Base64
How it works
Base64 processes input in groups of 3 bytes (24 bits). Each 24-bit group is split into four 6-bit chunks (sextets), and each sextet (value 0โ63) is an index into the 64-character encoding alphabet, yielding 4 output characters. When the input length is not a multiple of 3, the final incomplete group is padded with zero bits and the missing output positions are filled with the '=' padding character: 1 input byte yields 2 characters + '==', and 2 bytes yield 3 characters + '='. Decoding reverses the process. The base64url variant uses the same mechanism but with an alphabet where '+' and '/' are replaced by '-' and '_'.
Problem solved
Many protocols and formats (email, JSON, XML, URLs) were designed for text and do not safely carry raw binary bytes โ bytes outside the printable ASCII range can be corrupted, truncated, or interpreted as control characters. Base64 solves this by mapping arbitrary binary data onto a safe, printable subset of ASCII, so it can traverse a text channel and be reconstructed exactly.
Components
A table mapping values 0โ63 onto printable ASCII characters. In the standard variant: AโZ (0โ25), aโz (26โ51), 0โ9 (52โ61), '+' (62), '/' (63).
Official
Splits the input stream into 24-bit groups and further into four 6-bit sextets.
Mechanism for handling incomplete groups at the end of the input: 1 byte โ 2 characters + '==', 2 bytes โ 3 characters + '='. Ensures the output length is a multiple of 4.
Official
Implementation
Base64 is fully reversible without a key and provides no confidentiality. In AI contexts this cuts both ways: sensitive data encoded in Base64 stays exposed, and content filters that inspect only plaintext may miss malicious instructions encoded in Base64 (prompt-injection/jailbreak).
Using the standard alphabet ('+','/') where base64url ('-','_') is required breaks URLs, filenames, and JWT tokens.
Libraries differ in how they treat missing '=' and whitespace/line breaks, causing decode errors across systems.
Encoding grows size by about 1/3, which for large images/files in multimodal prompts increases token, bandwidth, and cost usage.
Evolution
One of the early standardized uses of Base64 encoding to carry binary data in email.
Base64 became one of MIME's Content-Transfer-Encodings, popularizing it as the way to encode email attachments.
The first specification collecting Base16/Base32/Base64 into a single document independent of MIME.
Obsoleted RFC 3548, reconciled implementation discrepancies, and formalized the URL-safe (base64url) variant.
JSON Web Token based the encoding of its header, payload, and signature on base64url, making the variant ubiquitous in web and API authentication.
Hyperparameters (configurable axes)
Standard ('+','/') vs URL-safe ('-','_').
Whether to append '=' padding characters. Some profiles (e.g. certain base64url uses) omit padding.
Optional splitting of output into lines (e.g. 76 characters in MIME) for email compatibility.
Computational complexity
Time complexity: O(n). Space complexity: O(n).
Parallelism
Each 24-bit group (3 bytes) is encoded independently of the others, so encoding/decoding is trivially parallelizable across blocks.
Hardware requirements
Base64 requires only simple bitwise operations and table lookups available on any CPU; it needs no accelerators.