What does Base64 decoding do?
Base64 decoding is encoding in reverse. It takes a string made of letters, numbers, + and / and turns it back into the original bytes, which this tool then reads as UTF-8 text.
It's the quickest way to find out what a strange-looking string such as SGVsbG8= actually says. Decoding needs no key or password, because Base64 was never meant to hide anything.
How Base64 decoding works
Each Base64 character stands for a number from 0 to 63, which is six bits. Decoding joins four characters into 24 bits and cuts them into three bytes. Padding with = at the end tells the decoder that the last group holds fewer than three bytes.
Base64: SGVsbG8=
Text: HelloOnce the bytes are back, they are read as UTF-8, the standard on the web, so emoji and non-Latin text come out correctly. A UTF-8 file that starts with a byte order mark gives a Base64 string that begins with 77u/. The mark is kept as an invisible character at the start of the result, so the round trip stays exact.
This tool is forgiving about presentation and strict about correctness. It accepts missing padding, line breaks, spaces and both alphabets. It rejects padding that is wrong or extra, such as SGVsbG8==, a lone =, characters outside the alphabet and lengths that can't be valid.
Where you'll run into Base64 strings
- The Authorization header of HTTP Basic authentication.
- Data URIs inside HTML and CSS files.
- Email source, where attachments and some text parts are Base64 encoded.
- API responses and database fields that store binary or multi-line values as text.
- Config files, environment variables and Kubernetes secrets.
- The header and payload of a JSON Web Token.
A quick example
A Basic authentication header looks like Authorization: Basic dXNlcjpwYXNz. The part after Basic is Base64:
dXNlcjpwYXNzDecoded, it reads:
user:passReading the parts of a JSON Web Token
A signed JSON Web Token in its usual compact form has three parts separated by dots: a header, a payload and a signature. The header and payload are Base64URL-encoded JSON, so you can read them here by pasting one part at a time, without the dots. Encrypted tokens have five parts, and decoding them does not reveal what is inside.
Why decoding fails
When a string refuses to decode, one of these is usually the reason:
- Characters that don't belong. Base64 only uses letters, numbers, + and / (or - and _). A stray quote, dot or comma makes the string invalid.
- Wrong padding. The number of = signs has to match the length of the string. Remove the padding completely, or use the right number.
- A missing piece. A length that leaves one extra character, with no way to form a full group, means the string was cut off.
- Plus signs lost on the way. In URLs and form data a + is sometimes turned into a space. This tool ignores spaces, so it can't repair them. Put the plus signs back before decoding.
- Binary data. The Base64 can be perfectly valid and still not be text. An image or a file decodes to bytes that can't be read as UTF-8, and the tool says so.
- Another text encoding. Text that was saved as Windows-1252 or another non-UTF-8 encoding won't decode as UTF-8.
Decoding in your own code
function fromBase64(base64) {
const binary = atob(base64);
const bytes = Uint8Array.from(binary, (char) => char.charCodeAt(0));
return new TextDecoder().decode(bytes);
}
console.log(fromBase64("SGVsbG8sIFRvb2xQbGFuayEg8J+Riw==")); // Hello, ToolPlank! ๐// Node.js
const base64 = "SGVsbG8sIFRvb2xQbGFuayEg8J+Riw==";
const text = Buffer.from(base64, "base64").toString("utf8");
console.log(text); // Hello, ToolPlank! ๐import base64
base64_text = "SGVsbG8sIFRvb2xQbGFuayEg8J+Riw=="
text = base64.b64decode(base64_text).decode("utf-8")
print(text) # Hello, ToolPlank! ๐Is it safe to paste private text here?
Decoding runs in your browser, and what you paste is not sent to our servers. The Privacy Policy has the details.