How Base64 works
Base64 takes 3 bytes at a time and writes them as 4 text characters.
That makes the output about 33% larger than the input. The = signs at the end are padding when the input length is not a multiple of 3.
Where you will see Base64
- Email attachments (MIME) and inline images.
data:URIs in HTML and CSS.- JSON Web Tokens - decode them with the JWT Decoder.
- HTTP Basic authentication headers - which is why they need HTTPS.
- Obfuscated scripts in malware and phishing emails.
Need a fingerprint instead of an encoding? Use the Hash Generator.
Frequently asked questions
What is Base64?
Base64 turns any data into plain text using 64 safe characters (A-Z, a-z, 0-9, + and /). It is used to put binary data into emails, JSON, URLs and data URIs.
Is Base64 encryption?
No. Anyone can decode Base64 instantly, as this tool shows. Never use it to hide passwords or secrets - attackers check for Base64 first.
What is Base64URL?
A variant that replaces + and / with - and _ and usually drops the = padding, so the result is safe inside URLs and file names. JWTs use Base64URL.
Why does decoded text look like gibberish?
The original data was probably binary (an image, a zip or encrypted data), not text. Use "Decode to file" to download it instead.
Why do attackers use Base64?
Malware and phishing emails often hide scripts, commands and links in Base64 to slip past simple filters. Decoding suspicious strings here is a quick way to see what they contain - safely, without running anything.