Skip to the Base64 decoder

RFC 4648 · Decoder & encoder

Base64 decode anything, without uploading anything.

Paste a Base64 string and get readable text, an image or a file back in the same keystroke. This Base64 decode online tool runs entirely in your browser — your data is never uploaded, never logged and never leaves your device.

  • Decodes as you type
  • 20+ character sets
  • Images, PDFs & JWTs
  • No ads, no sign-up

Updated · Standard and URL-safe Base64 (RFC 4648)

Base64 decoder and encoder tool

0 chars
Decoded result
Type: — Size: 0 B
Options
General
Decoding options

Ctrl+Enter decode Ctrl+Shift+C copy result Drop a file anywhere on the input to load it

Base64 decode online — free, instant and private

This is a Base64 decode online tool that does the work in your browser rather than on a server. Paste into the box above and the result appears as you go: no button, no page reload, no upload. Text comes out readable, images show up in the Preview tab, and anything binary gets a hex dump and a Download button with the right file extension.

Switch to Encode to run it in reverse, or use our dedicated encoder at freebase64encode.com. If you would rather decode Base64 in code, the snippets below cover Python, JavaScript, Linux, Windows PowerShell, PHP, Java, Go, C# and Ruby.

Working with a specific format? There are dedicated pages to convert Base64 to an image, Base64 to PDF and Base64 to hex, and to decode Base64URL and JWTs.

How to decode Base64 in three steps

  1. 01

    Paste your Base64 string

    Paste the Base64 data into the input box, or drag a file onto it. Whitespace, line breaks, data: URI prefixes and URL-safe characters are handled automatically.

  2. 02

    Read the decoded result

    The decoded output appears instantly in the panel beside the input, decoded in your browser. Choose a character set if the text looks wrong.

  3. 03

    Copy, download or preview

    Copy the decoded text, download binary output as a file with the right extension, inspect it as a hex dump, or preview a decoded image on the page.

More decoders

Decode Base64 to a specific format.

What you get

A Base64 decoder that tells you what it found.

Most online decoders hand back a wall of characters and leave you to guess. This one identifies the payload, repairs the common encoding mistakes, and shows the result in whatever form actually helps.

Nothing leaves your device

Every byte is decoded by JavaScript on this page. No upload, no request, no logging — check your network tab.

Automatic format detection

PNG, JPEG, GIF, WebP, SVG, PDF, ZIP, MP4, JSON, XML and HTML are recognised from their signature bytes and labelled.

Base64 image preview

Decode an image and see it rendered immediately, with its real pixel dimensions and file size, then download it as a file.

20+ character sets

UTF-8, UTF-16, Latin-1, Windows-1250/1251/1252, Shift_JIS, GBK, Big5, KOI8-R and more — with auto-detection.

Hex dump view

Binary output gets a classic offset / hex / ASCII dump so you can inspect headers and magic bytes on the page.

JWT aware

Paste a JSON Web Token and the header and payload are unpacked into a table, with timestamps converted to dates.

Forgiving input

Missing padding, URL-safe “-” and “_”, stray whitespace, MIME line wrapping and full data: URIs are handled automatically.

Line-by-line mode

Decode a list of independent Base64 values in one pass, one result per line — handy for logs and exports.

Encoding too

Flip to Encode for text or any file, with MIME wrapping, the URL-safe alphabet, or a ready-made data: URI.

Why this one

The difference is where the decoding happens.

Most Base64 decoders POST your string to a server, decode it there and send the result back. That means your token, key or file left your machine — for a transformation your browser can do in microseconds. This one never makes that request.

Feature comparison between this Base64 decoder and typical server-based online Base64 tools
Feature freebase64decode.com Typical online decoder
Where your data is decoded Your browser tab, always Uploaded to a server
Character sets 20+ charsets, decoded offline Server-side only
File size limit Only your device memory Typically capped at 100 MB
Decoded image preview Built in, with dimensions Not offered
Hex dump of binary output Built in Not offered
JWT header and payload view Automatic Not offered
URL-safe alphabet and padding repair Automatic Manual
data: URI detection Automatic Manual
Works without a connection Yes, once the page has loaded No
Ads and cookie banners None, and no tracking cookies Usually present

Do it in code

Base64 decode in Python, JavaScript, Linux and more.

Once you have checked a value in the decoder above, you usually need the same thing in code. Every snippet is copy-paste ready and covers the parts that normally bite: character sets, the URL-safe alphabet, and missing padding.

Python Base64 decode

Python's base64 module is in the standard library — no install needed. b64decode always returns bytes, so call .decode() when you want a str.

import base64

# Base64 string -> text
encoded = "SGVsbG8sIHdvcmxkIQ=="
text = base64.b64decode(encoded).decode("utf-8")
print(text)                      # Hello, world!

