Encoding & security

Base64 is not encryption: encoding, encryption and hashing explained

What Base64 actually does, why it does not protect secrets, how it differs from encryption and hashing, and how to encode and decode text and files.

Published:

The one-sentence answer

Base64 turns bytes into plain letters and digits so they can travel through systems that only handle text. Anyone can turn it back — there is no key and no secret involved.

Three different things

Base64 (encoding) Encryption (e.g. AES) Hashing (e.g. SHA-256)
Purpose Represent bytes as text Keep data secret Fingerprint / integrity check
Reversible? Yes, by anyone Yes, only with the key No
Needs a key? No Yes No
Typical use Email attachments, data URLs, JSON fields, tokens HTTPS, encrypted files, password managers Checking downloads, deduplication

So if you see cGFzc3dvcmQxMjM= in a config file, that is not a protected password. It decodes straight to password123.

Example: encoding and decoding text

  1. Open the Base64 encoder/decoder.
  2. In Mode, choose Encode, keep Input type on Text and type hello.
  3. Press Encode. The result is aGVsbG8=.
  4. Non-English text is encoded as UTF-8 first: こんにちは becomes 44GT44KT44Gr44Gh44Gv, and 안녕 becomes 7JWI64WV.
  5. To reverse it, switch Mode to Decode, paste the Base64 and press Decode. Use result as input moves the result back into the input box.

Base64 output is about one third larger than the original data (every 3 bytes become 4 characters).

Example: a file as a data URL

To embed a small icon directly in HTML or CSS:

  1. Choose Encode, set Input type to File and choose the image.
  2. Turn on Output as a data URL. The result starts with data:image/png;base64,….
  3. Paste it into <img src="…"> or background-image: url(…).

Keep this for small files. A 100 KB image becomes roughly 133 KB of text inside your page and cannot be cached separately.

URL-safe Base64

Standard Base64 uses + and /, which have special meanings in URLs. The URL-safe variant uses - and _ instead and usually drops the trailing =. JSON Web Tokens (JWT) use this form. Turn on URL-safe when encoding; when decoding, the tool accepts both forms automatically.

When you actually need something else

  • To keep data secret, use encryption with a proper key (for files, a tool such as an encrypted archive or a password manager) — not Base64.
  • To store passwords in your own application, use a dedicated password-hashing function such as Argon2, scrypt or bcrypt. A single fast hash like SHA-256 is not enough on its own.
  • To check that a download was not changed, compare its SHA-256 value with the publisher’s using the hash generator.
  • To create a new strong password, use the password generator.

Common problems

  • Decoded text looks like garbage. The data is probably not text (an image, a ZIP, compressed data). Use Save as file instead of reading it as text.
  • “Invalid character” errors. Check for stray characters from copy and paste, or a Base64 string that was cut off.
  • Warning about mixed characters. The input contains both + / and - _. Two different strings may have been joined together.
  • Credentials in a Basic auth header. Authorization: Basic dXNlcjpwYXNz is just Base64 of user:pass. It is only safe over HTTPS.

← All guides