Learn · Guide
Base64 Explained: Encoding, Not Encryption
What Base64 really does, why URLs need the safe variant, and why "encoded" never means "secret".
What Base64 actually is
Base64 maps binary bytes onto 64 printable ASCII characters (A–Z, a–z, 0–9, +, /) plus = padding, so that arbitrary binary can travel through systems that only handle text — email, JSON, URLs. It is a representation, exactly like writing the number ten as "10" instead of a tally.
Encoding is not encryption
This is the sentence to remember: Base64 can be reversed by anyone in seconds. Any online tool, any developer, any casual observer can decode it. Putting "encoded" in front of a secret does nothing for your security. If you need secrecy, use real encryption with a key; if you need tamper-evidence, use a signature or hash.
Standard vs URL-safe
Plain Base64 uses +, / and = — characters that have meaning inside URLs. URL-safe Base64 substitutes - for + and _ for /, and drops the trailing = padding. JWTs, for example, use Base64 URL encoding for their three segments. That's why a JWT never contains a literal +.
The UTF-8 gotcha
A classic bug: encode 中文 with a tool that assumes Latin-1, and you get a string that decodes back to mojibake. Correct tools convert the string to UTF-8 bytes first (TextEncoder) and decode from UTF-8 bytes (TextDecoder). ToolsKit's Base64 tool does this on both paths, so Chinese, emoji and accented text round-trip faithfully.
Where you'll meet it
- JWT header and payload segments.
data:URIs embedding small images and fonts in HTML and CSS.- Email attachments in their MIME form.
- Storing binary blobs in text-only columns or caches.
Try the round-trip
Paste 5Lit5paH into ToolsKit's Base64 decoder — it reads as 中文 in UTF-8. Then encode your own text, decode it, and confirm you got exactly what you started with. If a colleague ever says "we'll Base64 it so it's safe," you now have a better sentence ready.