Base58 encode and decode
Turn text or bytes into Base58, the alphabet of Bitcoin addresses, or decode it back, with the division by 58 written out. Paste an address to check its Base58Check checksum and see its parts.
Any text, including accents and emoji. It is turned into UTF-8 bytes first, and the bytes are encoded.
Step by step
- The bytes: 48 65 6C 6C 6F 20 57 6F 72 6C 64 21.
- Read as one number: 22,405,534,230,753,928,650,781,647,905.
- Divide by 58 until nothing is left, keeping each remainder:
| Number | ÷ 58 | Remainder | Character |
|---|---|---|---|
| 22,405,534,230,753,928,650,781,647,9052240…7905 | 386,302,314,323,343,597,427,269,7913863…9791 | 27 | U |
| 386,302,314,323,343,597,427,269,7913863…9791 | 6,660,384,729,712,820,645,297,7556660…7755 | 1 | 2 |
| 6,660,384,729,712,820,645,297,7556660…7755 | 114,834,219,477,807,252,505,1331148…5133 | 41 | i |
| 114,834,219,477,807,252,505,1331148…5133 | 1,979,900,335,824,262,974,2261979…4226 | 25 | S |
| 1,979,900,335,824,262,974,2261979…4226 | 34,136,212,686,625,223,6933413…3693 | 32 | Z |
| 34,136,212,686,625,223,6933413…3693 | 588,555,391,148,710,7535885…0753 | 19 | L |
| 588,555,391,148,710,7535885…0753 | 10,147,506,743,943,2881014…3288 | 49 | r |
| 10,147,506,743,943,2881014…3288 | 174,957,012,826,6081749…6608 | 24 | R |
| 174,957,012,826,6081749…6608 | 3,016,500,221,1483016…1148 | 24 | R |
| 3,016,500,221,1483016…1148 | 52,008,624,5025200…4502 | 32 | Z |
| 52,008,624,5025200…4502 | 896,700,422 | 26 | T |
| 896,700,422 | 15,460,352 | 6 | 7 |
| 15,460,352 | 266,557 | 46 | o |
| 266,557 | 4,595 | 47 | p |
| 4,595 | 79 | 13 | E |
| 79 | 1 | 21 | N |
| 1 | 0 | 1 | 2 |
Read the characters from the bottom up: 2NEpo7TZRRrLZSi2U.
Why Base58 exists
Base58 was written for Bitcoin, to show addresses and keys to people. It is Base64's 64 characters minus six: the look-alikes 0 (zero), O (capital o), I (capital i) and l (small L), and the symbols + and /. What is left is letters and digits only, so a string can be read off a screen without confusing two characters, a double click selects the whole of it, and an email program finds no punctuation to break a line at. Besides Bitcoin, IPFS uses it for its original content identifiers, the ones starting with Qm.
The order is digits, capitals, then small letters, as in ASCII, minus the four look-alikes. So 1 is 0, 9 is 8, A is 9 and z is 57.
How Base58 works: one big number, divided by 58
Base64 and Base32 regroup bits, because 64 and 32 are powers of two. 58 is not, so a Base58 character does not stand for any fixed group of bits. Instead the bytes are read as one large number and written in base 58, by the same repeated division that turns decimal into hex. Here is "Hi":
Encoding "Hi"
The bytes 48 69 are the number 0x4869 = 18537.
18537 ÷ 58 = 319 remainder 35 → c
319 ÷ 58 = 5 remainder 29 → W
5 ÷ 58 = 0 remainder 5 → 6
The remainders from the bottom up give 6Wc.
Leading zero bytes
The bytes 00 00 48 69 are the same number, 18537: zeros in front of a number change nothing. To keep them, each leading zero byte is written as 1, the character for 0.
So they encode as 116Wc. Only zero bytes at the very start are treated this way; zeros anywhere else are part of the number.
Because every character depends on the whole number, changing one byte can change characters all through the result. "Hello World!" and "Jello World!" differ only in their first byte:
| Text | Base58 | Base64 |
|---|---|---|
| Hello World! | 2NEpo7TZRRrLZSi2U | SGVsbG8gV29ybGQh |
| Jello World! | 2QRnfATR5gKu9g6s2 | SmVsbG8gV29ybGQh |
15 of the 17 Base58 characters differ (underlined), against 1 of the Base64 ones. Dividing a long number again and again also takes time that grows with the square of its length, which is why Base58 is used for short things like addresses and keys, not for files.
Base58Check: the checksum in Bitcoin addresses
A mistyped address must not quietly send money to the wrong place, so Bitcoin adds a checksum before encoding. The bytes are a version byte, the payload, and the first 4 bytes of SHA-256 applied twice to those two. This is the address 1BvBMSEYstWetqTFn5Au4m4GFg7xJaNVN2 taken apart:
SHA-256 of SHA-256 of the version and payload is F415766B5F558AAD59E37332E5C3143402C089A886F1585EE25EC20383F12CD5. Its first 4 bytes, F4 15 76 6B, are the checksum. Change any one character of the address and the number changes, so the checksum no longer matches; a random mistake gets through only about once in 232 (4.3 billion) tries. Try a one-character mistake.
