Blog
4 min read

Hashing vs Encryption vs Encoding: What's the Difference?

Three ways to transform data that people mix up constantly — sometimes with security consequences. Encoding changes format (Base64), encryption hides data with a key you can reverse, hashing makes a one-way fingerprint. What each is for and the mistakes to avoid.

Encoding, encryption and hashing all turn data into something that looks like gibberish. That's where the similarity ends. Mixing them up leads to real security mistakes — like "protecting" passwords with Base64.

The one-line version

  • Encoding changes the format so data can travel safely. Anyone can reverse it. No secret involved.
  • Encryption hides data so only someone with the key can read it. Reversible with the key.
  • Hashing creates a fixed-size fingerprint of data. Not reversible by design.

Encoding: a different format, not a secret

Encoding converts data into a form a system can handle. Examples:

  • Base64 — turns binary data (an image, a file) into letters and numbers so it can go inside JSON, email or a URL. hello → aGVsbG8=.
  • URL encoding — hello world → hello%20world.
  • UTF-8 — turns text characters into bytes.
btoa('hello')       // "aGVsbG8="
atob('aGVsbG8=')    // "hello"

Encoding is not security. Anyone can decode it instantly. A JWT's contents are Base64-encoded, not encrypted — anyone holding the token can read what's inside.

Encryption: reversible, with a key

Encryption scrambles data using a key. With the key, you get the original back. Without it, you get nothing useful.

  • Symmetric (e.g. AES): the same key encrypts and decrypts. Used for encrypting files, database fields, backups.
  • Asymmetric (e.g. RSA, elliptic-curve): a public key encrypts (or verifies) and a private key decrypts (or signs). Used in HTTPS, SSH and signatures. (SSH keys explained)

Use it when you need the data back later: stored API tokens for a third-party integration, sensitive documents, backups, everything travelling over the internet (HTTPS). (Encryption at rest vs in transit)

The hard part of encryption is key management: where the key lives, who can access it, how to rotate it. Encrypted data with the key sitting next to it isn't protected much. (Secrets management beyond .env files)

Hashing: a one-way fingerprint

A hash function turns any input into a fixed-length output:

SHA-256("hello")  → 2cf24dba5fb0a30e26e83b2ac5b9e29e1b161e5c1fa7425e73043362938b9824
SHA-256("hello!") → ce06092fb948d9ffac7d1a376e404b26b7575bcc11ee05a4615fef4fec3a308b

Properties:

  • Same input, same hash, every time.
  • Tiny change, completely different hash.
  • Can't be reversed to get the input back.

Uses:

  • Checking integrity — has this file changed? Download checksums, git commit IDs.
  • Lookups and deduplication — same content, same hash.
  • Verifying webhooks — HMAC (a hash with a secret key) proves a message came from the sender. (Handle webhooks reliably)
  • Storing passwords — with a special kind of hash.

Passwords: hash, with the right algorithm

You never need to read a user's password — only to check it. So you hash it, never encrypt it. When they log in, hash what they typed and compare.

But not with plain SHA-256: it's designed to be fast, and fast means attackers can try billions of guesses per second. Use a password hashing algorithm that's deliberately slow and adds a random salt: Argon2id, bcrypt or scrypt. (Password hashing explained)

The mistakes to avoid

Mistake Why it's wrong
"Encrypting" with Base64 Base64 is encoding; anyone can decode it
Encrypting passwords If the key leaks, every password leaks. Hash them.
Hashing passwords with MD5/SHA-1/SHA-256 Too fast; easily cracked
Putting secrets in a JWT payload It's only encoded; anyone can read it
Inventing your own encryption Use well-tested libraries; never roll your own
Hashing data you need back Hashes can't be reversed; use encryption

Which one do you need?

  • Need to send data through a system that only accepts text? → Encode.
  • Need to keep data secret but read it later? → Encrypt.
  • Need to verify something without storing it, or check it hasn't changed? → Hash.

The summary

  • Encoding = format change, no secret, anyone can reverse.
  • Encryption = secret with a key, reversible with the key.
  • Hashing = one-way fingerprint, irreversible.
  • Passwords: slow, salted hashes (Argon2id, bcrypt). Never encoding, never plain encryption.

EasySpawn serves every app over HTTPS and keeps backups encrypted, with secrets stored server-side rather than in your code. See how it works or join the waitlist.

Related: Password Hashing Explained · Encryption at Rest vs in Transit · What Is a JWT? · What Is JSON?

Keep reading