Base64 Decoder

Decode Base64 back to readable text, in the standard or the URL-safe alphabet, entirely in your browser.

Runs entirely in your browser. Nothing is uploaded, logged or stored.

Paste a Base64 string and read what it actually contains: an Authorization header, a JWT segment, a data URI, a config value someone encoded to get it past a form.

How it works

The string is decoded back to bytes, which are then read as UTF-8. Line breaks and spaces are ignored first, so Base64 wrapped at 64 or 76 characters — as it is in emails and PEM files — pastes in without cleaning.

Decoding is strict about everything else: a character outside the alphabet or a length that cannot be right is reported rather than quietly skipped, because a silent partial decode is how truncated tokens go unnoticed.

Examples

Case Input Result
An Authorization header value YWxhZGRpbjpvcGVuc2VzYW1l aladdin:opensesame
A JWT payload, which uses the URL-safe alphabet eyJzdWIiOiIxMjMifQ {"sub":"123"}

Frequently asked questions

Why does my JWT segment fail to decode?

JSON Web Tokens use the URL-safe alphabet and drop the padding, so switch the alphabet option. Also decode one segment at a time: a JWT is three Base64 strings joined by dots, and the whole thing is not itself Base64.

I get "binary data rather than text".

The string decoded correctly, but the bytes are not UTF-8 text — an image, a compressed payload or an encrypted blob. Showing them as characters would corrupt them, so nothing is displayed.

Is the value sent anywhere?

No. Decoding happens in the page. That matters here more than anywhere: Base64 strings pasted into a decoder are very often credentials.

Good to know

  • Everything happens in your browser. What you paste is not uploaded, not logged and not stored.

Sources

All Code tools