Glossary

Base64

A way of writing arbitrary bytes using 64 safe text characters.

Base64 encodes binary data as text, so bytes can travel through channels that only handle text, an email body, a JSON string, a URL, an HTML attribute. It takes three bytes at a time and writes them as four characters, which is why encoded data is about 33% larger than the original.

It is an encoding, not encryption. Anyone can decode it, instantly, with no key. Base64 in a token or a config file conceals nothing: it exists to make the bytes transportable, not secret. Treating it as protection is a recurring and serious mistake.

There are two alphabets. Standard base64 uses + and /, which both have meaning inside a URL. Base64url replaces them with - and _ and usually drops the = padding, which is what JWTs and URL parameters use. Decoding with the wrong alphabet fails or produces garbage, so the variant matters.