Skip to the tool

Base64 decode

Paste Base64, read the text. UTF-8 safe, data URIs unwrapped, padding repaired and both alphabets accepted, with encode one click away.

Guide

How to use it

  1. Paste the Base64. Whitespace, line wraps and a data:…;base64, prefix are handled for you.
  2. The decoded text appears as you paste. Binary content is flagged rather than printed as junk.
  3. Hit Switch to encode to go the other way, UTF-8 safe for accents and emoji.
  4. Tick URL-safe when working with JWT segments or URL parameters.

Examples

Worked examples

The classic

SGVsbG8sIHdvcmxkIQ== decodes to Hello, world! Paste it and watch the padding get handled.

A Kubernetes secret

Values in a secrets manifest are Base64, not encrypted. Decoding one here (locally, which is the only acceptable place) shows the plain connection string inside.

A Basic auth header

Authorization: Basic dXNlcjpwYXNz decodes to user:pass, a neat demonstration of why Basic auth needs HTTPS.

Method

How it works

Base64 maps every three bytes to four characters from a 64-character alphabet. Decoding reverses that: the input is cleaned (whitespace stripped, URL-safe characters normalised, padding restored), converted back to bytes and interpreted as UTF-8 text. Content that is not text, images, archives, certificates, is detected by its control bytes and flagged.

All of it runs on your device. Base64 blobs routinely contain credentials, so pasting them into a server-side decoder is exactly the mistake this tool exists to avoid.

FAQ

Frequently asked questions

What is Base64?

A way of writing any bytes using 64 safe characters (A-Z, a-z, 0-9, + and /), so binary data can travel through systems built for text: email attachments, JSON fields, URLs and config files.

Is Base64 encryption?

No, and this matters: it is a reversible encoding with no key. Anyone can decode it, as this page proves. Base64-encoding a password or API key hides nothing.

Why does my Base64 fail to decode?

Usually missing characters at either end from a partial copy, stray text mixed in, or a URL-safe variant with - and _ where + and / are expected. This decoder accepts both alphabets and fixes missing padding automatically.

What are the = signs at the end?

Padding. Base64 works in groups of three bytes; when the input does not divide evenly, one or two = characters fill the last group. Some systems drop them, so this decoder restores padding for you.

Why is my decoded output gibberish?

The Base64 probably wraps binary data, an image, a zip, a certificate, rather than text. The decoder flags this instead of printing junk; the image page handles files properly.

Is what I paste kept anywhere?

No. Decoding runs in your browser with nothing transmitted or stored, which matters because Base64 blobs often contain tokens and credentials.

More tools

Related tools

Base64 encodeThe other direction, with the not-encryption warning. Image to Base64Data URIs with ready-to-paste CSS and HTML snippets. JWT decoderBase64url segments decoded and explained in one go. Hash generatorOne-way digests, the thing Base64 is not.
Skip to the tool

Base64 decode

Paste Base64, read the text. UTF-8 safe, data URIs unwrapped, padding repaired and both alphabets accepted, with encode one click away.

Paste Base64 and the decoded text appears instantly. Data URIs are unwrapped automatically.

Everything runs in your browser. Base64 is encoding, not encryption: anyone can decode it, so never treat it as secrecy.

Guide

How to use it

  1. Paste the Base64. Whitespace, line wraps and a data:…;base64, prefix are handled for you.
  2. The decoded text appears as you paste. Binary content is flagged rather than printed as junk.
  3. Hit Switch to encode to go the other way, UTF-8 safe for accents and emoji.
  4. Tick URL-safe when working with JWT segments or URL parameters.

Examples

Worked examples

The classic

SGVsbG8sIHdvcmxkIQ== decodes to Hello, world! Paste it and watch the padding get handled.

A Kubernetes secret

Values in a secrets manifest are Base64, not encrypted. Decoding one here (locally, which is the only acceptable place) shows the plain connection string inside.

A Basic auth header

Authorization: Basic dXNlcjpwYXNz decodes to user:pass, a neat demonstration of why Basic auth needs HTTPS.

Method

How it works

Base64 maps every three bytes to four characters from a 64-character alphabet. Decoding reverses that: the input is cleaned (whitespace stripped, URL-safe characters normalised, padding restored), converted back to bytes and interpreted as UTF-8 text. Content that is not text, images, archives, certificates, is detected by its control bytes and flagged.

All of it runs on your device. Base64 blobs routinely contain credentials, so pasting them into a server-side decoder is exactly the mistake this tool exists to avoid.

FAQ

Frequently asked questions

What is Base64?

A way of writing any bytes using 64 safe characters (A-Z, a-z, 0-9, + and /), so binary data can travel through systems built for text: email attachments, JSON fields, URLs and config files.

Is Base64 encryption?

No, and this matters: it is a reversible encoding with no key. Anyone can decode it, as this page proves. Base64-encoding a password or API key hides nothing.

Why does my Base64 fail to decode?

Usually missing characters at either end from a partial copy, stray text mixed in, or a URL-safe variant with - and _ where + and / are expected. This decoder accepts both alphabets and fixes missing padding automatically.

What are the = signs at the end?

Padding. Base64 works in groups of three bytes; when the input does not divide evenly, one or two = characters fill the last group. Some systems drop them, so this decoder restores padding for you.

Why is my decoded output gibberish?

The Base64 probably wraps binary data, an image, a zip, a certificate, rather than text. The decoder flags this instead of printing junk; the image page handles files properly.

Is what I paste kept anywhere?

No. Decoding runs in your browser with nothing transmitted or stored, which matters because Base64 blobs often contain tokens and credentials.

More tools

Related tools