Security › Cryptography Basics
Base64
An encoding of bytes as text; not encryption.
Also known as: Base 64, base64 encoding
Base64 turns arbitrary bytes into text made of 64 safe characters (A-Z, a-z, 0-9, +, /, with = padding). It lets binary data travel through places built for text: JSON, email, URLs, HTTP headers.
import base64
base64.b64encode(b"hello") # b'aGVsbG8='
base64.b64decode(b"aGVsbG8=") # b'hello'
echo -n hello | base64 # aGVsbG8=
The classic mistake: treating it as security
Base64 is an encoding, not encryption. There is no key, and anyone can reverse it in one line. A password or token in Base64 is a password in plain sight. See hashing vs encryption. This is why Basic auth only makes sense over HTTPS, and why you can read the contents of a JWT by decoding it.
Facts that are useful to know
- It makes data bigger: about a third larger, since every 3 bytes become 4 characters.
- Base64URL is a variant that swaps
+and/for-and_(and often drops the padding), so the result is safe in URLs. JWTs use it. - Bytes in, bytes out. To encode a string, you first need bytes, which means picking a character encoding such as UTF-8.
Typical uses: embedding a small image in HTML or CSS as a data: URL, sending file contents in a JSON API, and transporting binary keys or signatures as text. For large files, upload them as binary instead; the size overhead adds up.