Explanation
How Base64 Encoder works
Base64 is an encoding scheme (defined in RFC 4648) that converts byte sequences into a sequence of 64 printable ASCII characters (A-Z, a-z, 0-9, +, /). It encodes 3 bytes (24 bits) into 4 characters (6 bits each) and uses = as padding at the end.
Typical applications are email attachments (MIME, RFC 2045), data URLs for images (data:image/png;base64,...), JWT tokens, PEM certificates, HTTP Basic Authentication, JSON APIs and configuration files. This tool processes only UTF-8 text, not files or arbitrary binary data. The output needs four characters per started group of three input bytes; padding affects short inputs.
Important: Base64 is not encryption. The encoding can be reversed by anyone without a key. Base64-encoded data is just as readable as the original text — merely represented in a different format.
Common mistakes
- Confusing Base64 with encryption: Base64 provides no security whatsoever. Anyone can decode the encoded text without a key. For privacy use real encryption (AES, ChaCha20).
- Forgetting URL-unsafe characters: Standard Base64 contains + and /, which have special meaning in URLs. For URL contexts use Base64URL (with - and _) or URL encoding.
- Confusing text characters with bytes: Unicode characters can occupy multiple UTF-8 bytes; the output length therefore cannot be derived from the JavaScript character count.
- “Hiding” sensitive data in Base64: Encoding passwords, API keys or personal data in Base64 offers no protection. In logs, URLs or configurations they are trivially readable.
Limits of this tool
- No privacy — Base64 is readable, not encrypted.
- Four output characters per started group of three input bytes; padding affects short inputs.
- Text input/output only — no file encoding (images, PDFs etc.).
- No Base64URL mode (RFC 4648 §5) — only standard Base64 with + and /.
- Decoding binary data (non-UTF-8) fails, since only text output is supported.
Sources
- RFC 4648: The Base16, Base32, and Base64 Data Encodings. IETF, 2006. Defines standard Base64 and Base64URL.
- RFC 2045: MIME Part One — Format of Internet Message Bodies. Defines Base64 for email attachments (Content-Transfer-Encoding).
- WHATWG HTML Standard: Definition of btoa() and atob() for Base64 conversions in the browser.
- WHATWG Encoding Standard: Definition of TextEncoder, UTF-8 and fatal TextDecoder decoding.