Base64 example: encoding is not encryption

A short string, its standard Base64 form, and the security mistake this encoding does not prevent.

Open Base64 Encode / Decode to run this case yourself.

Plain text

CompareStack

Standard Base64

Q29tcGFyZVN0YWNr

What Base64 is

Base64 is a way to write binary data with a 64-character alphabet so it survives systems that expect text: older mail gateways, JSON fields, and some HTTP headers. The string CompareStack encodes to Q29tcGFyZVN0YWNr. Padding with = appears when the input length is not divisible by three; this 12-byte input needs none.

CompareStack uses standard Base64: the alphabet includes + and /, with = padding. Decode strips whitespace first. If the decoded bytes are not valid UTF-8, the tool shows hexadecimal instead of mis-decoded text. URL-safe Base64, the JWT style that uses - and _, is not translated automatically. Swap those characters and restore padding before decoding it here.

What Base64 is not

Base64 is encoding, not encryption. There is no key. Anyone who can read Q29tcGFyZVN0YWNr can recover CompareStack with a public algorithm. It does not protect passwords, API tokens, or personal data. Putting a secret in Base64 and calling it “encoded for security” only hides it from a casual glance.

It is also not compression. Encoded text is larger than the original bytes. And it is not a signature: nothing in the alphabet proves who produced the string.

When this tool may not be the right choice

  • Password storage or any secrecy requirement. Use a password hash or real encryption, with a key you control.
  • URL-safe or JWT Base64 until you have converted the alphabet and padding.
  • Checking that a token is authentic. Decoding shows the bytes. It does not verify a signature.

Processing and privacy

Paste tools also run on the server. The text is sent in the form POST, with a limit of 100,000 characters per field. It is not written into a document library or a user account. Server logs can still record technical request metadata such as IP address and URL. Do not paste secrets, credentials, or personal data you are not allowed to send to a web service.

The Privacy Policy and how processing works are the full description.

Open Base64 Encode / Decode

Related examples

Related guides