Skip to content
Encoders & Decoders

Last updated:

Base64 Decode Online

Base64 decode in seconds. Paste a Base64 string and this free tool turns it back into readable text as you type, with support for URL-safe Base64, missing padding and Unicode. Everything runs in your browser, so nothing is uploaded.

Base64

0 characters ยท 0 lines

Decoded text

Loading tool
0 characters ยท 0 linesLive preview

Your text is processed in your browser and never uploaded.

More free tools you may need next.

How to use Base64 Decode

  1. 1

    Paste your Base64 string

    Paste it into the left box. Standard and URL-safe Base64 both work, and line breaks, missing = padding and a data URI prefix such as data:text/plain;base64, are cleaned up for you.

  2. 2

    Read the decoded text

    The text appears on the right as you type. If the input can't be decoded, a short message explains what is wrong, and your input stays in the box so you can fix it.

  3. 3

    Copy it or encode it again

    Press Copy to use the result, or press the swap button to turn it back into Base64 with Base64 Encode.

What does Base64 decoding do?

Base64 decoding is encoding in reverse. It takes a string made of letters, numbers, + and / and turns it back into the original bytes, which this tool then reads as UTF-8 text.

It's the quickest way to find out what a strange-looking string such as SGVsbG8= actually says. Decoding needs no key or password, because Base64 was never meant to hide anything.

How Base64 decoding works

Each Base64 character stands for a number from 0 to 63, which is six bits. Decoding joins four characters into 24 bits and cuts them into three bytes. Padding with = at the end tells the decoder that the last group holds fewer than three bytes.

Text
Base64:  SGVsbG8=
Text:    Hello

Once the bytes are back, they are read as UTF-8, the standard on the web, so emoji and non-Latin text come out correctly. A UTF-8 file that starts with a byte order mark gives a Base64 string that begins with 77u/. The mark is kept as an invisible character at the start of the result, so the round trip stays exact.

This tool is forgiving about presentation and strict about correctness. It accepts missing padding, line breaks, spaces and both alphabets. It rejects padding that is wrong or extra, such as SGVsbG8==, a lone =, characters outside the alphabet and lengths that can't be valid.

Where you'll run into Base64 strings

  • The Authorization header of HTTP Basic authentication.
  • Data URIs inside HTML and CSS files.
  • Email source, where attachments and some text parts are Base64 encoded.
  • API responses and database fields that store binary or multi-line values as text.
  • Config files, environment variables and Kubernetes secrets.
  • The header and payload of a JSON Web Token.

A quick example

A Basic authentication header looks like Authorization: Basic dXNlcjpwYXNz. The part after Basic is Base64:

Text
dXNlcjpwYXNz

Decoded, it reads:

Text
user:pass

Reading the parts of a JSON Web Token

A signed JSON Web Token in its usual compact form has three parts separated by dots: a header, a payload and a signature. The header and payload are Base64URL-encoded JSON, so you can read them here by pasting one part at a time, without the dots. Encrypted tokens have five parts, and decoding them does not reveal what is inside.

Why decoding fails

When a string refuses to decode, one of these is usually the reason:

  • Characters that don't belong. Base64 only uses letters, numbers, + and / (or - and _). A stray quote, dot or comma makes the string invalid.
  • Wrong padding. The number of = signs has to match the length of the string. Remove the padding completely, or use the right number.
  • A missing piece. A length that leaves one extra character, with no way to form a full group, means the string was cut off.
  • Plus signs lost on the way. In URLs and form data a + is sometimes turned into a space. This tool ignores spaces, so it can't repair them. Put the plus signs back before decoding.
  • Binary data. The Base64 can be perfectly valid and still not be text. An image or a file decodes to bytes that can't be read as UTF-8, and the tool says so.
  • Another text encoding. Text that was saved as Windows-1252 or another non-UTF-8 encoding won't decode as UTF-8.

Decoding in your own code

JavaScript
function fromBase64(base64) {
  const binary = atob(base64);
  const bytes = Uint8Array.from(binary, (char) => char.charCodeAt(0));
  return new TextDecoder().decode(bytes);
}

console.log(fromBase64("SGVsbG8sIFRvb2xQbGFuayEg8J+Riw==")); // Hello, ToolPlank! ๐Ÿ‘‹
JavaScript
// Node.js
const base64 = "SGVsbG8sIFRvb2xQbGFuayEg8J+Riw==";
const text = Buffer.from(base64, "base64").toString("utf8");

console.log(text); // Hello, ToolPlank! ๐Ÿ‘‹
Python
import base64

base64_text = "SGVsbG8sIFRvb2xQbGFuayEg8J+Riw=="
text = base64.b64decode(base64_text).decode("utf-8")

print(text)  # Hello, ToolPlank! ๐Ÿ‘‹

Is it safe to paste private text here?

Decoding runs in your browser, and what you paste is not sent to our servers. The Privacy Policy has the details.

Frequently asked questions

Paste it into the left box. The decoded text appears on the right straight away, and Copy puts it on your clipboard.

Just paste it. Missing = signs are added automatically before decoding. Only padding that is present but wrong, such as one = too many, is rejected.

Yes. A string that uses - and _ instead of + and / is converted automatically, so Base64URL values from tokens and URLs decode too.

This tool does it for you. It decodes the Base64 to bytes and reads them as UTF-8, so emoji, Urdu and other non-English text come out correctly. In your own code, decode the bytes with a UTF-8 decoder such as TextDecoder in JavaScript.

The string contains a character that Base64 doesn't use, such as a quote, a dot or a comma. Remove it, or check that you copied only the Base64 part.

The number of = signs doesn't match what the length of the string needs. For example, SGVsbG8== has one = too many. Remove the padding completely, or use the right number of signs.

The Base64 itself is fine, but the bytes inside don't form UTF-8 text. That usually means the data is binary, such as an image, an archive or an encrypted value.

The original text began with a byte order mark (U+FEFF), which some editors add to UTF-8 files. A Base64 string that starts with 77u/ usually has one. The tool keeps it so decoding returns exactly what was encoded.

No. This tool decodes text only. Base64 that holds an image or another binary file decodes to bytes that aren't readable text, so a converter made for files is the right tool.

No. Decoding happens in your browser and nothing is uploaded.