# Reject anything that is not valid Base64 instead of silently skipping it
base64.b64decode(encoded, validate=True)

# URL-safe alphabet (RFC 4648 section 5): "-" and "_" instead of "+" and "/"
base64.urlsafe_b64decode("SGVsbG8_d29ybGQtMQ==")

# Unpadded input (JWTs, URL parameters) raises binascii.Error -- pad it first
def b64decode_any(s: str) -> bytes:
    s = s.replace("-", "+").replace("_", "/")
    return base64.b64decode(s + "=" * (-len(s) % 4))

# Base64 -> image file on disk
with open("logo.png", "wb") as f:
    f.write(base64.b64decode(image_b64))

# Decode every line of a file separately
with open("encoded.txt") as f:
    for line in f:
        print(base64.b64decode(line.strip()).decode("utf-8"))

The mechanics

What Base64 is, and how decoding reverses it.

Base64 rewrites arbitrary bytes as 64 printable characters — A–Z a–z 0–9 + / — so binary data survives systems built for text. Decoding runs it backwards: each character is looked up to a 6-bit value, four of them form 24 bits, and those bits are re-cut into three bytes. It is an encoding, not encryption, so anyone can do it.

Worked example: TWFu → Man

How the four Base64 characters “TWFu” decode to the three bytes “Man”
Base64 T · W · F · u
Index 19 · 22 · 5 · 46
6-bit groups 010011 010110 000101 101110
Re-cut into 8 bits 01001101 01100001 01101110
Bytes 77 · 97 · 110
Text Man

Trailing = signs are padding, not data: == means the last group held one byte, = means two. Base64 output is always about 33% larger than what it decodes to.

The Base64 alphabet (index table)

Every Base64 character stands for a number from 0 to 63. Decoding looks each character up in this table (RFC 4648, table 1). URL-safe Base64 is identical except that 62 is - and 63 is _, and = is padding rather than a value.

Base64 index table: the value of each of the 64 characters
Value Char Value Char Value Char Value Char
0 A 16 Q 32 g 48 w
1 B 17 R 33 h 49 x
2 C 18 S 34 i 50 y
3 D 19 T 35 j 51 z
4 E 20 U 36 k 52 0
5 F 21 V 37 l 53 1
6 G 22 W 38 m 54 2
7 H 23 X 39 n 55 3
8 I 24 Y 40 o 56 4
9 J 25 Z 41 p 57 5
10 K 26 a 42 q 58 6
11 L 27 b 43 r 59 7
12 M 28 c 44 s 60 8
13 N 29 d 45 t 61 9
14 O 30 e 46 u 62 +
15 P 31 f 47 v 63 /

Where you actually meet Base64

Email attachments

MIME (RFC 2045) Base64-encodes attachments and wraps the output at 76 characters. Decoders skip the line breaks — this one strips them for you.

Data URIs

data:image/png;base64,… inlines an image, font or SVG into HTML or CSS. Paste the whole URI here and the prefix is detected and removed automatically.

JSON Web Tokens

Each of the three JWT segments is base64url with the padding removed. Paste a token and the header and payload are unpacked into a readable table.

HTTP Basic auth

Authorization: Basic carries base64(username:password). Decoding it takes one paste — which is exactly why Basic auth is only acceptable over HTTPS.

Config and secrets files

Kubernetes Secrets, PEM certificates and SSH keys store binary as Base64 so the file stays text. Decoding is how you check what is actually inside.

APIs and databases

Binary blobs travel through JSON, XML and text columns as Base64. The hex view here shows the real bytes, so you can spot the file type by its signature.

Standard vs. URL-safe Base64

RFC 4648 defines two alphabets. The standard one uses + and /, which both mean something inside a URL. The URL-safe variant (§5, often called base64url) swaps them for - and _ and usually drops the = padding. This decoder detects which one you pasted: a string containing - or _ is treated as URL-safe unless you force the setting yourself.

How to decode a Base64 image

Paste the whole data URI — data:image/png;base64, prefix included — or just the encoded part. The prefix is stripped, the signature bytes are checked, and the picture appears in the Preview tab with its real dimensions. Download saves it as a genuine PNG, JPEG, GIF, WebP or SVG file. If the preview stays blank, open the Hex tab and look for a known signature such as 89 50 4e 47 (PNG) or ff d8 ff (JPEG) — a missing one means the string was truncated.

Six decoding errors, and what they mean

“Invalid character at position N”

Something is outside the Base64 alphabet — usually a stray quote, an ellipsis from a truncated copy, or a URL-safe character while strict decoding is forced.

Length is not a multiple of 4

The padding was removed. Turn on Repair padding; if the remainder is exactly one character, the string is genuinely truncated and cannot be recovered.

Mojibake — é instead of é

The bytes were decoded with the wrong character set. Try UTF-8 first, then Windows-1252 for text that came from older Windows software.

Unreadable symbols everywhere

The payload is binary, not text. Switch to the Hex or Preview tab and download it as a file instead of copying the text.

It decodes to more Base64

The value was encoded twice. Press “Send to input” to feed the result back in and decode it again.

Base64 is not encryption

Anyone can decode it in one paste. If a secret is “protected” only by Base64, treat it as already exposed and rotate it.

