Guide · Updated 2026-10-08
Base64 Is Not Encryption: What Encoding, Hashing and Encrypting Really Mean
The difference between Base64 encoding, hashing and encryption, with tested examples of each and the mistakes that cause real security problems.
Base64, hashes and encryption are often mixed up, and mixing them up leads to real security mistakes. They solve three different problems. The Base64 Encode and Decode tool and the Hash Generator let you see the difference for yourself.
Encoding: changing the form, not hiding the content
Base64 turns any data into plain letters, numbers and a few symbols so it can travel through systems that only handle text. Anyone can reverse it, with no key. In the tool, the text “Café ☕” encodes to Q2Fmw6kg4piV, and decoding that string gives the same text back. Nothing was protected.
The practical effect is that Base64 makes data about one third larger. An 82.7 KB image became a data address of 112,895 characters in our test. Use it to embed small items or move data through text-only channels, never to hide passwords or secrets.
Hashing: a one-way fingerprint
A hash function turns input of any size into a fixed-length fingerprint. The same input always gives the same fingerprint, a tiny change gives a completely different one, and you cannot work backwards to the input. The SHA-256 hash of the text “hello world” is b94d27b9934d3e08a52e52d7da7dabfac484efe37a5380ee9088f7ace2efcde9, which matches the result of the standard sha256sum command.
- Good for: checking that a file or message was not changed, and building other security features.
- Not good for storing passwords by itself. Fast hashes such as SHA-256 can be guessed at billions of attempts a second. Password storage uses slow, salted functions such as bcrypt or Argon2.
- SHA-1 is no longer considered safe for security, though it still appears for compatibility.
Encryption: hiding content with a key
Encryption scrambles data so only someone with the right key can read it, and the original can be recovered. It protects secrets in storage and in transit. It needs proper tools and key management, and it is not something an online encoder or a hash tool provides.
A quick comparison
| Reversible? | Needs a key? | Purpose | |
|---|---|---|---|
| Base64 encoding | Yes, by anyone | No | Carry data as text |
| Hashing | No | No (salts and keys can be added) | Fingerprint and verify |
| Encryption | Yes, with the key | Yes | Keep content secret |
A common mistake: trusting a token because you can read it
A JSON Web Token is three Base64 parts separated by dots. Anyone can decode the first two with the JWT Decoder and read what the token claims, including when it expires. Decoding does not check the signature, so a readable token is not proof that it is genuine. Only the server that holds the secret key can verify it.
Frequently asked questions
Is Base64 secure? No. It is a way of writing data, not of protecting it.
Can a hash be reversed? Not directly, but common inputs such as short or well-known passwords can be guessed and compared, which is why passwords need slow salted hashing.
Do these tools upload my text? No. Base64 and hashing run in your browser.