Skip to content
CodeShift
Menu

What Is Base64 Encoding?

Base64 converts binary data to text using 64 printable characters. 'Man' encodes to 'TWFu'. It is used in email attachments, data URIs, and JWTs.

By The CodeShift DeskPublished September 10, 2026

Base64 encodes arbitrary binary data as a string of 64 printable ASCII characters. Three bytes of input become four Base64 characters — always printable, always safe in text systems like email. The word “Man” encodes to TWFu. The scheme is defined in RFC 4648, which governs Base16, Base32, and Base64.

The 64-Character Alphabet

Index Character Index Character Index Character Index Character
0 A 16 Q 32 g 48 w
1 B 17 R 33 h 49 x
2 C 18 S 34 i 50 y
3 D 19 T 35 j 51 z
4 E 20 U 36 k 52 0
5 F 21 V 37 l 53 1
6 G 22 W 38 m 54 2
7 H 23 X 39 n 55 3
8 I 24 Y 40 o 56 4
9 J 25 Z 41 p 57 5
10 K 26 a 42 q 58 6
11 L 27 b 43 r 59 7
12 M 28 c 44 s 60 8
13 N 29 d 45 t 61 9
14 O 30 e 46 u 62 +
15 P 31 f 47 v 63 /

Each Base64 character represents exactly 6 bits.

Step-by-Step: Encoding “Man”

The word “Man” in ASCII is three bytes: M = 77, a = 97, n = 110.

  1. Write out the binary for each byte:

    • M = 01001101
    • a = 01100001
    • n = 01101110
  2. Concatenate: 010011010110000101101110 (24 bits total).

  3. Split into four 6-bit groups: 010011 010110 000101 101110.

  4. Convert each group to decimal: 19, 22, 5, 46.

  5. Look up each index in the alphabet: T, W, F, u.

Result: TWFu

Use the Base64 encoder/decoder to verify any string instantly.

Padding with the = Character

Base64 works in 3-byte input blocks. When the input length is not a multiple of 3, padding fills the gap:

Input Bytes Output Padding
Man 3 TWFu None
Ma 2 TWE= One =
M 1 TQ== Two ==

The padding makes it clear where the data ends and ensures every Base64 string has a length that is a multiple of 4.

Where Base64 Is Used

Email attachments (MIME). Email was designed for ASCII text. SMTP cannot reliably transmit raw binary data. MIME uses Base64 to encode attachments — images, PDFs, spreadsheets — as ASCII for transport.

Data URIs. A browser can embed a small image directly in HTML or CSS as a Base64 string: data:image/png;base64,iVBORw0KGgo.... No separate file request is needed.

JSON Web Tokens (JWTs). The header and payload of a JWT are Base64url-encoded (a URL-safe variant that replaces + with - and / with _).

HTTP Basic Auth. Credentials sent in the Authorization header are Base64-encoded. This is not security — anyone can decode them. HTTPS handles the actual security.

What Base64 Is Not

Base64 is not encryption. The encoded string can be decoded by anyone in a fraction of a second. Do not use it to hide passwords or sensitive data. It is purely a way to represent binary data as text.

See What Is UTF-8? for how characters become bytes before Base64 encodes them, or ASCII vs. Unicode to understand the character standards that underpin this whole system.

Frequently asked questions

Why does Base64 make data larger?+

Base64 encodes 3 bytes of input as 4 ASCII characters. That is a 33% size increase. The trade-off is that the output contains only safe printable characters.

What is the equals sign (=) at the end of Base64 strings?+

Padding. Base64 works in groups of 3 bytes. If the input is not a multiple of 3, one or two = characters are added to complete the final group.

Is Base64 encryption?+

No. Base64 is an encoding, not encryption. Anyone can decode it in seconds with no key. Do not use it to protect sensitive data.

What is Base64url?+

A variant of Base64 that replaces + with - and / with _ so the output can be used safely in URLs and filenames. JWTs (JSON Web Tokens) use Base64url.

Where does the number 64 come from?+

The 64 characters used are a subset of ASCII that is safe in most text contexts: A–Z, a–z, 0–9, plus (+), and slash (/). 64 = 2 to the power of 6, meaning each Base64 digit carries 6 bits.

Keep reading