Questions

Base64 decoding, answered.

What is Base64 decode?

Base64 decode is the process of turning a Base64-encoded string back into the original bytes it represents. Base64 encoding takes binary data and rewrites it using 64 printable ASCII characters so it can travel safely through systems that only handle text, such as email or JSON. Decoding reverses that mapping: every four Base64 characters become three original bytes.

How do I decode a Base64 string online?

Paste the Base64 string into the input box at the top of this page. The decoded result appears immediately in the output box beside it — there is no button to press and no waiting. You can then copy the text, download it as a file, view it as a hex dump, or preview it if the result is an image.

Is this Base64 decoder safe to use with sensitive data?

Yes. All decoding happens in JavaScript inside your own browser, so your input is never uploaded, transmitted, logged or stored anywhere. You can verify this by opening your browser developer tools and watching the network tab while you decode, or by disconnecting from the internet — the tool keeps working after the page has loaded.

Is Base64 encryption? Is it secure?

No. Base64 is an encoding, not encryption. It offers no security at all because anyone can reverse it without a key or password, which is exactly what this page does. Never use Base64 to protect passwords, tokens or personal data. Use real encryption such as AES, and TLS for data in transit.

How do I decode a Base64 image?

Paste the full data URI, including the data:image/png;base64, prefix, or just the encoded part on its own. The prefix is stripped automatically and the image signature is checked, so the picture appears in the Preview tab together with its pixel dimensions and file size. Use the Download button to save it as a real PNG, JPEG, GIF, WebP or SVG file.

Why does my decoded text show strange characters like é or �?

That is a character set mismatch: the bytes are correct but they are being interpreted with the wrong encoding. Set the character set option to UTF-8 first. If the data came from an older Windows application, try Windows-1252 or ISO-8859-1. Leaving the setting on Auto-detect tries strict UTF-8 first and falls back to Windows-1252.

What does “invalid Base64” mean and how do I fix it?

It means the input contains a character outside the Base64 alphabet, or its length is not a multiple of four. The usual causes are a truncated copy, a quotation mark or ellipsis that came along with the text, or a URL-safe string using - and _ . Keep the Strip whitespace and Repair padding options on, and the decoder fixes most of these automatically.

What is the difference between standard and URL-safe Base64?

Standard Base64 (RFC 4648 section 4) uses + and / as its last two characters, both of which have special meaning inside a URL. URL-safe Base64, also called Base64url (RFC 4648 section 5), replaces them with - and _ and usually omits the = padding. This decoder detects which variant you pasted and converts it automatically.

Can I decode a Base64 file?

Yes. Click the File button or drag a file onto the input box. The file is read locally by your browser, decoded on your own device, and the result can be downloaded with the correct extension. Because nothing is uploaded there is no imposed size limit — the practical ceiling is your device memory rather than a server quota.

How do I decode Base64 in Python?

Use the standard library: import base64, then base64.b64decode("SGVsbG8=").decode("utf-8"). b64decode always returns bytes, so call .decode() to get a string. Use base64.urlsafe_b64decode for the URL-safe alphabet, and pass validate=True if you want malformed input to raise an error instead of being silently ignored.

How do I decode Base64 in Linux or Bash?

Pipe the string into the base64 command: echo "SGVsbG8=" | base64 --decode. Use printf %s instead of echo if the trailing newline matters, base64 -d file > out.bin for files, and base64 -di to ignore line wrapping. The long form --decode works on both Linux and macOS; older macOS releases only accept a capital -D as the short flag.

How do I decode Base64 in Windows or PowerShell?

In PowerShell run [Text.Encoding]::UTF8.GetString([Convert]::FromBase64String("SGVsbG8=")). To turn a Base64 file back into a binary file, read it with Get-Content -Raw, pass it to [Convert]::FromBase64String and save the bytes with [IO.File]::WriteAllBytes. From the classic Command Prompt, certutil -decode encoded.txt decoded.bin does the same job and ships with every version of Windows.

How do I decode Base64 in JavaScript?

In the browser, atob() decodes to a binary string, but it mangles non-ASCII text on its own. Convert the result to bytes and run it through TextDecoder: new TextDecoder().decode(Uint8Array.from(atob(b64), c => c.charCodeAt(0))). In Node.js use Buffer.from(b64, "base64").toString("utf8"), or the "base64url" encoding for URL-safe input.

Can I decode a JWT here?

Yes. Paste a JSON Web Token and the header and payload are unpacked into a readable table automatically, with issued-at and expiry timestamps converted into dates. The signature is shown but not verified, because verification requires the secret or public key — which this tool never asks for and could not use anyway, since nothing leaves your browser.

Does this tool cost anything or require an account?

No. It is completely free, has no sign-up, no account and no usage limits. It is a static page, so there is no server processing your data and nothing to bill you for.

Why is Base64 output larger than the original data?

Base64 represents every three bytes of input with four output characters, so the encoded form is roughly 33% larger, plus padding and any line breaks. That overhead is the price of being able to move binary data through text-only channels.