Encoding, Encryption and Hashing: What Is the Difference?
Base64, URL encoding, encryption and hashes are often confused. This guide explains what each one is for and when to use it.
Encoding: changing the format
Encoding converts data into another representation so that it can travel safely, for example Base64 for binary data in text, or URL encoding so that spaces and symbols are safe in a link. Anyone can reverse it, so it provides no secrecy.
Encryption: hiding the data
Encryption scrambles data using a key so that only someone with the right key can read it. It is designed to be reversible by the right person and not by anyone else.
Hashing: a one-way fingerprint
A hash function turns any input into a fixed-length value. The same input always gives the same hash, but you cannot get the original back from it. Hashes are used to check that data has not changed. Even a tiny change produces a completely different hash.
Which one to use
Use encoding to make data fit a format, encryption to keep data secret, and hashing to verify integrity or to store passwords. For passwords, use a dedicated slow algorithm such as bcrypt or Argon2 rather than a plain hash.
A common mistake
Base64 is often mistaken for encryption. A Base64 string such as a token or password can be decoded by anyone in seconds, so never rely on it to protect secrets.
This guide is general information. Rules differ between institutions, so confirm requirements with your college or the portal you are using.