Version bytes and the first character
The version byte is the most significant part of the number, so it decides which character or two the result can start with (a version byte of 0 is the exception: it is a leading zero byte, so it becomes a 1). These are the common Bitcoin prefixes, with the first characters worked out by encoding the smallest and largest value of each kind:
| Version | What it is | Payload | Starts with | Longest |
|---|---|---|---|---|
| 00 | Bitcoin address (P2PKH, pay to public key hash) | 20 bytes | 1 | 34 |
| 05 | Bitcoin script address (P2SH) | 20 bytes | 3 | 34 |
| 6F | Bitcoin testnet address (P2PKH) | 20 bytes | m or n | 34 |
| C4 | Bitcoin testnet script address (P2SH) | 20 bytes | 2 | 35 |
| 80 | Bitcoin private key, WIF | 32 bytes | 5 | 51 |
| 80 | Bitcoin private key, WIF, compressed public key | 33 bytes | K or L | 52 |
| EF | Bitcoin testnet private key, WIF | 32 bytes | 9 | 51 |
| EF | Bitcoin testnet private key, WIF, compressed public key | 33 bytes | c | 52 |
How long Base58 is
Each character carries log2 58 ≈ 5.86 bits, so n bytes need up to about 1.37 × n characters, a little more than Base64's 1.33 × n. The exact length depends on the number, so the table gives the most, for bytes that are all FF.
| Bytes | Base58, at most | Base64 with padding |
|---|---|---|
| 1 | 2 | 4 |
| 4 | 6 | 8 |
| 8 | 11 | 12 |
| 16 | 22 | 24 |
| 20 | 28 | 28 |
| 25 | 35 | 36 |
| 32 | 44 | 44 |
| 37 | 51 | 52 |
| 64 | 88 | 88 |
Common mistakes
- Encoding in pieces, as if it were Base64. Base64 can be cut into groups of 3 bytes and the pieces joined; Base58 cannot, because it is one number. "Hello " and "World!" are d3yC1LKq and kYLPNvXS, but "Hello World!" is 2NEpo7TZRRrLZSi2U. The same reason means one changed byte can change the whole string.
- Dropping the leading zero bytes. The bytes 00 00 48 69 and 48 69 are the same number. Only the leading 1s, 116Wc against 6Wc, tell them apart, so an encoder or decoder that skips them changes the data, and a Bitcoin address loses its version byte.
- Typing 0, O, I or l. They are not in the alphabet, so a string that seems to contain one has been misread. Change the last character of 2NEpo7TZRRrLZSi2U to a capital O and this decoder says: "O" (character 17) is not in the Base58 alphabet. Base58 leaves out 0, O, I and l because they are easy to mistake for each other; did you mean o?
- Confusing Base58 with Base58Check. Plain Base58 has no checksum: a mistyped character still decodes, to different bytes. Only Base58Check, as used for addresses, catches it. Decoding an address with plain Base58 also gives 25 bytes, not the 20-byte payload: the version byte comes first and the 4 checksum bytes last.
Questions
Why does Base58 leave out 0, O, I and l?
Because in many fonts 0 and O look the same, and so do I and l. Leaving them out means a Base58 string can be copied by eye without a mix-up. Base58 also drops the + and / of Base64, so a string is all letters and digits: a double click selects the whole of it, and nothing in it is mistaken for punctuation.
Why do Bitcoin addresses start with 1?
A legacy Bitcoin address starts with the version byte 0. Base58 treats the bytes as one number, and a number has no leading zeros, so each zero byte at the start is written as a 1, the character for zero, to keep it. Script addresses use version byte 5 and so start with 3.
What is Base58Check?
Base58 with a checksum: a version byte, then the payload, then the first 4 bytes of SHA-256 applied twice to the version and payload. A wallet recomputes the checksum before sending money, so a mistyped address is refused instead of paying a stranger. This page checks pasted addresses the same way.
Is Base58 the same as Base64 with some characters removed?
No. 58 is not a power of two, so a character does not stand for a fixed group of bits. The whole input is one number, divided by 58 again and again. That is why changing one byte can change characters all through the result: "Hello World!" and "Jello World!" differ in 15 of their 17 Base58 characters, but in only 1 of their Base64 characters.
How long is a Bitcoin address in Base58?
A legacy address is 25 bytes: a version byte, a 20-byte hash and a 4-byte checksum. Any 25 bytes are at most 35 Base58 characters, but an address's version byte is 0, which becomes a single 1, so it is at most 34. Some are shorter, because the length depends on the size of the number, not only on the byte count.
Why do some Bitcoin addresses start with bc1?
Those are SegWit addresses, written in Bech32 (BIP 173), or in Bech32m (BIP 350) for Taproot addresses starting bc1p: a different encoding with its own error-detecting checksum. They are not Base58Check, so this checker does not read them.
For encodings that regroup bits instead, see Base64 and Base32; for numbers in any base from 2 to 36, the base 36 converter.