Base64 Decoder
Decode Base64 and Base64URL back to text or raw bytes.
Paste Base64 on the left.
How it works
Base64 is an encoding, not encryption. There is no key: anything Base64-encoded is readable by anyone who notices what it is. That is worth stating plainly, because a surprising amount of software still treats a Base64 string as if the transformation hid something.
Both alphabets, either padding
Standard Base64's + and / and Base64URL's - and _ both decode,
including a string that mixes them — values get re-encoded as they pass between systems, and rejecting one for an
alphabet swap helps nobody. Trailing = is optional. Whitespace and line wrapping are stripped, so a
PEM block or a folded mail header pastes straight in.
When the bytes are not text
UTF-8 decoding runs in strict mode. If the bytes are not valid UTF-8 — a compressed blob, an executable, a key — you get a hex dump with an ASCII gutter rather than a failed decode. The alternative, a lenient decode, returns a wall of replacement characters that looks like success and is not.
Errors name the character
A character outside both alphabets is reported with its position, and a length that cannot be Base64 at all — a final group of one character, which is six bits, too few for any whole byte — is reported as such rather than as a generic failure.
Example
A JWT's middle segment is Base64URL. Paste one here and the claims come back as JSON — which is the whole point of the JWT Decoder's warning that a token is not encrypted. For the token as a whole, use that tool instead; it splits the segments and checks the claims for you.
Frequently asked questions
Do I need to choose between Base64 and Base64URL?
No. Both alphabets decode, including a string that mixes them, because payloads get re-encoded as they pass between systems. Padding is optional too — Base64URL omits it by spec and copied values often carry it anyway.
What happens when the bytes are not text?
You get a hex dump with an ASCII gutter instead of a failed decode. UTF-8 validation runs in strict mode, so a binary payload is reported as binary rather than returned as a wall of replacement characters that would look like a successful decode.
Is Base64 a form of encryption?
No. It is a reversible encoding with no key, designed to carry bytes through channels that only accept text. Anything Base64-encoded is readable by anyone who notices it is Base64.
Related tools
Base64 Encoder
Encode text or bytes to Base64 or Base64URL.
LocalJWT Decoder
Decode a JSON Web Token and read its header, claims and expiry.
LocalHex ↔ ASCII Converter
Convert between hex byte sequences and readable text.
LocalJSON Formatter & Validator
Format, validate and measure JSON, with errors located by line and column.
LocalSAML Response Decoder
Decode a SAMLResponse and read its issuer, subject, conditions and attributes.
LocalYAML to JSON Converter
Convert YAML to JSON and back, with what the conversion costs stated rather than dropped.
LocalFrom the intelligence desk
- Vulnerability Ajax.NET Professional Insecure Deserialization (CVE-2021-23758)
- Vulnerability Kopia Command Injection (CVE-2026-45695)
- Vulnerability The Events Calendar Code Injection (CVE-2026-78159)
- Vulnerability The Events Calendar Insecure Deserialization (CVE-2026-78006)