Base64 turns binary or text data into a string of printable ASCII characters so it can travel through systems that only handle text. This guide explains how it works and when to use each variant.
What Base64 does
Base64 re-encodes bytes as printable ASCII text by grouping them and mapping each group to a character from a 64-character alphabet (A-Z, a-z, 0-9, + and /). The result can be safely embedded in JSON, URLs, email and configuration files.
Encoding is not encryption
Base64 provides no confidentiality whatsoever — anyone can reverse it instantly with no key. It is only a representation, not a security measure. If you need to protect data, use real encryption, and never rely on Base64 to hide a secret.
Standard vs. URL-safe Base64
Standard Base64 uses + and / and pads with =, characters that are meaningful or invalid in URLs. The URL-safe variant swaps them for - and _ and often omits padding, so the output can go directly into a URL or filename without further escaping.
Size and padding
Base64 grows the data by about 33%, because every 3 input bytes become 4 output characters. Padding with = ensures the output length is a multiple of 4, which is why decoders reject truncated or unpadded input by default.