png;base64,iVBORw0KGgo.... No separate file request is needed.
JSON Web Tokens (JWTs). The header and payload of a JWT are Base64url-encoded (a URL-safe variant that replaces + with - and / with _).
HTTP Basic Auth. Credentials sent in the Authorization header are Base64-encoded. This is not security — anyone can decode them. HTTPS handles the actual security.
What Base64 Is Not
Base64 is not encryption. The encoded string can be decoded by anyone in a fraction of a second. Do not use it to hide passwords or sensitive data. It is purely a way to represent binary data as text.
See What Is UTF-8? for how characters become bytes before Base64 encodes them, or ASCII vs. Unicode to understand the character standards that underpin this whole system.