Base64 Decode
Decode Base64 text back into its original readable form.
A string like SGVsbG8gd29ybGQ= looks encrypted. It is not. It is Base64, an encoding scheme, and anyone with a decoder — including this one — can turn it straight back into plain text in a fraction of a second.
Encoding is not encryption, and that distinction matters
Base64 exists to make arbitrary binary data safe to pass through systems that only handle plain text — email attachments, JSON fields, URLs, config files. It maps every 3 bytes of input to 4 printable characters. That is the entire job. There is no key, no secret, nothing hidden.
Which means Base64 provides zero confidentiality. If you ever see a password, API key or personal data stored as a Base64 string thinking it is “encoded for safety,” that is a mistake worth fixing immediately — anyone who finds the string can decode it as fast as you can paste it into a box like this one.
Decoding a Base64 string
- Paste the Base64 text into the box.
- Decode it.
- Read the plain-text, image, or file result.
- If the output looks like garbage, check whether the string is actually URL-safe Base64, which swaps two characters for ones legal in a URL.
- Re-encode only if you need to pass the value along through the same kind of system again.
Where you will run into Base64 in practice
- Data URIs embedding a small image directly inside HTML or CSS, starting
data:image/png;base64,. - The header and payload sections of a JWT authentication token.
- Email attachments, which are Base64-encoded inside the raw message so they survive as plain text.
- Basic HTTP authentication headers, which encode a username and password — another reminder this is not encryption.
- API responses and config files that embed small binary blobs, like certificates, inside JSON or XML.
A quick sanity check on length
Valid Base64 output is always a multiple of 4 characters long, padded with one or two = signs at the end if the original data was not an exact multiple of 3 bytes. If a string you are trying to decode does not fit that pattern, it may be truncated, corrupted, or simply not Base64 at all — worth checking before you assume the decoder is broken.
Base64 decoding questions
Does Base64 keep my data private?
No. It is an encoding format with no secret key involved, designed purely to represent binary data as text. Anyone can decode it with a free tool in an instant, so never rely on it to keep information private.
Why does a JWT token look like three chunks of Base64?
A JSON Web Token has three parts — header, payload and signature — each Base64-encoded and joined with dots. You can decode the header and payload to read the claims inside; the signature verifies authenticity but does not decode into readable text.
What does the equals sign at the end of a Base64 string mean?
It is padding. Base64 processes data in groups of 3 bytes, and when the input does not divide evenly into groups of three, one or two = characters are added at the end to complete the final group.
Why is my decoded output unreadable garbage?
The string may use URL-safe Base64, which replaces + and / with - and _, or it may simply not be Base64 to begin with. Confirm the source and try the URL-safe variant if plain decoding fails.
Is decoding Base64 done locally, or sent to a server?
It is sent to the server to be decoded, but nothing you paste in — including any tokens or data URIs — is stored after processing.